Cell Register
Regimes · ISO 27001

ISO/IEC 27001:2022

Attaches the supplier and change controls to every asset and the network controls to every connected one.

Who it binds: the organisation that holds the certificate, through the Annex A controls it declared applicable.

On the register, tick "ISO/IEC 27001 in place" and these rows appear on every asset the regime reaches. Source framework page on the compliance graph.

The rows, and when each attaches

Asset owner duty
on every asset
Supplier and change controls on every asset
ISO 27001 5.19 · 5.20 · 5.22 · 8.32
The integrator and the maintenance provider are suppliers; the change to a machine is a change.
Asset owner duty
where the asset is networked
Network controls where the asset is on a network
ISO 27001 5.21 · 8.9 · 8.20 · 8.21 · 8.22
Network security, the services on it, segregation and a secure configuration baseline attach to any connected asset; the ICT supply chain control attaches to what the supplier delivers into it.
Asset owner duty
where a vendor cloud manages it
Where a fleet or model is managed from a vendor cloud
ISO 27001 5.23
A fleet manager or a model service hosted by the vendor is a cloud service: acquisition, use and exit are governed.
On the register as a wholeISO 27001 5.19 · 8.22

On the floor

The integrator and the maintenance provider are suppliers, a change to a machine is a change, and a connected controller is on the network: the supplier, change and network controls attach on the register the way they do to any other asset. Where a fleet or a model is managed from a vendor cloud, the cloud services control attaches too.

The clauses, quoted

10 of 93 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 8.32 Change management

Put changes to facilities and systems through change management procedures.

Evidence an auditor accepts: change_requests; change_approvals; implementation_testing
Common gap: missing formal approval
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

Evidence an auditor accepts: network_topology_diagrams; firewall_rule_sets; network_access_control_lists
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.21 Security of network services

Identify, implement and monitor security mechanisms and service levels for network services.

Evidence an auditor accepts: network_service_inventory; service_security_configurations; monitoring_and_logging
Common gap: Out‑of‑date service inventory missing recent cloud assets
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

Evidence an auditor accepts: network_segmentation_policy; network_topology_diagrams; firewall_rule_set_documents
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

Evidence an auditor accepts: baseline_configurations; change_control_records; configuration_audit_reports
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: supplier_security_requirements; contractual_security_clauses; supply_chain_risk_assessments
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: cloud_service_selection; cloud_contract_management; cloud_security_monitoring
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022

See what it attaches to your list

Paste the equipment list, tick the regime, and every asset it reaches carries these rows. Eight assets free, no account.

Build my cell register