A.8 · 34 controls

ISO 27001 Technological controls

The 34 technological controls are where most engineering effort lands: access, cryptography, logging, secure development, networks, and backups.

A.8.1

User endpoint devices

Safeguard the information that lives on, runs through or is reachable from laptops, phones and other user endpoint devices.

Guidance and how to meet it →
A.8.2

Privileged access rights

Limit and oversee privileged access so only authorised users, components and services hold elevated rights.

Guidance and how to meet it →
A.8.3

Information access restriction

Allow only authorised access to information and related assets while blocking unauthorised access.

Guidance and how to meet it →
A.8.4

Access to source code

Properly manage read and write access to source code, development tools and software libraries.

Guidance and how to meet it →
A.8.5

Secure authentication

Make sure users and entities are securely authenticated before access to systems, applications and services.

Guidance and how to meet it →
A.8.6

Capacity management

Monitor and tune resource use to keep enough capacity in processing facilities, people and facilities.

Guidance and how to meet it →
A.8.7

Protection against malware

Protect information and related assets against malware, backed by user awareness.

Guidance and how to meet it →
A.8.8

Management of technical vulnerabilities

Prevent exploitation by identifying technical vulnerabilities, assessing exposure and taking timely action.

Guidance and how to meet it →
A.8.9New

Configuration management

Establish, document, implement, monitor and review secure configurations across hardware, software, services and networks.

Guidance and how to meet it →
A.8.10New

Information deletion

Delete information from systems, devices and media once no longer needed, to cut exposure and meet legal obligations.

Guidance and how to meet it →
A.8.11New

Data masking

Use data masking to limit exposure of sensitive data including PII and meet legal and contractual requirements.

Guidance and how to meet it →
A.8.12New

Data leakage prevention

Apply data leakage prevention to detect and stop unauthorised disclosure of sensitive information.

Guidance and how to meet it →
A.8.13

Information backup

Maintain and regularly test backups of information, software and systems so they can be recovered after loss or failure.

Guidance and how to meet it →
A.8.14

Redundancy of information processing facilities

Build enough redundancy into information processing facilities to meet availability requirements.

Guidance and how to meet it →
A.8.15

Logging

Produce, store, protect and analyse logs of activities, exceptions, faults and other relevant events.

Guidance and how to meet it →
A.8.16New

Monitoring activities

Monitor networks, systems and applications for anomalous behaviour and act on it to detect potential incidents.

Guidance and how to meet it →
A.8.17

Clock synchronization

Synchronise system clocks to approved time sources so security events can be correlated and investigations supported.

Guidance and how to meet it →
A.8.18

Use of privileged utility programs

Keep tight control over utility programs powerful enough to bypass normal system and application safeguards.

Guidance and how to meet it →
A.8.19

Installation of software on operational systems

Manage how software is installed on live operational systems so integrity stays intact and vulnerabilities are not introduced.

Guidance and how to meet it →
A.8.20

Networks security

Secure and manage networks and network devices to protect the information flowing through systems and applications.

Guidance and how to meet it →
A.8.21

Security of network services

Identify, deliver and monitor the security mechanisms, service levels and requirements of network services.

Guidance and how to meet it →
A.8.22

Segregation of networks

Split networks into separate security zones for groups of services, users and systems and control traffic between them.

Guidance and how to meet it →
A.8.23New

Web filtering

Manage access to external websites to cut exposure to malicious content and block unauthorised web resources.

Guidance and how to meet it →
A.8.24

Use of cryptography

Define and apply rules for using cryptography effectively, including key management, to protect confidentiality, authenticity and integrity.

Guidance and how to meet it →
A.8.25

Secure development life cycle

Establish and apply rules so that security is built into the whole lifecycle of developing software and systems.

Guidance and how to meet it →
A.8.26

Application security requirements

Identify, specify and approve information security requirements whenever applications are developed or acquired.

Guidance and how to meet it →
A.8.27

Secure system architecture and engineering principles

Establish, document and apply secure engineering principles across all information system development.

Guidance and how to meet it →
A.8.28New

Secure coding

Apply secure coding principles to software development to reduce the number of security vulnerabilities in the code.

Guidance and how to meet it →
A.8.29

Security testing in development and acceptance

Define and run security testing throughout development and acceptance before code reaches production.

Guidance and how to meet it →
A.8.30

Outsourced development

Direct, monitor and review outsourced system development so required security measures are implemented.

Guidance and how to meet it →
A.8.31

Separation of development, test and production environments

Separate and secure development, test and production environments to protect production systems and data.

Guidance and how to meet it →
A.8.32

Change management

Subject changes to information processing facilities and systems to formal change management procedures.

Guidance and how to meet it →
A.8.33

Test information

Select, protect and manage test information appropriately to keep tests reliable and safeguard operational data.

Guidance and how to meet it →
A.8.34

Protection of information systems during audit testing

Plan and agree audit and assurance activities on operational systems with management to minimise their impact.

Guidance and how to meet it →