Cell Register
Standards · ISO 27001

ISO/IEC 27001:2022

Rendered when the buyer ticks "ISO/IEC 27001 in place". The register cites 10 of its 93 clauses, behind 3 findings: flat network: networked assets with no zone named, no change record on an adaptive or networked asset, vendor share at or above a third, and on the obligation rows of every asset it reaches. Binds the organisation that holds the certificate, through the Annex A controls it declared applicable.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches on the register: the ISO 27001 regime page.

Clauses cited

10 of 93
ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 8.32 Change management

Put changes to facilities and systems through change management procedures.

Evidence an auditor accepts: change_requests; change_approvals; implementation_testing
Common gap: missing formal approval
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

Evidence an auditor accepts: network_topology_diagrams; firewall_rule_sets; network_access_control_lists
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.21 Security of network services

Identify, implement and monitor security mechanisms and service levels for network services.

Evidence an auditor accepts: network_service_inventory; service_security_configurations; monitoring_and_logging
Common gap: Out‑of‑date service inventory missing recent cloud assets
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

Evidence an auditor accepts: network_segmentation_policy; network_topology_diagrams; firewall_rule_set_documents
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

Evidence an auditor accepts: baseline_configurations; change_control_records; configuration_audit_reports
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: supplier_security_requirements; contractual_security_clauses; supply_chain_risk_assessments
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: cloud_service_selection; cloud_contract_management; cloud_security_monitoring
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022

See which clauses your list engages

Paste the list and every asset names the clauses behind it, filtered to the regimes that apply to you. Eight assets free, no account.

Build my cell register