ISO 27001 Technological Controls

    Technical security controls for systems, networks, and applications. Covers 34 controls from access management to secure development.

    Showing 34 controls in Technological Controls

    A.8.1

    User endpoint devices

    To ensure security of information accessed through user endpoint devices.

    A.8.2

    Privileged access rights

    To prevent unauthorized access and compromise of systems through misuse of privileged access rights.

    A.8.3

    Information access restriction

    To ensure authorized access and prevent unauthorized access to information.

    A.8.4

    Access to source code

    To prevent unauthorized access to source code and maintain integrity of code.

    A.8.5

    Secure authentication

    To ensure the authenticity of users and protect against unauthorized access.

    A.8.6

    Capacity management

    To ensure systems perform adequately and ensure required system availability.

    A.8.7

    Protection against malware

    To ensure that information and information processing facilities are protected against malware.

    A.8.8

    Management of technical vulnerabilities

    To prevent exploitation of technical vulnerabilities.

    A.8.9

    Configuration management

    To establish and maintain secure configurations of systems.

    A.8.10

    Information deletion

    To prevent unnecessary retention of information and reduce exposure to unauthorized disclosure.

    A.8.11

    Data masking

    To limit exposure of sensitive data while maintaining usability for testing and development.

    A.8.12

    Data leakage prevention

    To detect and prevent unauthorized transmission of sensitive information.

    A.8.13

    Information backup

    To protect against loss of data and ensure business continuity.

    A.8.14

    Redundancy of information processing facilities

    To ensure availability of critical systems through redundancy.

    A.8.15

    Logging

    To record events and generate evidence for investigation and monitoring.

    A.8.16

    Monitoring activities

    To detect anomalous behavior and potential security incidents.

    A.8.17

    Clock synchronization

    To ensure accuracy of logs and support forensic investigation and audit.

    A.8.18

    Use of privileged utility programs

    To prevent misuse of privileged utilities that could bypass security controls.

    A.8.19

    Installation of software on operational systems

    To prevent unauthorized software installation and maintain system integrity.

    A.8.20

    Networks security

    To ensure the protection of information in networks and supporting information processing facilities.

    A.8.21

    Security of network services

    To ensure the security of network services and the information they carry.

    A.8.22

    Segregation of networks

    To separate networks into security zones based on risk and trust levels.

    A.8.23

    Web filtering

    To manage access to external websites and reduce security risks.

    A.8.24

    Use of cryptography

    To ensure proper and effective use of cryptography to protect confidentiality, authenticity and integrity of information.

    A.8.25

    Secure development life cycle

    To ensure that information security is designed and implemented within the development lifecycle of systems.

    A.8.26

    Application security requirements

    To ensure security is built into applications from requirements through implementation.

    A.8.27

    Secure system architecture and engineering principles

    To ensure systems are designed with security in mind using established security principles.

    A.8.28

    Secure coding

    To prevent security vulnerabilities in application code.

    A.8.29

    Security testing in development and acceptance

    To identify and address security vulnerabilities before production deployment.

    A.8.30

    Outsourced development

    To ensure outsourced development meets security requirements and follows secure practices.

    A.8.31

    Separation of development, test and production environments

    To reduce the risks of unauthorized access or changes to the production environment.

    A.8.32

    Change management

    To ensure changes are made in a controlled manner with minimal disruption and risk.

    A.8.33

    Test information

    To ensure test data does not contain production data that could be exposed.

    A.8.34

    Protection of information systems during audit testing

    To minimize disruption to business processes from audit activities.

    Other Control Categories

    ISO 27001 Technological Controls | ISMS Directory