Analyze/catalog/frameworks/iso-27001.json

{
  "key": "ISO 27001",
  "order": 5,
  "name": "ISO/IEC 27001 Information security management systems",
  "shortName": "ISO 27001:2022",
  "version": "2022 (Annex A controls)",
  "publisher": "ISO/IEC",
  "type": "standard",
  "url": "https://www.iso.org/standard/27001",
  "retrieved": "2026-09-24",
  "mapping": "jsolve",
  "note": "Mapping by JSolve B.V.: which tests evidence a control is JSolve's assessment, not the publisher's. A control with tests is fully assessed only when they check everything about it that Azure configuration can show. Controls that do not concern the Azure environment (people, physical security, organization-wide governance, end-user devices, software development) are not applicable; the other controls without a test need evidence outside configuration. Control titles are the Annex A headings.",
  "controls": {
    "A.5.1": {"title":"Policies for information security","applicability":"notApplicable"},
    "A.5.2": {"title":"Information security roles and responsibilities","applicability":"notApplicable"},
    "A.5.3": {"title":"Segregation of duties","applicability":"manual"},
    "A.5.4": {"title":"Management responsibilities","applicability":"notApplicable"},
    "A.5.5": {"title":"Contact with authorities","applicability":"notApplicable"},
    "A.5.6": {"title":"Contact with special interest groups","applicability":"notApplicable"},
    "A.5.7": {"title":"Threat intelligence","applicability":"notApplicable"},
    "A.5.8": {"title":"Information security in project management","applicability":"notApplicable"},
    "A.5.9": {"title":"Inventory of information and other associated assets","coverage":"partial","tests":["AZ-GOV-006","AZ-GOV-007","AZ-GOV-011","AZ-VM-013"]},
    "A.5.10": {"title":"Acceptable use of information and other associated assets","applicability":"notApplicable"},
    "A.5.11": {"title":"Return of assets","applicability":"notApplicable"},
    "A.5.12": {"title":"Classification of information","coverage":"partial","tests":["AZ-DEF-024"]},
    "A.5.13": {"title":"Labelling of information","applicability":"manual"},
    "A.5.14": {"title":"Information transfer","coverage":"partial","tests":["AZ-APIM-002","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-BCK-005","AZ-BOT-003","AZ-CAPP-001","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-STG-001","AZ-STG-002","AZ-STG-010","AZ-STG-018","AZ-STG-019"]},
    "A.5.15": {"title":"Access control","coverage":"partial","tests":["AZ-ACR-002","AZ-AKS-002","AZ-APIM-004","AZ-APP-009","AZ-COS-003","AZ-GOV-005","AZ-IAM-008","AZ-IAM-010","AZ-IAM-023","AZ-KV-002","AZ-KV-009","AZ-MSG-001","AZ-STG-003","AZ-STG-004"]},
    "A.5.16": {"title":"Identity management","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-004","AZ-ACR-005","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-AKS-008","AZ-APP-004","AZ-APP-006","AZ-AUTO-002","AZ-BOT-002","AZ-COS-001","AZ-IAM-006","AZ-IAM-007","AZ-IAM-020","AZ-IAM-022","AZ-MSG-001","AZ-MY-003","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011","AZ-STG-023"]},
    "A.5.17": {"title":"Authentication information","coverage":"partial","tests":["AZ-ADF-001","AZ-AKS-008","AZ-APIM-003","AZ-APP-006","AZ-AUTO-001","AZ-AUTO-002","AZ-IAM-013","AZ-IAM-014","AZ-IAM-022","AZ-KV-006","AZ-KV-011","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-STG-012","AZ-STG-013","AZ-STG-024"]},
    "A.5.18": {"title":"Access rights","coverage":"partial","tests":["AZ-IAM-004","AZ-IAM-005","AZ-IAM-006","AZ-IAM-007","AZ-IAM-020"]},
    "A.5.19": {"title":"Information security in supplier relationships","coverage":"partial","tests":["AZ-IAM-021","AZ-IAM-025"]},
    "A.5.20": {"title":"Addressing information security within supplier agreements","applicability":"manual"},
    "A.5.21": {"title":"Managing information security in the ICT supply chain","applicability":"manual"},
    "A.5.22": {"title":"Monitoring, review and change management of supplier services","applicability":"manual"},
    "A.5.23": {"title":"Information security for use of cloud services","applicability":"manual"},
    "A.5.24": {"title":"Information security incident management planning and preparation","coverage":"partial","tests":["AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021"]},
    "A.5.25": {"title":"Assessment and decision on information security events","coverage":"partial","tests":["AZ-DEF-022"]},
    "A.5.26": {"title":"Response to information security incidents","coverage":"partial","tests":["AZ-DEF-022"]},
    "A.5.27": {"title":"Learning from information security incidents","applicability":"notApplicable"},
    "A.5.28": {"title":"Collection of evidence","applicability":"manual"},
    "A.5.29": {"title":"Information security during disruption","applicability":"manual"},
    "A.5.30": {"title":"ICT readiness for business continuity","coverage":"partial","tests":["AZ-BCK-010","AZ-BCK-011","AZ-LOG-013"]},
    "A.5.31": {"title":"Legal, statutory, regulatory and contractual requirements","applicability":"notApplicable"},
    "A.5.32": {"title":"Intellectual property rights","applicability":"notApplicable"},
    "A.5.33": {"title":"Protection of records","coverage":"partial","tests":["AZ-BCK-002","AZ-STG-025","AZ-STG-026"]},
    "A.5.34": {"title":"Privacy and protection of PII","applicability":"notApplicable"},
    "A.5.35": {"title":"Independent review of information security","applicability":"notApplicable"},
    "A.5.36": {"title":"Compliance with policies, rules and standards for information security","coverage":"partial","tests":["AZ-GOV-001","AZ-GOV-002","AZ-GOV-003","AZ-GOV-009"]},
    "A.5.37": {"title":"Documented operating procedures","applicability":"manual"},
    "A.6.1": {"title":"Screening","applicability":"notApplicable"},
    "A.6.2": {"title":"Terms and conditions of employment","applicability":"notApplicable"},
    "A.6.3": {"title":"Information security awareness, education and training","applicability":"notApplicable"},
    "A.6.4": {"title":"Disciplinary process","applicability":"notApplicable"},
    "A.6.5": {"title":"Responsibilities after termination or change of employment","applicability":"notApplicable"},
    "A.6.6": {"title":"Confidentiality or non-disclosure agreements","applicability":"notApplicable"},
    "A.6.7": {"title":"Remote working","applicability":"notApplicable"},
    "A.6.8": {"title":"Information security event reporting","applicability":"notApplicable"},
    "A.7.1": {"title":"Physical security perimeters","applicability":"notApplicable"},
    "A.7.2": {"title":"Physical entry","applicability":"notApplicable"},
    "A.7.3": {"title":"Securing offices, rooms and facilities","applicability":"notApplicable"},
    "A.7.4": {"title":"Physical security monitoring","applicability":"notApplicable"},
    "A.7.5": {"title":"Protecting against physical and environmental threats","applicability":"notApplicable"},
    "A.7.6": {"title":"Working in secure areas","applicability":"notApplicable"},
    "A.7.7": {"title":"Clear desk and clear screen","applicability":"notApplicable"},
    "A.7.8": {"title":"Equipment siting and protection","applicability":"notApplicable"},
    "A.7.9": {"title":"Security of assets off-premises","applicability":"notApplicable"},
    "A.7.10": {"title":"Storage media","applicability":"notApplicable"},
    "A.7.11": {"title":"Supporting utilities","applicability":"notApplicable"},
    "A.7.12": {"title":"Cabling security","applicability":"notApplicable"},
    "A.7.13": {"title":"Equipment maintenance","applicability":"notApplicable"},
    "A.7.14": {"title":"Secure disposal or re-use of equipment","applicability":"notApplicable"},
    "A.8.1": {"title":"User endpoint devices","coverage":"partial","tests":["AZ-IAM-030"]},
    "A.8.2": {"title":"Privileged access rights","coverage":"partial","tests":["AZ-AKS-005","AZ-BCK-003","AZ-IAM-001","AZ-IAM-002","AZ-IAM-003","AZ-IAM-009","AZ-IAM-011","AZ-IAM-012","AZ-IAM-015","AZ-IAM-016","AZ-IAM-017","AZ-IAM-018","AZ-IAM-019","AZ-IAM-021","AZ-IAM-028"]},
    "A.8.3": {"title":"Information access restriction","coverage":"partial","tests":["AZ-ACR-002","AZ-AKS-002","AZ-APIM-004","AZ-APP-009","AZ-COS-003","AZ-GOV-005","AZ-IAM-008","AZ-IAM-010","AZ-IAM-023","AZ-KV-002","AZ-KV-009","AZ-MSG-001","AZ-STG-003","AZ-STG-004"]},
    "A.8.4": {"title":"Access to source code","applicability":"notApplicable"},
    "A.8.5": {"title":"Secure authentication","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-004","AZ-ACR-005","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-APP-004","AZ-BOT-002","AZ-COS-001","AZ-IAM-024","AZ-IAM-026","AZ-IAM-027","AZ-IAM-029","AZ-IAM-030","AZ-MSG-001","AZ-MY-003","AZ-NET-021","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011","AZ-STG-023","AZ-VM-004"]},
    "A.8.6": {"title":"Capacity management","coverage":"partial","tests":["AZ-GOV-012"]},
    "A.8.7": {"title":"Protection against malware","coverage":"partial","tests":["AZ-DEF-002","AZ-DEF-014","AZ-DEF-025","AZ-DFA-001","AZ-VM-003","AZ-VM-006"]},
    "A.8.8": {"title":"Management of technical vulnerabilities","coverage":"partial","tests":["AZ-AKS-006","AZ-APIM-007","AZ-DEF-001","AZ-DEF-003","AZ-DEF-008","AZ-DEF-009","AZ-DEF-015","AZ-DEF-017","AZ-DFA-002","AZ-DFA-003","AZ-GOV-008","AZ-GOV-010","AZ-SQL-009","AZ-VM-005","AZ-VM-009"]},
    "A.8.9": {"title":"Configuration management","coverage":"partial","tests":["AZ-AKS-004","AZ-APIM-001","AZ-APP-003","AZ-APP-005","AZ-APP-007","AZ-DEF-001","AZ-DFA-004","AZ-GOV-001","AZ-GOV-002","AZ-GOV-009","AZ-NET-014","AZ-NET-022","AZ-VM-003","AZ-VM-007","AZ-VM-013"]},
    "A.8.10": {"title":"Information deletion","coverage":"partial","tests":["AZ-GOV-006"]},
    "A.8.11": {"title":"Data masking","coverage":"partial","tests":["AZ-SQL-010"]},
    "A.8.12": {"title":"Data leakage prevention","coverage":"partial","tests":["AZ-AI-003","AZ-AI-006","AZ-BCK-005","AZ-NET-007","AZ-STG-010","AZ-SYN-001"]},
    "A.8.13": {"title":"Information backup","coverage":"partial","tests":["AZ-BCK-001","AZ-BCK-002","AZ-BCK-003","AZ-BCK-004","AZ-BCK-005","AZ-BCK-006","AZ-BCK-007","AZ-BCK-008","AZ-BCK-009","AZ-BCK-010","AZ-GOV-004","AZ-STG-014","AZ-STG-015","AZ-STG-016","AZ-STG-017","AZ-STG-022","AZ-VM-010"]},
    "A.8.14": {"title":"Redundancy of information processing facilities","coverage":"partial","tests":["AZ-BCK-004","AZ-BCK-007","AZ-BCK-009","AZ-BCK-011","AZ-BCK-012","AZ-STG-022"]},
    "A.8.15": {"title":"Logging","coverage":"partial","tests":["AZ-DBX-005","AZ-LOG-001","AZ-LOG-002","AZ-LOG-014","AZ-LOG-015","AZ-LOG-016","AZ-LOG-017","AZ-LOG-018","AZ-LOG-019","AZ-LOG-020","AZ-LOG-021","AZ-LOG-022","AZ-LOG-023","AZ-LOG-024","AZ-LOG-025","AZ-LOG-026","AZ-MY-002","AZ-NET-024","AZ-NET-025","AZ-PG-002","AZ-PG-003","AZ-SQL-001","AZ-SQL-002","AZ-VM-008"]},
    "A.8.16": {"title":"Monitoring activities","coverage":"partial","tests":["AZ-BCK-006","AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-016","AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021","AZ-DEF-023","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012","AZ-LOG-013","AZ-LOG-017","AZ-LOG-018","AZ-LOG-020","AZ-LOG-023","AZ-LOG-025","AZ-NET-020","AZ-NET-024","AZ-NET-025"]},
    "A.8.17": {"title":"Clock synchronisation","applicability":"manual"},
    "A.8.18": {"title":"Use of privileged utility programs","coverage":"partial","tests":["AZ-AKS-005"]},
    "A.8.19": {"title":"Installation of software on operational systems","applicability":"manual"},
    "A.8.20": {"title":"Networks security","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-ADX-001","AZ-AI-002","AZ-AI-003","AZ-AI-005","AZ-AI-006","AZ-AI-007","AZ-AKS-003","AZ-AKS-007","AZ-APP-008","AZ-AVD-001","AZ-BOT-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-DBX-006","AZ-GOV-007","AZ-KV-003","AZ-KV-004","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-007","AZ-NET-008","AZ-NET-009","AZ-NET-010","AZ-NET-011","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-NET-019","AZ-NET-020","AZ-NET-021","AZ-NET-022","AZ-NET-023","AZ-PAAS-001","AZ-SQL-005","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-SYN-001","AZ-VM-011","AZ-VM-012"]},
    "A.8.21": {"title":"Security of network services","coverage":"partial","tests":["AZ-NET-010","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-NET-019","AZ-NET-020"]},
    "A.8.22": {"title":"Segregation of networks","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-ADX-001","AZ-AI-002","AZ-AI-005","AZ-AI-007","AZ-AKS-003","AZ-AKS-007","AZ-APP-008","AZ-AVD-001","AZ-BOT-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-DBX-006","AZ-KV-003","AZ-KV-004","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-008","AZ-NET-009","AZ-PAAS-001","AZ-SQL-005","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-VM-011","AZ-VM-012"]},
    "A.8.23": {"title":"Web filtering","coverage":"partial","tests":["AZ-NET-019"]},
    "A.8.24": {"title":"Use of cryptography","coverage":"partial","tests":["AZ-ADX-002","AZ-ADX-003","AZ-AKS-009","AZ-APIM-002","AZ-APIM-005","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-AUTO-001","AZ-BOT-003","AZ-CAPP-001","AZ-KV-001","AZ-KV-005","AZ-KV-007","AZ-KV-008","AZ-KV-010","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-SQL-007","AZ-SQL-008","AZ-STG-001","AZ-STG-002","AZ-STG-018","AZ-STG-019","AZ-STG-020","AZ-STG-021","AZ-VM-001","AZ-VM-002"]},
    "A.8.25": {"title":"Secure development life cycle","applicability":"notApplicable"},
    "A.8.26": {"title":"Application security requirements","applicability":"notApplicable"},
    "A.8.27": {"title":"Secure system architecture and engineering principles","applicability":"notApplicable"},
    "A.8.28": {"title":"Secure coding","applicability":"notApplicable"},
    "A.8.29": {"title":"Security testing in development and acceptance","applicability":"notApplicable"},
    "A.8.30": {"title":"Outsourced development","applicability":"notApplicable"},
    "A.8.31": {"title":"Separation of development, test and production environments","applicability":"manual"},
    "A.8.32": {"title":"Change management","coverage":"partial","tests":["AZ-ADF-002"]},
    "A.8.33": {"title":"Test information","applicability":"notApplicable"},
    "A.8.34": {"title":"Protection of information systems during audit testing","applicability":"notApplicable"}
  }
}