ISO/IEC 27001:2022 — Annex A
Every virtue against the Annex A controls of ISO/IEC 27001:2022. Control identifiers link to the ISO catalogue page; strengths are stated as words.
| Virtue | Control | Control title | Strength | Why it maps |
|---|---|---|---|---|
| 義 01 Gi | A.8.24 | Use of cryptography | direct | Cryptographic signatures are how an action is bound to the actor who took it. |
| A.8.15 | Logging | direct | Tamper-evident logs are how a system makes its own conduct provable after the fact. | |
| 勇 02 Yū | A.5.7 | Threat intelligence | direct | Threat intelligence is the raw material for going to look for the archer rather than waiting for the arrow. |
| A.8.16 | Monitoring activities | direct | Monitoring activities cover detection but not proactive hunting beyond configured alerting — that gap is the virtue. | |
| A.5.26 | Response to information security incidents | direct | Responding to incidents is the courage to engage once contact with an adversary is made. | |
| 仁 03 Jin | A.6.3 | Information security awareness, education and training | partial | Training helps people cope with controls; it does not make the controls humane. |
| A.5.10 | Acceptable use of information and assets | partial | Acceptable-use rules govern behaviour but not whether compliance is realistic for the people bound by them. | |
| 礼 04 Rei | A.5.15 | Access control | direct | Access control is the operational form of the virtue. |
| A.5.18 | Access rights | direct | Provisioning and reviewing access rights keeps privilege matched to the role over time. | |
| A.8.2 | Privileged access rights | direct | Constraining privileged access is where surplus privilege does the most damage. | |
| A.8.3 | Information access restriction | direct | Restricting information access enforces need-to-know at the data layer. | |
| 誠 05 Makoto | A.8.24 | Use of cryptography | direct | Hashes and checksums are how a record proves it has not been altered. |
| A.6.8 | Information security event reporting | direct | Event reporting is the channel that lets an uncomfortable truth travel up rather than be buried. | |
| A.8.15 | Logging | direct | Logging preserves a truthful account of what happened for later scrutiny. | |
| 名誉 06 Meiyo | A.5.1 | Policies for information security | direct | A stated policy is the standard a team holds itself to unprompted. |
| A.5.2 | Information security roles and responsibilities | direct | Assigned security responsibilities are the structure accountability hangs on. | |
| A.5.35 | Independent review of information security | direct | Independent review is the outside check that accountability is real and not self-reported. | |
| A.5.36 | Compliance with policies, rules and standards | direct | Verifying compliance with the rules you set is honour made routine. | |
| 忠義 07 Chūgi | A.6.1 | Screening | direct | Screening establishes mutual trust at the point of hire. |
| A.6.2 | Terms and conditions of employment | direct | Employment terms make the obligations of the relationship explicit on both sides. | |
| A.6.4 | Disciplinary process | partial | A disciplinary process addresses breaches, but coerced loyalty produces the insider it was meant to prevent — so the fit is only partial. | |
| A.6.5 | Responsibilities after termination or change of employment | direct | Defining responsibilities that survive a role change keeps the obligation mutual through transitions. | |
| 自制 08 Jisei | A.8.32 | Change management | direct | Change management is the virtue's core: every change deliberate, every deployment reversible. |
| A.8.9 | Configuration management | direct | Configuration management keeps the known-good state defined and enforced. | |
| A.8.31 | Separation of development, test and production environments | direct | Separating development, test and production is the restraint not to change production directly. | |
| A.8.33 | Test information | partial | Controlling test information supports safe change but sits at the edge of the domain. |