+91 88795 82623

Latest Articles on ISO 27001

Structure of ISO 27001:2013

By CUNIX Team
Structure of ISO 27001:2013

Controls (Annex A)

A.5: Information Security Policies – Controlling how policies are written and revised

A.6: Information Security Organization â€“ Controls on how responsibilities are assigned; also includes controls for mobile devices

A.7: Human Resources Security â€“ Pre-employment, during and after employment controls

A.8: Asset management â€“ Asset inventory and acceptable use controls; also for information classification and media management

A.9: Access control â€“ Access control policy, user access management, system and application access control

A.10: Cryptography â€“ Encryption and Key Management Controls

A.11: Physical and environmental security â€“ Controls defining secure areas, entry controls, protection against threats, security of the equipment, secure removal, clear desk and clear screen policy, etc.

A.12: Operational security – Procedures and responsibilities, malware, backup, logging, monitoring, installation, vulnerability etc.

A.13: Communications Security â€“ Network security, information transfer, e-mail security checks etc.

A.14: Acquisition, development and maintenance of the system â€“ Controls defining security requirements and security in the development and support processes

A.15: Vendor Relations â€“ Controls on what to include in agreements and how to monitor suppliers

A.16: Information Security Incident Management â€“ Controls to signal events and weaknesses, define responsibilities, assessment of events, response and learn from incidents and collection of evidences.

A.17: Aspects of information security in the management of continuity of operations â€“ Controlling the planning, implementation and review of the continuity of information security operations.

A.18: Compliance â€“ Controls Requiring the Identification of Applicable Laws and Regulations, Protection of Intellectual Property, Protection of Personal Data and Examination of the Security of Personal Information

One of the biggest myths about ISO 27001 implementation is that it is computer-centric. On the contrary it involves various aspects as mentioned above in Annexure.

Controls mentioned in Appendix A are essential part of ISO 27001 Implementation. As per the risk assessment, an organization can decide the applicability of the controls with valid rationale.

Tags:#iso 27001
Share:

Related Articles

Why AI-First Companies Cannot Afford to Ignore ISO 27001
Latest Articles on ISO 27001

March 6, 2026 · CUNIX Team

Why AI-First Companies Cannot Afford to Ignore ISO 27001

Artificial Intelligence is no longer a future promise — it is the backbone of products, decisions, and business models across every sector. From AI-powered diagnostics in healthcare to large language models embedded in fintech platforms, AI companies in India and globally are processing extraordinary volumes of sensitive data every single day. Yet, as the AI […]

Read Article
Understanding the ISO 27001 Certification Process in India
Latest Articles on ISO 27001

January 16, 2026 · CUNIX Team

Understanding the ISO 27001 Certification Process in India

In an era where data breaches and cyber threats are rising, protecting sensitive information has become a top priority for every organization. That’s where the ISO 27001 certification process in India comes in a globally recognized framework designed to secure your business data and strengthen trust. ISO 27001 is the globally recognized standard for establishing, […]

Read Article
How to Get ISO 27001 Certification in India: A Practical, Step-by-Step Guide
Latest Articles on ISO 27001

October 27, 2025 · CUNIX Team

How to Get ISO 27001 Certification in India: A Practical, Step-by-Step Guide

For Indian organizations, ISO 27001 certification is the most credible way to prove information security maturity, win enterprise deals, and comply with customer, regulatory, and partner expectations. Certification is achieved through establishing an ISMS, implementing controls based on risk, and passing a two-stage external audit by an accredited certification body in India, followed by annual […]

Read Article