Skip to content
Digital Bushido

ISO/IEC 27001:2022 — Annex A

Every virtue against the Annex A controls of ISO/IEC 27001:2022. Control identifiers link to the ISO catalogue page; strengths are stated as words.

ISO/IEC 27001:2022 — Annex ATable scrolls horizontally.
VirtueControlControl titleStrengthWhy it maps
01 GiA.8.24Use of cryptographydirectCryptographic signatures are how an action is bound to the actor who took it.
A.8.15LoggingdirectTamper-evident logs are how a system makes its own conduct provable after the fact.
02 A.5.7Threat intelligencedirectThreat intelligence is the raw material for going to look for the archer rather than waiting for the arrow.
A.8.16Monitoring activitiesdirectMonitoring activities cover detection but not proactive hunting beyond configured alerting — that gap is the virtue.
A.5.26Response to information security incidentsdirectResponding to incidents is the courage to engage once contact with an adversary is made.
03 JinA.6.3Information security awareness, education and trainingpartialTraining helps people cope with controls; it does not make the controls humane.
A.5.10Acceptable use of information and assetspartialAcceptable-use rules govern behaviour but not whether compliance is realistic for the people bound by them.
04 ReiA.5.15Access controldirectAccess control is the operational form of the virtue.
A.5.18Access rightsdirectProvisioning and reviewing access rights keeps privilege matched to the role over time.
A.8.2Privileged access rightsdirectConstraining privileged access is where surplus privilege does the most damage.
A.8.3Information access restrictiondirectRestricting information access enforces need-to-know at the data layer.
05 MakotoA.8.24Use of cryptographydirectHashes and checksums are how a record proves it has not been altered.
A.6.8Information security event reportingdirectEvent reporting is the channel that lets an uncomfortable truth travel up rather than be buried.
A.8.15LoggingdirectLogging preserves a truthful account of what happened for later scrutiny.
名誉 06 MeiyoA.5.1Policies for information securitydirectA stated policy is the standard a team holds itself to unprompted.
A.5.2Information security roles and responsibilitiesdirectAssigned security responsibilities are the structure accountability hangs on.
A.5.35Independent review of information securitydirectIndependent review is the outside check that accountability is real and not self-reported.
A.5.36Compliance with policies, rules and standardsdirectVerifying compliance with the rules you set is honour made routine.
忠義 07 ChūgiA.6.1ScreeningdirectScreening establishes mutual trust at the point of hire.
A.6.2Terms and conditions of employmentdirectEmployment terms make the obligations of the relationship explicit on both sides.
A.6.4Disciplinary processpartialA disciplinary process addresses breaches, but coerced loyalty produces the insider it was meant to prevent — so the fit is only partial.
A.6.5Responsibilities after termination or change of employmentdirectDefining responsibilities that survive a role change keeps the obligation mutual through transitions.
自制 08 JiseiA.8.32Change managementdirectChange management is the virtue's core: every change deliberate, every deployment reversible.
A.8.9Configuration managementdirectConfiguration management keeps the known-good state defined and enforced.
A.8.31Separation of development, test and production environmentsdirectSeparating development, test and production is the restraint not to change production directly.
A.8.33Test informationpartialControlling test information supports safe change but sits at the edge of the domain.