NixFleet

ISO 27001:2022 - Annex A mapping

Annex A controls across A.5 (organisational) and A.8 (technological).

ISO/IEC 27001:2022 Annex A is the cross-sector certification reference. The Annex A controls covered by nixfleet-compliance fall in clauses A.5 (organisational) and A.8 (technological).

Annex ATitleControls
A.5.9Inventory of assets_asset-inventory
A.5.19, A.5.21Supplier relationships / supply chain_supply-chain
A.5.24, A.5.26Incident management_incident-response
A.5.29, A.5.30Continuity / ICT readiness_disaster-recovery
A.8.2, A.8.3Privileged access / access restriction_access-control
A.8.5Secure authentication_authentication
A.8.8Management of technical vulnerabilities_vulnerability-mgmt, _baseline-hardening
A.8.9Configuration management_baseline-hardening
A.8.13Information backup_backup-retention
A.8.15, A.8.16Logging / monitoring_audit-logging
A.8.20, A.8.24Network security / cryptography_encryption-in-transit
A.8.24Use of cryptography_encryption-at-rest, _key-management
A.8.32Change management_change-management

Canonical control source: docs/iso27001-mapping.md in the compliance repo.

← Back to compliance