Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO 27001 Compliance Software

International standard for information security management systems (ISMS) covering Management System Clauses and Annex A controls across Organisational, People, Physical and Technological domains.

Framework at a glance

Short name

ISO 27001

Version

2022

Category

Information Security

Controls

93

What ISO 27001 covers

93 controls across 13 domains — every one tracked, owned and evidenced in Cyber Horizon.

Organizational

23 controls
  • A.5.1 Policies for information security
  • A.5.2 Information security roles and responsibilities
  • A.5.3 Segregation of duties
  • A.5.4 Management responsibilities
  • A.5.5 Contact with authorities

Incident Management

5 controls
  • A.5.24 Information security incident management planning and preparation
  • A.5.25 Assessment and decision on information security events
  • A.5.26 Response to information security incidents
  • A.5.27 Learning from information security incidents
  • A.5.28 Collection of evidence

Business Continuity

2 controls
  • A.5.29 Information security during disruption
  • A.5.30 ICT readiness for business continuity

Compliance

4 controls
  • A.5.31 Legal, statutory, regulatory and contractual requirements
  • A.5.32 Intellectual property rights
  • A.5.33 Protection of records
  • A.5.36 Compliance with policies, rules and standards for information security

Privacy

1 controls
  • A.5.34 Privacy and protection of personal identifiable information (PII)

Audit

1 controls
  • A.5.35 Independent review of information security

Operations

1 controls
  • A.5.37 Documented operating procedures

People

8 controls
  • A.6.1 Screening
  • A.6.2 Terms and conditions of employment
  • A.6.3 Information security awareness, education and training
  • A.6.4 Disciplinary process
  • A.6.5 Responsibilities after termination or change of employment

Physical

9 controls
  • A.7.1 Physical security perimeters
  • A.7.2 Physical entry
  • A.7.3 Securing offices, rooms and facilities
  • A.7.4 Physical security monitoring
  • A.7.5 Protecting against physical and environmental threats

Media Management

1 controls
  • A.7.10 Storage media

Infrastructure

2 controls
  • A.7.11 Supporting utilities
  • A.7.12 Cabling security

Asset Management

2 controls
  • A.7.13 Equipment maintenance
  • A.7.14 Secure disposal or re-use of equipment

Technological

34 controls
  • A.8.1 User endpoint devices
  • A.8.2 Privileged access rights
  • A.8.3 Information access restriction
  • A.8.4 Access to source code
  • A.8.5 Secure authentication

How Cyber Horizon automates ISO 27001

Every ISO 27001 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO 27001?

International standard for information security management systems (ISMS) covering Management System Clauses and Annex A controls across Organisational, People, Physical and Technological domains.

How many controls does ISO 27001 have?

ISO 27001 (2022) has 93 controls in Cyber Horizon's catalogue, organised across 13 domains.

How does Cyber Horizon help with ISO 27001?

Cyber Horizon maps ISO 27001 into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27001 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 27001 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27001 in Cyber Horizon.