ISO/IEC 27001:2022
Rendered when the buyer ticks "ISO/IEC 27001 in place". The register cites 10 of its 93 clauses, behind 3 findings: flat network: networked assets with no zone named, no change record on an adaptive or networked asset, vendor share at or above a third, and on the obligation rows of every asset it reaches. Binds the organisation that holds the certificate, through the Annex A controls it declared applicable.
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches on the register: the ISO 27001 regime page.
Clauses cited
10 of 93ISO 27001 5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 8.32 Change managementPut changes to facilities and systems through change management procedures.
Common gap: missing formal approval
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks securitySecure, manage and control networks and network devices.
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.21 Security of network servicesIdentify, implement and monitor security mechanisms and service levels for network services.
Common gap: Out‑of‑date service inventory missing recent cloud assets
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networksSegregate groups of services, users and systems in the network.
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022
See which clauses your list engages
Paste the list and every asset names the clauses behind it, filtered to the regimes that apply to you. Eight assets free, no account.
Build my cell register