GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"

ISO 27001 Incident Management Controls for Response and Records

iso 27001 incident management controls for response and records

A ransomware note on a Tuesday morning does not care whether your organization has a documented incident response policy. What it cares about is whether your team already knows who has authority to isolate a subnet, who calls outside counsel, and who starts the clock on regulatory notification. ISO/IEC 27001:2022 addresses that gap through five […]

ISO 27001 Cloud Security Controls for Cloud and SaaS Environments

iso 27001 cloud security controls for cloud saas environments

Ninety percent of companies now run some part of their business on cloud applications, according to Bitkom’s 2025 Cloud Report, up from 81 percent the year before. ISO/IEC 27001:2022 responded to that shift with a control that did not exist in the 2013 version: Annex A 5.23, Information Security for Use of Cloud Services. For […]

ISO 27001 Supplier Security Controls for Vendor Risk and Contracts

iso 27001 supplier security controls for vendor risk and contracts

Third-party breaches now account for more than 60% of all data compromises in the United States, according to the Ponemon Institute’s 2024 Cost of a Data Breach Report. Yet most organizations spend the majority of their security budget on internal controls, leaving the supplier ecosystem as the largest unmonitored attack surface in their environment. ISO […]

ISO 27001 Access Control Requirements and Evidence Records

ISO 27001 Access Control Requirements and Evidence Records

Access control failures account for a disproportionate share of data breaches IBM’s 2024 Cost of a Data Breach Report put compromised credentials at the root of nearly one in three incidents. For US organizations pursuing ISO 27001 certification, Annex A 5.15 through 5.18 translate that risk reality into a structured set of requirements that auditors […]

ISO 27001 Technological Controls for Access, Logging and Secure Development

ISO 27001 Technological Controls for Access Logging and Secure Development

ISO 27001:2022 reorganized its control landscape significantly. The 2013 version carried 114 controls across 14 categories; the 2022 revision consolidated and expanded this into 93 controls across four themes: organizational, people, physical, and technological. The technological controls Annex A clauses 8.1 through 8.34 represent the largest single category, covering 34 controls that govern how organizations […]

ISO 27001 Physical Controls for Facilities, Equipment and Secure Areas

ISO 27001 Physical Controls for Facilities Equipment and Secure Areas

Physical security failures account for a significant share of enterprise data breaches yet most ISO 27001 implementations treat physical controls as an afterthought behind firewalls and access policies. The 2022 revision of ISO/IEC 27001 restructured this entirely. Annex A.7 now consolidates all physical and environmental security requirements into a dedicated control domain, covering everything from […]

How Long It Really Takes to Get ISO/IEC 42001 Lead Implementer Certified?

How Long It Really Takes to Get ISOIEC 42001 Lead Implementer Certified

“Why would someone with a corporate communications and ESG/sustainability background suddenly decide to become an AI Governance Lead Implementer & Auditor?” From Sustainability to AI Governance: Why I Decided to Learn How to Govern AI Instead of Competing with It? A year ago, if someone had told me I would be spending my evenings reading […]

ISO 27001 People Controls: Roles, Awareness and Employment Security

iso 27001 people controls roles awareness and employment security

According to Verizon’s 2024 Data Breach Investigations Report, 74% of all breaches involve a human element whether that’s social engineering, misuse of privileges, credential theft, or simple error. ISO/IEC 27001:2022 confronts this reality directly through its people controls, a set of requirements spanning the entire employee lifecycle from pre-hire screening to post-termination access revocation. For […]

ISO 27001 Organizational Controls: Governance, Risk & Suppliers

iso 27001 organizational controls governance risk suppliers

Organizational controls are where ISO 27001 implementation either holds together or falls apart. Of the 93 controls in Annex A of ISO/IEC 27001:2022, 37 fall under the organizational category covering governance structures, information security policies, risk treatment, supplier relationships, incident management, and business continuity. For US organizations pursuing ISMS certification, these controls form the operational […]

ISO 27001 Annex A Controls List: All 93 Controls by Theme

iso 27001 annex a controls list

The 2022 revision of ISO 27001 restructured its control framework from 114 controls across 14 domains into 93 controls organized under four themes and for US-based GRC and information security professionals, that reorganization carries real implications for audit readiness, NIST CSF 2.0 alignment, and certification timelines. Whether you’re scoping an Information Security Management System (ISMS) […]