Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
ISO 27001:2013-Compliant Cybersecurity: Annex A Controls

ISO 27001:2013-Compliant Cybersecurity: Annex A Controls

2h 15mIntermediate2022-03-24

Authors

Marc Menninger

Marc Menninger

Cybersecurity Director

Course details

The Annex A controls in the ISO 27001 standard are used by organizations around the world to improve their information security programs and demonstrate good security practices to others. In this second part of his two-part ISO 27001 course, instructor Marc Menninger provides a comprehensive overview of all 114 security controls in Annex A of the ISO 27001 standard. You can use this knowledge to build a better security program and prepare for compliance with the ISO 27001 standard. This course includes handy documents with recommended ways to demonstrate compliance with ISO 27001, providing you with tools you need to get started on implementing the controls to build an ISO 27001-compliant cybersecurity program.

Note: It is recommended that you start with part one, Building an ISO 27001-Compliant Cybersecurity Program: Getting Started, which includes background information and compliance requirements you need to know if you're serious about building an ISO 27,001-compliant cybersecurity program.

Skills covered

Governance, Risk, and ComplianceIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Introduction to the Annex A controls

Policies and the Organization of Information Security (Clauses A.5 and A.6)

  • Management direction for information security (Clause A.5.1)
  • Information security roles and responsibilities and segregation of duties (Clauses A.6.1.1 and A.6.1.2)
  • Contact with authorities and special interest groups and information security in project management (Clauses A.6.1.3, A.6.1.4, and A.6.1.5)
  • Mobile device policy and teleworking (Clauses A.6.2.1 and A.6.2.2)

Human Resources Security (Clause A.7)

  • Human resources security - Prior to employment (Clause A.7.1)
  • Human resources security - During employment (Clause A.7.2)
  • Human resources security - Termination and change of employment (Clause A.7.3)

Asset Management (Clause A.8)

  • Asset management - Responsibility for assets (Clause A.8.1)
  • Asset management - Information classification (Clause A.8.2)
  • Asset management - Media handling (Clause A.8.3)

Access Control and Cryptography (Clauses A.9 and A.10)

  • Access control - Business requirements of access control (Clause A.9.1)
  • Access control - User access management and user responsibilities (Clauses A.9.2 and A.9.3)
  • Access control - System and application access control (Clause A.9.4)
  • Cryptography - Cryptographic controls (Clause A.10.1)

Physical and Environmental Security (Clause A.11)

  • Physical and environmental security - Secure areas (Clause A.11.1)
  • Physical and environmental security - Equipment (Clause A.11.2)

Operations Security (Clause A.12)

  • Operations security - Operational procedures and responsibilities (Clause A.12.1)
  • Operations security - Protection from malware (Clause A.12.2)
  • Operations security - Backup (Clause A.12.3)
  • Operations security - Logging and monitoring (Clause A.12.4)
  • Operations security - Control of operational software (Clause A.12.5)
  • Operations security - Technical vulnerability management (Clause A.12.6)
  • Operations security - Information systems audit considerations (Clause A.12.7)

Communications Security (Clause A.13)

  • Communications security - Network security management (Clause A.13.1)
  • Communications security - Information transfer (Clause A.13.2)

System Acquisition, Development, and Maintenance (Clause A.14)

  • System lifecycle - Security requirements of information systems (Clause A.14.1)
  • System lifecycle - Security in development and support processes (Clause A.14.2)
  • System lifecycle - Test data (Clause A.14.3)

Supplier Relationships (Clause A.15)

  • Supplier relationships - Information security in supplier relationships (Clause A.15.1)
  • Supplier relationships - Supplier service delivery management (Clause A.15.2)

Incident Management and Continuity (Clauses A.16 and A.17)

  • Management of information security incidents and improvements (Clause A.16.1)
  • Information security continuity and redundancies (Clauses A.17.1 and A.17.2)

Compliance (Clause A.18)

  • Compliance - Compliance with legal and contractual requirements (Clause A.18.1)
  • Compliance - Information security reviews (Clause A.18.2)

Conclusion

  • Next steps for complying with ISO 27001

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal