Your checklists (
0
)
AI Checklist Generator
From the makers of
Manifestly Checklists
Sign in
Email address
Email me a magic link
Home
> ISO 27001 Annex A controls requirement
ISO 27001 Annex A controls requirement
Information Security Policy
Organization of Information Security
Define the roles and responsibilities for information security
Establish an information security management framework
Implement information security awareness, education, and training programs
Asset Management
Identify assets that need to be protected
Classify assets based on their value and sensitivity
Ensure proper handling and disposal of assets
Human Resources Security
Conduct background checks on employees
Define and communicate information security responsibilities to employees
Provide security training to employees
Physical and Environmental Security
Communications and Operations Management
Monitor and control access to information systems
Ensure the availability of information systems
Implement procedures for the secure handling of information
Access Control
Restrict access to information based on user roles and responsibilities
Implement user authentication mechanisms
Monitor and log access to information systems
Cryptography
Use encryption to protect sensitive information
Ensure the integrity and authenticity of cryptographic keys
Implement procedures for the secure use of cryptography
Security Incident Management
Establish an incident response team
Define procedures for reporting and responding to security incidents
Conduct post-incident reviews to identify areas for improvement
Business Continuity Management
Develop a business continuity plan
Test the plan regularly to ensure its effectiveness
Update the plan based on lessons learned from tests and incidents
Compliance
Monitor compliance with legal and regulatory requirements
Conduct internal audits of information security controls
Report on the effectiveness of information security controls to management
Download CSV
Download JSON
Download Markdown
Use in Manifestly