ISO 27001 Technological controls
The 34 technological controls are where most engineering effort lands: access, cryptography, logging, secure development, networks, and backups.
User endpoint devices
Safeguard the information that lives on, runs through or is reachable from laptops, phones and other user endpoint devices.
Guidance and how to meet it →Privileged access rights
Limit and oversee privileged access so only authorised users, components and services hold elevated rights.
Guidance and how to meet it →Information access restriction
Allow only authorised access to information and related assets while blocking unauthorised access.
Guidance and how to meet it →Access to source code
Properly manage read and write access to source code, development tools and software libraries.
Guidance and how to meet it →Secure authentication
Make sure users and entities are securely authenticated before access to systems, applications and services.
Guidance and how to meet it →Capacity management
Monitor and tune resource use to keep enough capacity in processing facilities, people and facilities.
Guidance and how to meet it →Protection against malware
Protect information and related assets against malware, backed by user awareness.
Guidance and how to meet it →Management of technical vulnerabilities
Prevent exploitation by identifying technical vulnerabilities, assessing exposure and taking timely action.
Guidance and how to meet it →Configuration management
Establish, document, implement, monitor and review secure configurations across hardware, software, services and networks.
Guidance and how to meet it →Information deletion
Delete information from systems, devices and media once no longer needed, to cut exposure and meet legal obligations.
Guidance and how to meet it →Data masking
Use data masking to limit exposure of sensitive data including PII and meet legal and contractual requirements.
Guidance and how to meet it →Data leakage prevention
Apply data leakage prevention to detect and stop unauthorised disclosure of sensitive information.
Guidance and how to meet it →Information backup
Maintain and regularly test backups of information, software and systems so they can be recovered after loss or failure.
Guidance and how to meet it →Redundancy of information processing facilities
Build enough redundancy into information processing facilities to meet availability requirements.
Guidance and how to meet it →Logging
Produce, store, protect and analyse logs of activities, exceptions, faults and other relevant events.
Guidance and how to meet it →Monitoring activities
Monitor networks, systems and applications for anomalous behaviour and act on it to detect potential incidents.
Guidance and how to meet it →Clock synchronization
Synchronise system clocks to approved time sources so security events can be correlated and investigations supported.
Guidance and how to meet it →Use of privileged utility programs
Keep tight control over utility programs powerful enough to bypass normal system and application safeguards.
Guidance and how to meet it →Installation of software on operational systems
Manage how software is installed on live operational systems so integrity stays intact and vulnerabilities are not introduced.
Guidance and how to meet it →Networks security
Secure and manage networks and network devices to protect the information flowing through systems and applications.
Guidance and how to meet it →Security of network services
Identify, deliver and monitor the security mechanisms, service levels and requirements of network services.
Guidance and how to meet it →Segregation of networks
Split networks into separate security zones for groups of services, users and systems and control traffic between them.
Guidance and how to meet it →Web filtering
Manage access to external websites to cut exposure to malicious content and block unauthorised web resources.
Guidance and how to meet it →Use of cryptography
Define and apply rules for using cryptography effectively, including key management, to protect confidentiality, authenticity and integrity.
Guidance and how to meet it →Secure development life cycle
Establish and apply rules so that security is built into the whole lifecycle of developing software and systems.
Guidance and how to meet it →Application security requirements
Identify, specify and approve information security requirements whenever applications are developed or acquired.
Guidance and how to meet it →Secure system architecture and engineering principles
Establish, document and apply secure engineering principles across all information system development.
Guidance and how to meet it →Secure coding
Apply secure coding principles to software development to reduce the number of security vulnerabilities in the code.
Guidance and how to meet it →Security testing in development and acceptance
Define and run security testing throughout development and acceptance before code reaches production.
Guidance and how to meet it →Outsourced development
Direct, monitor and review outsourced system development so required security measures are implemented.
Guidance and how to meet it →Separation of development, test and production environments
Separate and secure development, test and production environments to protect production systems and data.
Guidance and how to meet it →Change management
Subject changes to information processing facilities and systems to formal change management procedures.
Guidance and how to meet it →Test information
Select, protect and manage test information appropriately to keep tests reliable and safeguard operational data.
Guidance and how to meet it →Protection of information systems during audit testing
Plan and agree audit and assurance activities on operational systems with management to minimise their impact.
Guidance and how to meet it →