Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
ISO 27001:2022-Compliant Cybersecurity: The Annex A Controls

ISO 27001:2022-Compliant Cybersecurity: The Annex A Controls

2h 11mAdvanced2023-10-19

Authors

Marc Menninger

Marc Menninger

Cybersecurity Director

Course details

The Annex A controls in the ISO 27001 standard are used by organizations around the world to improve their information security programs and demonstrate good security practices to others. In this second part of his two-part ISO 27001 course, instructor Marc Menninger provides a comprehensive overview of all 93 security controls in Annex A of the ISO 27001 standard. You can use this knowledge to build a better security program and prepare for compliance with the ISO 27001 standard. This course includes handy documents with recommended ways to demonstrate compliance with ISO 27001, providing you with tools you need to get started on implementing the controls to build an ISO 27001-compliant cybersecurity program.

Note: It is recommended that you start with part one, ISO 27001:2022-Compliant Cybersecurity: Getting Started, which includes background information and compliance requirements you need to know if you're serious about building an ISO 27001-compliant cybersecurity program.

Skills covered

Governance, Risk, and ComplianceIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

0. Introduction

  • 01 - Introduction to the Annex A controls

1. Governance

  • 02 - Policies for information security (Control 5.1)
  • 03 - Roles, responsibilities, and duties (Controls 5.2 5.4)
  • 04 - Contacts and project management (Controls 5.5, 5.6, and 5.8)

2. Asset Management

  • 05 - Responsibility for information assets (Controls 5.9, 5.10, 6.7, and 8.1)
  • 06 - Asset security procedures (Controls 5.11, 5.14, and 5.37)

3. Information Protection

  • 07 - Classification, labeling, and privacy (Controls 5.12, 5.13, and 5.34)
  • 08 - Deletion, masking, DLP, and test data (Controls 8.10 8.12, and 8.33)

4. Identity and Access Management

  • 09 - Access management (Controls 5.15 5.18)
  • 10 - System and application access control (Controls 8.2 8.5)

5. Supplier Relationships Security

  • 11 - Supplier relationships security (Controls 5.19 5.21)
  • 12 - Managing supplier service delivery and cloud services security (Controls 5.22 and 5.23)

6. Information Security Event Management

  • 13 - Information security incident management (Controls 5.24 5.28, and 6.8)
  • 14 - Logging and monitoring (Controls 8.15 8.17)

7. Continuity

  • 15 - Continuity (Controls 5.29, 5.30, and 8.13)
  • 16 - Backup and availability (Controls 8.13 and 8.14)

8. Legal, Compliance, and Security Assurance

  • 17 - Legal and compliance (Controls 5.31 5.33)
  • 18 - Information security assurance (Control 5.35 and 5.36)

9. Human Resource Security

  • 19 - Prior to employment (Controls 6.1 and 6.2)
  • 20 - During employment (Controls 6.3 6.6)

10. Physical Security

  • 21 - Ensuring authorized access (Controls 7.1 7.3)
  • 22 - Protecting secure areas (Controls 7.4 7.6)
  • 23 - Equipment security (Controls 7.7 7.10)
  • 24 - Utilities, cabling, and equipment management (Controls 7.11 7.14)

11. System and Network Security

  • 25 - Network security management (Controls 8.20 8.23)
  • 26 - Protection of information systems (Controls 8.7, 8.18, 8.30, and 8.34)

12. Threat and Vulnerability Management and Secure Configuration

  • 27 - Threat and vulnerability management (Controls 5.7 and 8.8)
  • 28 - Secure configuration (Controls 8.9, 8.19, and 8.24)

13. Application Security

  • 29 - Secure development (Controls 8.25 8.28)
  • 30 - Testing, separate environments, and change management (Controls 8.29, 8.31, and 8.32)

Conclusion

  • 31 - Achieving ISO 27001 compliance

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal