ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 Technological controls

5. ISO 27001 Annex A – 8 Technological controls

A.8 Technological Controls Overview

Technological controls define the technical requirements and safeguard mechanisms designed to protect data, software, infrastructure, networks, and systems against unauthorized access, integrity loss, and operational disruption.

Draft Descriptions for A.8.1 – A.8.34

A.8.1 User Endpoint Devices

  • Purpose: To safeguard information processed, stored, or accessed via user endpoint devices.
  • Description: Endpoints (laptops, mobile phones, desktops) must be protected using configuration baselines, full-disk encryption, automated patching, screen locks, anti-malware, and remote-wipe capabilities.

A.8.2 Privileged Access Rights

  • Purpose: To restrict and control the allocation and use of administrative privileges.
  • Description: Admin and root privileges must be tightly restricted using the principle of least privilege, assigned based on job roles, subjected to multi-factor authentication (MFA), and reviewed periodically.

A.8.3 Information Access Restriction

  • Purpose: To prevent unauthorized access to application data, files, and core systems.
  • Description: Access to information and system functions must be controlled using access control policies, role-based permissions (RBAC), and explicit authorization rules based on business requirements.

A.8.4 Access to Source Code

  • Purpose: To prevent unauthorized access, tampering, or theft of application source code.
  • Description: Read and write access to source code and development repositories must be restricted strictly to authorized developers, with mandatory access logging, branch protections, and multi-party reviews.

A.8.5 Secure Authentication

  • Purpose: To ensure identity verification mechanisms securely authenticate users before granting system access.
  • Description: Strong authentication mechanisms (e.g., MFA, passwordless logins, robust password policies, encrypted credential transmission) must be implemented across all critical applications and infrastructure.

A.8.6 Capacity Management

  • Purpose: To ensure systems maintain required operational performance, availability, and processing capacity.
  • Description: System resource utilization (CPU, memory, bandwidth, storage) must be monitored and forecasted proactively to prevent performance degradation or unexpected service outages.

A.8.7 Protection Against Malware

  • Purpose: To protect systems and data from malicious software (viruses, ransomware, spyware).
  • Description: Deployment of central Endpoint Detection and Response (EDR) or anti-malware solutions, paired with automated signature/heuristic updates, user awareness, and regular scanning protocols.

A.8.8 Management of Technical Vulnerabilities

  • Purpose: To prevent exploitation of technical vulnerabilities across infrastructure and software.
  • Description: Continuous vulnerability scanning, patch management protocols, threat intelligence evaluation, and strict SLA-driven remediation timelines for discovered vulnerabilities.

A.8.9 Configuration Management

  • Purpose: To establish and maintain secure baseline configurations for hardware, software, network, and cloud services.
  • Description: Systems must be configured according to hardened security baselines (e.g., CIS benchmarks), with automated drift detection and strict change tracking protocols for any configuration updates.

A.8.10 Information Deletion

  • Purpose: To prevent exposure of sensitive data when it is no longer required.
  • Description: Secure data erasure procedures (overwriting, cryptographic erasure, or degaussing) must be established to irreversibly delete data held in storage, databases, or cloud environments when retention periods end.

A.8.11 Data Masking

  • Purpose: To limit the exposure of sensitive data, such as PII or financial details, to unauthorized viewers.
  • Description: Data masking, pseudonymization, obfuscation, or tokenization techniques must be applied according to data classification levels and regulatory compliance obligations (e.g., masking credit card or health details in non-production environments).

A.8.12 Data Leakage Prevention (DLP)

  • Purpose: To detect and prevent unauthorized extraction or transmission of sensitive data.
  • Description: Technical DLP mechanisms must monitor and restrict the exfiltration of sensitive information across network egress channels, email gateways, USB ports, and cloud uploads.

A.8.13 Information Backup

  • Purpose: To ensure data can be recovered completely and timely following an incident, corruption, or hardware failure.
  • Description: Regular, encrypted backups of systems, configurations, and data must be executed, stored off-site or in isolated cloud locations, and tested periodically for restoration integrity.

A.8.14 Redundancy of Information Processing Facilities

  • Purpose: To meet system availability and business continuity requirements.
  • Description: High availability (HA) architectures, failover clusters, load balancing, and geographically redundant infrastructure must be implemented to ensure continuous operations during hardware or facility failures.

A.8.15 Logging

  • Purpose: To capture event data to assist in investigations, detect anomalous behavior, and monitor access.
  • Description: Systems, applications, network gear, and cloud environments must generate audit logs covering login events, configuration changes, and privileged actions. Logs must be time-synchronized and centrally forwarded to a SIEM.

A.8.16 Monitoring Activities

  • Purpose: To detect unauthorized or anomalous operational behaviors across networks and applications.
  • Description: Networks, systems, and application behaviors must be monitored in real time using automated detection rules, anomaly alerts, and security operations center (SOC) processes.

A.8.17 Clock Synchronization

  • Purpose: To ensure time stamps across logs and system records are accurate and consistent across the organization.
  • Description: Internal system clocks across servers, firewalls, and network devices must synchronize to a authoritative Network Time Protocol (NTP) master clock source.

A.8.18 Use of Privileged Utility Programs

  • Purpose: To prevent administrative utilities from bypassing system security controls.
  • Description: The use of system utilities capable of overriding security or operating controls must be strictly restricted, authorized, logged, and separated from operational application environments.

A.8.19 Installation of Software on Operational Systems

  • Purpose: To safeguard operational environments from software corruption, malware, or licensing issues.
  • Description: Policies and automated controls must restrict users from installing unauthorized software on company endpoints or production servers. Only vetted, digitally signed applications are permitted.

A.8.20 Network Controls

  • Purpose: To protect data flowing across internal networks and external boundaries.
  • Description: Network infrastructure must be secured using firewalls, intrusion prevention systems (IPS), web application firewalls (WAF), secure routing protocols, and perimeter filters.

A.8.21 Security of Network Services

  • Purpose: To ensure third-party network services maintain adequate security levels.
  • Description: Security mechanisms, service levels, and monitoring parameters must be defined for all network services provided internally or by external providers (e.g., VPNs, dedicated links, DNS management).

A.8.22 Segregation of Networks

  • Purpose: To contain security breaches and isolate sensitive business traffic.
  • Description: Networks must be split into distinct logical or physical security domains (e.g., VLANs, subnets, micro-segmentation) to isolate development, production, corporate, and guest user zones.

A.8.23 Web Filtering

  • Purpose: To protect endpoints and networks from accessing malicious or unauthorized websites.
  • Description: Web proxy or DNS-based URL filtering controls must restrict access to known malicious domains, phishing sites, or unauthorized categories of web content.

A.8.24 Use of Cryptography

  • Purpose: To ensure the proper and effective use of encryption to protect confidentiality and integrity.
  • Description: Rules governing data encryption in transit (e.g., TLS 1.3) and at rest (e.g., AES-256) must be enforced across all sensitive databases, network channels, endpoints, and storage systems.

A.8.25 Secure Development Life Cycle (SDLC)

  • Purpose: To ensure security is integrated directly into software creation and deployment.
  • Description: Formal rules and processes for secure architecture design, threat modeling, code reviews, static/dynamic security testing (SAST/DAST), and dependency vulnerability tracking throughout the software lifecycle.

A.8.26 Application Security Requirements

  • Purpose: To ensure security requirements are identified and implemented during the application design phase.
  • Description: System functional and technical requirements must explicitly detail security controls (e.g., input sanitization, output encoding, session handling, state management) for both internally developed and acquired applications.

A.8.27 Secure System Architecture and Engineering Principles

  • Purpose: To ensure information systems are designed, implemented, and maintained using secure design fundamentals.
  • Description: Systems must be engineered using principles such as defense-in-depth, zero trust, default deny, fail-secure mechanisms, and boundary isolation.

A.8.28 Secure Coding

  • Purpose: To prevent the introduction of common software vulnerabilities into source code.
  • Description: Developers must follow standardized secure coding standards (e.g., OWASP, SANS Top 25) to prevent flaws like SQL injection, cross-site scripting (XSS), buffer overflows, and broken access controls.

A.8.29 Security Testing in Development and Acceptance

  • Purpose: To validate that security controls operate effectively before system releases enter production.
  • Description: Automated and manual security testing (e.g., unit security tests, penetration testing, vulnerability scanning, functional validation) must occur during testing phases prior to deployment.

A.8.30 Outsourced Development

  • Purpose: To verify that third-party developers build software securely according to organizational standards.
  • Description: Organizations must enforce contractually binding security requirements, code ownership, secure coding guidelines, independent vulnerability assessments, and audit rights for external vendor code.

A.8.31 Separation of Development, Test, and Production Environments

  • Purpose: To prevent development and testing activities from causing operational outages or data leakage in production.
  • Description: Development, testing, staging, and production environments must be logically isolated. Production data must not be transferred into test environments unless properly masked.

A.8.32 Change Management

  • Purpose: To ensure modifications to systems and software do not adversely impact availability or security.
  • Description: Software deployments, system configuration edits, and infrastructure changes must undergo peer review, formal change approval, rollback planning, and automated testing before execution.

A.8.33 Test Information

  • Purpose: To ensure data used for testing purposes is selected, protected, and managed securely.
  • Description: Live operational data containing sensitive or personal information should avoid being used directly in non-production environments; synthetic or anonymized test data must be used whenever possible.

A.8.34 Protection of Information Systems During Audit Testing

  • Purpose: To minimize the operational impact of security assessments and compliance audits on live systems.
  • Description: Audit activities, vulnerability scans, and penetration tests involving operational production environments must be carefully planned, scheduled outside peak hours, scoped, and monitored continuously.

Articles

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *