ISO 27001
ISO/IEC 27001:2022
La norme internationale pour les systèmes de management de la sécurité de l'information (SMSI). La révision 2022 réorganise l'Annexe A en 93 mesures réparties sur quatre thèmes : organisationnel, humain, physique et technologique.
Who it applies to
Toute organisation, quels que soient sa taille ou son secteur, souhaitant certifier son système de management de la sécurité de l'information. La certification est volontaire mais souvent exigée contractuellement par les grands clients et partenaires.
A.5 Organizational
- A.5.1 Policies for information security10 mapped
Define, approve, publish and review a set of information security policies.
- A.5.7 Threat intelligence
Collect and analyse information about information security threats to produce actionable intelligence.
- A.5.9 Inventory of information and other associated assets6 mapped
Maintain an inventory of information and associated assets, including owners.
- A.5.15 Access control17 mapped
Establish and implement rules to control physical and logical access to information based on business and security requirements.
- A.5.16 Identity management16 mapped
Manage the full lifecycle of identities used to access information and other associated assets.
- A.5.24 Information security incident management planning and preparation13 mapped
Plan and prepare for managing information security incidents by defining processes, roles and responsibilities.
- A.5.26 Response to information security incidents13 mapped
Respond to information security incidents in line with documented procedures.
A.8 Technological
- A.8.8 Management of technical vulnerabilities10 mapped
Obtain information about technical vulnerabilities, evaluate exposure and take appropriate remediation measures.
- A.8.16 Monitoring activities11 mapped
Monitor networks, systems and applications for anomalous behaviour and act on potential incidents.
- A.8.24 Use of cryptography15 mapped
Define and implement rules for the effective use of cryptography, including key management.
- A.8.9 Configuration management10 mapped
Establish, document, implement, monitor and review the configuration of hardware, software, services and networks.
- A.8.13 Information backup6 mapped
Maintain and regularly test backup copies of information, software and systems in line with the backup policy.
- A.8.15 Logging11 mapped
Produce, store, protect and analyse logs that record activities, exceptions, faults and other relevant events.