|
4 Organisational Context Controls
|
|
4.1 - Understanding the organisation External and Internal Issues;
|
Control - Information security Internal and External Issues and topic-specific risk assessments shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.
Purpose - To ensure continuing suitability, adequacy, effectiveness of management direction and support for information security in accordance with business, legal, statutory, regulatory and contractual requirements.
Guidance - At the highest level, the organization should define an “information security Pestle and SWOT” which is approved by top management and which sets out the organization’s approach to managing its information security accoding to the identifyed Risks. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, Policies 4.1, Audit 9.2 and Management Review 9.3.
|
|
4.2 - Understanding the needs and expectations of interested parties
|
Control - Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of interested parties/supplier’s products or services.
Purpose - To maintain an agreed level of information security in supplier relationships.
Guidance - The organization should establish and communicate a topic-specific policy on supplier relationships to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
4.2.2 - Legal and Regulatory Requirements
|
Control - implement and maintain a process to identify, have access to, and assess the applicable legal and regulatory requirements related to the continuity of its products and services, activities and resources.
Purpose - To reduce the risk of fraud, error and bypassing of information security controls.
Guidance - Segregation of duties and areas of responsibility aims to separate conflicting duties between different individuals in order to prevent one individual from executing potential conflicting duties on their own. The organization should determine which duties and areas of responsibility need to be segregated. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System Policies, ISO 27001:2022, ISO 27002:2022, 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
4.3.2 - Principles of Security and resilience of its Security management systems
|
Control - Management shall require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.
Purpose - To ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.
Guidance - Management should demonstrate support of the information security policy, topic-specific policies, procedures and information security controls. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
4.4 - Scope of Business Activities.
|
Control - ACI Global understands that Consistent and predictable results are achieved more effectively and efficiently when activities are planned and managed as interrelated processes that function as a coherent system. To do this ACI Global has adopted the process approach when developing, implementing, and improving the effectiveness of its Business "Quality" management system.
Purpose - To ensure appropriate flow of information takes place with respect to information security between the organization and relevant legal, regulatory and supervisory authorities.
Guidance - The organization should specify when and by whom authorities (e.g. law enforcement, regulatory bodies, supervisory authorities) should be contacted and how identified information security incidents should be reported in a timely manner. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
4.5 - Management System and Processes for educational organisations.
|
Control - The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.
Purpose - To ensure appropriate flow of information takes place with respect to information security.
Guidance - Membership of special interest groups or forums should be considered as a means to achieve conformance. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
4.6 - Compliance obligations.
|
Control - Information relating to information security threats shall be collected and analysed to produce threat intelligence.
Purpose - To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken.
Guidance - Information about existing or emerging threats is collected and analysed in order to as required. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
4.7 - Compliance risk assessment.
|
Control - Information security shall be integrated into project management.
Purpose - To ensure information security risks related to projects and deliverables are effectively addressed in project management throughout the project life cycle.
Guidance - Information security should be integrated into project management to ensure information security risks are addressed as part of the project management. This can be applied to any type of project regardless of its complexity, size, duration, discipline or application area (e.g. a project for a core business process, ICT, facility management or other supporting processes). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5 Organisational Controls
|
|
5.1 - Policies for information security
|
Control - Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.
Purpose - To ensure continuing suitability, adequacy, effectiveness of management direction and support for information security in accordance with business, legal, statutory, regulatory and contractual requirements.
Guidance - At the highest level, the organization should define an “information security policy” which is approved by top management and which sets out the organization’s approach to managing its information security. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Audit 9.2 and Management Review 9.3.
|
|
5.2 - Information security roles and responsibilities
|
Control - Information security roles and responsibilities shall be defined and allocated according to the organization needs.
Purpose - To establish a defined, approved and understood structure for the implementation, operation and management of information security within the organization.
Guidance - Allocation of information security roles and responsibilities should be done in accordance with the information security policy and topic-specific policies (see 5.1). The organization should define and manage responsibilities so as to conform. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
5.3 - Segregation of duties
|
Control - Conflicting duties and conflicting areas of responsibility shall be segregated.
Purpose - To reduce the risk of fraud, error and bypassing of information security controls.
Guidance - Segregation of duties and areas of responsibility aims to separate conflicting duties between different individuals in order to prevent one individual from executing potential conflicting duties on their own. The organization should determine which duties and areas of responsibility need to be segregated. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System Policies, ISO 27001:2022, ISO 27002:2022, 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
5.4 - Management responsibilities
|
Control - Management shall require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.
Purpose - To ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.
Guidance - Management should demonstrate support of the information security policy, topic-specific policies, procedures and information security controls. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
5.5 - Contact with authorities
|
Control - The organization shall establish and maintain contact with relevant authorities.
Purpose - To ensure appropriate flow of information takes place with respect to information security between the organization and relevant legal, regulatory and supervisory authorities.
Guidance - The organization should specify when and by whom authorities (e.g. law enforcement, regulatory bodies, supervisory authorities) should be contacted and how identified information security incidents should be reported in a timely manner. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
5.6 - Contact with special interest groups
|
Control - The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.
Purpose - To ensure appropriate flow of information takes place with respect to information security.
Guidance - Membership of special interest groups or forums should be considered as a means to achieve conformance. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Policies 5.2, Roles and Resposibilities 5.3, Audit 9.2 and Management Review 9.3.
|
|
5.7 - Threat intelligence
|
Control - Information relating to information security threats shall be collected and analysed to produce threat intelligence.
Purpose - To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken.
Guidance - Information about existing or emerging threats is collected and analysed in order to as required. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.8 - Information security in project management
|
Control - Information security shall be integrated into project management.
Purpose - To ensure information security risks related to projects and deliverables are effectively addressed in project management throughout the project life cycle.
Guidance - Information security should be integrated into project management to ensure information security risks are addressed as part of the project management. This can be applied to any type of project regardless of its complexity, size, duration, discipline or application area (e.g. a project for a core business process, ICT, facility management or other supporting processes). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.9 - Inventory of information and other associated assets
|
Control - An inventory of information and other associated assets, including owners, shall be developed and maintained.
Purpose - To identify the organization’s information and other associated assets in order to preserve their information security and assign appropriate ownership.
Guidance - The organization should identify its information and other associated assets and determine their importance in terms of information security. Documentation should be maintained in dedicated or existing inventories as appropriate. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.10 - Acceptable use of information and other associated assets
|
Control - Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented.
Purpose - To ensure information and other associated assets are appropriately protected, used and handled.
Guidance - Personnel and external party users using or having access to the organization’s information and other associated assets should be made aware of the information security requirements for protecting and handling the organization’s information and other associated assets. They should be responsible for their use of any information processing facilities. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.11 - Return of assets
|
Control - Personnel and other interested parties as appropriate shall return all the organization’s assets in their possession upon change or termination of their employment, contract or agreement.
Purpose - To protect the organization’s assets as part of the process of changing or terminating employment, contract or agreement.
Guidance - The change or termination process should be formalized to include the return of all previously issued physical and electronic assets owned by or entrusted to the organization. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.12 - Classification of information
|
Control - Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.
Purpose - To ensure identification and understanding of protection needs of information in accordance with its importance to the organization.
Guidance - The organization should establish a topic-specific policy on information classification and communicate it to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.13 - Labelling of information
|
Control - An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organization.
Purpose - To facilitate the communication of classification of information and support automation of information processing and management.
Guidance - Procedures for information labelling should cover information and other associated assets in all formats. The labelling should reflect the classification scheme established in 5.12. The labels should be easily recognizable. The procedures should give guidance on where and how labels are attached in consideration of how the information is accessed or the assets are handled depending on the types of storage media. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.14 - Information transfer
|
Control - Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
Purpose - To maintain the security of information transferred within an organization and with any external interested party.
Guidance - The organization should establish and communicate a topic-specific policy on information transfer to all relevant interested parties. Rules, procedures and agreements to protect information in transit should reflect the classification of the information involved. Where information is transferred between the organization and third parties, transfer agreements (including recipient authentication) should be established and maintained to protect information in all forms in transit (see 5.10). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.15 - Access control
|
Control - Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
Purpose - To ensure authorized access and to prevent unauthorized access to information and other associated assets.
Guidance - Owners of information and other associated assets should determine information security and business requirements related to access control. A topic-specific policy on access control should be defined which takes account of these requirements and should be communicated to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.16 - Identity management
|
Control - The full life cycle of identities shall be managed.
Purpose - To allow for the unique identification of individuals and systems accessing the organization’s information and other associated assets and to enable appropriate assignment of access rights.
Guidance - The processes used in the context of identity management should ensure that integrity and maintain Transparency in accordance with the Organisations legal requirements. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.17 - Authentication information
|
Control - Allocation and management of authentication information shall be controlled by a management process, including advising personnel on appropriate handling of authentication information.
Purpose - To ensure proper entity authentication and prevent failures of authentication processes.
Guidance - Allocation of authentication information should be in accordance with the Organisations processes and Legal guidelines. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.18 - Access rights
|
Control - Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control.
Purpose - To ensure access to information and other associated assets is defined and authorized according to the business requirements.
Guidance - The provisioning process for assigning or revoking physical and logical access rights granted to an entity’s authenticated identity should include clear guidelines to ensure conformance to all National and International directives. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.19 - Information security in supplier relationships
|
Control - Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.
Purpose - To maintain an agreed level of information security in supplier relationships.
Guidance - The organization should establish and communicate a topic-specific policy on supplier relationships to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30.
|
|
5.20 - Addressing information security within supplier agreements
|
Control - Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.
Purpose - To maintain an agreed level of information security in supplier relationships.
Guidance - Supplier agreements should be established and documented to ensure that there is clear understanding between the organization and the supplier regarding both parties’ obligations to fulfil relevant information security requirements. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Management Review 9.3.
|
|
5.21 - Managing information security in the information and communication technology (ICT) supply chain
|
Control - Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.
Purpose - To maintain an agreed level of information security in supplier relationships.
Guidance - The Oreganisations should address all necessary requirements when reviewing information security within ICT supply chain security in addition to the general information security requirements for supplier relationships: Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3.
|
|
5.22 - Monitoring, review and change management of supplier services
|
Control - The organization shall regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
Purpose - To maintain an agreed level of information security and service delivery in line with supplier agreements.
Guidance - Monitoring, review and change management of supplier services should ensure the information security terms and conditions of the agreements are complied with, information security incidents and problems are managed properly and changes in supplier services or business status do not affect service delivery. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3.
|
|
5.23 - Information security for use of cloud services
|
Control - Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements.
Purpose - To specify and manage information security for the use of cloud services (External Platforms).
Guidance - The organization should establish and communicate topic-specific policy on the use of cloud services to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3.
|
|
5.24 - Information security incident management planning and preparation
|
Control - The organization shall plan and prepare for managing information security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities.
Purpose - To ensure quick, effective, consistent and orderly response to information security incidents, including communication on information security events.
Guidance - The organization should establish appropriate information security incident management processes. Roles and responsibilities to carry out the incident management procedures should be determined and effectively communicated to the relevant internal and external interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3.
|
|
5.25 - Assessment and decision on information security events
|
Control - The organization shall assess information security events and decide if they are to be categorized as information security incidents.
Purpose - To ensure effective categorization and prioritization of information security events.
Guidance - A categorization and prioritization scheme of information security incidents should be agreed for the identification of the consequences and priority of an incident. The scheme should include the criteria to categorize events as information security incidents. The point of contact should assess each information security event using the agreed scheme. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3.
|
|
5.26 - Response to information security incidents
|
Control - Information security incidents shall be responded to in accordance with the documented procedures.
Purpose - To ensure efficient and effective response to information security incidents.
Guidance - The organization should establish and communicate procedures on information security incident response to all relevant interested parties.Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Incident Reporting 10.2.
|
|
5.27 - Learning from information security incidents
|
Control - Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.
Purpose - To reduce the likelihood or consequences of future incidents.
Guidance - The organization should establish procedures to quantify and monitor the types, volumes and costs of information security incidents. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.28 - Collection of evidence
|
Control - The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
Purpose - To ensure the availabTo ensure a consistent and effective management of evidence related to information security incidents for the purposes of disciplinary and legal actions.
Guidance - Internal procedures should be developed and followed when dealing with evidence related to information security events for the purposes of disciplinary and legal actions. The requirements of different jurisdictions should be considered to maximize chances of admission across the relevant jurisdictions. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.29 - Information security during disruption
|
Control - The organization shall plan how to maintain information security at an appropriate level during disruption.
Purpose - To protect information and other associated assets during disruption.
Guidance - The organization should determine its requirements for adapting information security controls during disruption. Information security requirements should be included in the business continuity management processes. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.30 - ICT readiness for business continuity
|
Control - ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
Purpose - To ensure the availability of the organization’s information and other associated assets during disruption.
Guidance - ICT readiness for business continuity is an important component in business continuity management and information security management to ensure that the organization’s objectives can continue to be met during disruption. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.31 - Legal, statutory, regulatory and contractual requirements
|
Control - Legal, statutory, regulatory and contractual requirements relevant to information security and the organization’s approach to meet these requirements shall be identified, documented and kept up to date.
Purpose - To ensure compliance with legal, statutory, regulatory and contractual requirements related to information security.
Guidance - External requirements including legal, statutory, regulatory or contractual requirements should be taken into consideration when developing Documentation, Legislation and regulations, Cryptography and Contracts. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.32 - Intellectual property rights
|
Control - The organization shall implement appropriate procedures to protect intellectual property rights.
Purpose - To ensure compliance with legal, statutory, regulatory and contractual requirements related to intellectual property rights and use of proprietary products.
Guidance - The Organisation should take the necessary steps to protect any material that can be considered intellectual property. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.33 - Protection of records
|
Control - Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release.
Purpose - To ensure compliance with legal, statutory, regulatory and contractual requirements, as well as community or societal expectations related to the protection and availability of records.
Guidance - The organization should take the necessary steps to protect the authenticity, reliability, integrity and usability of records, as their business context and requirements for their management change over time. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Documentation 7.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.34 - Privacy and protection of personal identifiable information (PII)
|
Control - The organization shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.
Purpose - To ensure compliance with legal, statutory, regulatory and contractual requirements related to the information security aspects of the protection of PII.
Guidance - The organization should establish and communicate a topic-specific policy on privacy and protection of PII to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022 and EU General Data Protection Regulation (GDPR).
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.35 - Independent review of information security
|
Control - The organization’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.
Purpose - To ensure the continuing suitability, adequacy and effectiveness of the organization’s approach to managing information security.
Guidance - The organization should have processes to conduct independent reviews. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.36 - Compliance with policies, rules and standards for information security
|
Control - Compliance with the organization’s information security policy, topic-specific policies, rules and standards shall be regularly reviewed.
Purpose - To ensure that information security is implemented and operated in accordance with the organization’s information security policy, topic-specific policies, rules and standards.
Guidance - Managers, service, product or information owners should identify how to review that information security requirements defined in the information security policy, topic-specific policies, rules, standards and other applicable regulations are met. Automatic measurement and reporting tools should be considered for efficient regular review. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
5.37 - Documented operating procedures
|
Control - Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
Purpose - To ensure the correct and secure operation of information processing facilities.
Guidance - Documented procedures should be prepared for the organization’s operational activities associated with information security so as to ensure conformity. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Action to Address Risk and Opportunities 6.1, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6 People Controls
|
|
6.1 - Screening
|
Control - Background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into consideration applicable laws, regulations and ethics and be proportional to the business requirements, the classification of the information to be accessed and the perceived risks.
Purpose - To ensure all personnel are eligible and suitable for the roles for which they are considered and remain eligible and suitable during their employment.
Guidance - A screening process should be performed for all personnel including full-time, part-time and temporary staff. Where these individuals are contracted through suppliers of services, screening requirements should be included in the contractual agreements between the organization and the suppliers. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.2 - Terms and conditions of employment
|
Control - The employment contractual agreements shall state the personnel’s and the organization’s responsibilities for information security.
Purpose - To ensure personnel understand their information security responsibilities for the roles for which they are considered.
Guidance - The contractual obligations for personnel should take into consideration the organization’s information security policy and relevant topic-specific policies. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.3 - Information security awareness, education and training
|
Control - Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organization's information security policy, topic-specific policies and procedures, as relevant for their job function.
Purpose - To ensure personnel and relevant interested parties are aware of and fulfil their information security responsibilities.
Guidance - An information security awareness, education and training programme should be established in line with the organization’s information security policy, topic-specific policies and relevant procedures on information security, taking into consideration the organization’s information to be protected and the information security controls that have been implemented to protect the information. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Educational organisation Objectives and Targets 6.2, Competence capability and maturity 7.2, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.4 - Disciplinary process
|
Control - A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.
Purpose - To ensure personnel and other relevant interested parties understand the consequences of information security policy violation, to deter and appropriately deal with personnel and other relevant interested parties who committed the violation.
Guidance - The disciplinary process should not be initiated without prior verification that an information security policy violation has occurred (see 5.28). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Educational organisation Objectives and Targets 6.2, Competence capability and maturity 7.2, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.5 - Responsibilities after termination or change of employment
|
Control - Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties.
Purpose - To protect the organization’s interests as part of the process of changing or terminating employment or contracts.
Guidance - The process for managing termination or change of employment should define which information security responsibilities and duties should remain valid after termination or change. This can include confidentiality of information, intellectual property and other knowledge obtained, as well as responsibilities contained within any other confidentiality agreement (see 6.6). Responsibilities and duties still valid after termination of employment or contract should be contained in the individual’s terms and conditions of employment (see 6.2), contract or agreement. Other contracts or agreements that continue for a defined period after the end of the individual’s employment can also contain information security responsibilities. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Educational organisation Objectives and Targets 6.2, Competence capability and maturity 7.2, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.6 - Confidentiality or non-disclosure agreements
|
Control - Confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
Purpose - To maintain confidentiality of information accessible by personnel or external parties.
Guidance - Confidentiality or non-disclosure agreements should address the requirement to protect confidential information using legally enforceable terms. Confidentiality or non-disclosure agreements are applicable to interested parties and personnel of the organization. Based on an organization’s information security requirements, the terms in the agreements should be determined by taking into consideration the type of information that will be handled, its classification level, its use and the permissible access by the other party. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Educational organisation Objectives and Targets 6.2, Competence capability and maturity 7.2, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.7 - Remote working
|
Control - Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises.
Purpose - To ensure the security of information when personnel are working remotely.
Guidance - Remote working occurs whenever personnel of the organization work from a location outside of the organization’s premises, accessing information whether in hardcopy or electronically via ICT equipment. Remote working environments include those referred to as “teleworking”, “telecommuting”, “flexible workplace”, “virtual work environments" and “remote maintenance”. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, Compliance Obligations 4.5, Continuity and resilerence Planning 4.5, Organisational Roles, Responsibilities, Authority and Compliance Function 5.3, Educational organisation Objectives and Targets 6.2, Competence capability and maturity 7.2, Resources 7.1, Emplyment and Registration Process, Documentation 7.5, Raising Concerns 8.3, Risk Treatment Plans 8.3, Management Review 9.3 and Accelerating Continuous Improvement 10.3.
|
|
6.8 - Information security event reporting
|
Control - The organization shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.
Purpose - To support timely, consistent and effective reporting of information security events that can be identified by personnel.
Guidance - All personnel and users should be made aware of their responsibility to report information security events as quickly as possible in order to prevent or minimize the effect of information security incidents. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7 Physical Controls
|
|
7.1 - Physical security perimeters
|
Control - Security perimeters shall be defined and used to protect areas that contain information and other associated assets.
Purpose - To prevent unauthorized physical access, damage and interference to the organization’s information and other associated assets.
Guidance - The Organisation needs to determine strict guidelines in line with National and International Norms when implementing the appropriate requirements for physical security perimeters. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.2 - Physical entry
|
Control - Secure areas shall be protected by appropriate entry controls and access points.
Purpose - To ensure only authorized physical access to the organization’s information and other associated assets occurs.
Guidance - Access points such as delivery and loading areas and other points where unauthorized persons can enter the premises should be controlled and, if possible, isolated from information processing facilities to avoid unauthorized access. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.3 - Securing offices, rooms and facilities
|
Control - Physical security for offices, rooms and facilities shall be designed and implemented.
Purpose - To prevent unauthorized physical access, damage and interference to the organization’s information and other associated assets in offices, rooms and facilities.
Guidance - The Organisations needs to consider National and Internation Norms when adopting guidelines so as to secure offices, rooms and facilities. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.4 - Physical security monitoring
|
Control - Premises shall be continuously monitored for unauthorized physical access.
Purpose - To detect and deter unauthorized physical access.
Guidance - Physical premises should be monitored by surveillance systems, which can include guards, intruder alarms, video monitoring systems such as closed-circuit television and physical security information management software either managed internally or by a monitoring service provider. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.5 - Protecting against physical and environmental threats
|
Control - Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.
Purpose - To prevent or reduce the consequences of events originating from physical and environmental threats.
Guidance - Risk assessments to identify the potential consequences of physical and environmental threats should be performed prior to beginning critical operations at a physical site, and at regular intervals. Necessary safeguards should be implemented and changes to threats should be monitored. Specialist advice should be obtained on how to manage risks arising from physical and environmental threats such as fire, flood, earthquake, explosion, civil unrest, toxic waste, environmental emissions and other forms of natural disaster or disaster caused by human beings. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.6 - Working in secure areas
|
Control - Security measures for working in secure areas shall be designed and implemented.
Purpose - To protect information and other associated assets in secure areas from damage and unauthorized interference by personnel working in these areas.
Guidance - The security measures for working in secure areas should apply to all personnel and cover all activities taking place in the secure area. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.7 - Clear desk and clear screen
|
Control - Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.
Purpose - To reduce the risks of unauthorized access, loss of and damage to information on desks, screens and in other accessible locations during and outside normal working hours.
Guidance - The organization should establish and communicate a topic-specific policy on clear desk and clear screen to all relevant interested parties. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.8 - Equipment siting and protection
|
Control - Equipment shall be sited securely and protected.
Purpose - To reduce the risks from physical and environmental threats, and from unauthorized access and damage.
Guidance - The Organisation should take the necessary advice when ensuring the necessary guidelines are considered to protect equipment. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.9 - Security of assets off-premises
|
Control - Off-site assets shall be protected.
Purpose - To prevent loss, damage, theft or compromise of off-site devices and interruption to the organization’s operations.
Guidance - Any device used outside the organization’s premises which stores or processes information (e.g. mobile device), including devices owned by the organization and devices owned privately and used on behalf of the organization [bring your own device (BYOD)] needs protection. The use of these devices should be authorized by management. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.10 - Storage media
|
Control - Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organization’s classification scheme and handling requirements.
Purpose - To ensure only authorized disclosure, modification, removal or destruction of information on storage media.
Guidance - The Organisation should take the necessary advice so as to determine guidelines for the management of removable storage media, and the Secure reuse and Disposal of such Media Devices. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.11 - Supporting utilities
|
Control - Information processing facilities shall be protected from power failures and other disruptions caused by failures in supporting utilities.
Purpose - To prevent loss, damage or compromise of information and other associated assets, or interruption to the organization’s operations due to failure and disruption of supporting utilities.
Guidance - Organizations depend on utilities (e.g. electricity, telecommunications, water supply, gas, sewage, ventilation and air conditioning) to support their information processing facilities. Therefore, the organization should ensure Suatainability of all utilities. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.12 - Cabling security
|
Control - Cables carrying power, data or supporting information services shall be protected from interception, interference or damage.
Purpose - To prevent loss, damage, theft or compromise of information and other associated assets and interruption to the organization’s operations related to power and communications cabling.
Guidance - The Organisation should take the necessary advice in line with National and International and Statutory Guidelines so as to ensure the security of Cabling for the continuity and resillerence of its opertaions. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.13 - Equipment maintenance
|
Control - Equipment shall be maintained correctly to ensure availability, integrity and confidentiality of information.
Purpose - To prevent loss, damage, theft or compromise of information and other associated assets and interruption to the organization’s operations caused by lack of maintenance.
Guidance - The Organisation should take the necessary advice in line with National and International and Statutory Guidelines for the Maintenance of Its equipment. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
7.14 - Secure disposal or re-use of equipment
|
Control - Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
Purpose - To prevent leakage of information from equipment to be disposed or re-used.
Guidance - Equipment should be verified to ensure whether or not storage media is contained prior to disposal or re-use. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8 Technological controls
|
|
8.1 - User end point devices
|
Control - Information stored on, processed by or accessible via user end point devices shall be protected.
Purpose - To protect information against the risks introduced by using user endpoint devices.
Guidance - The organization should establish a topic-specific policy on secure configuration and handling of user endpoint devices. The topic-specific policy should be communicated to all relevant personnel. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - 2025-07-17, AV Report, Vulnerabilities External.
|
|
8.2 - Privileged access rights
|
Control - The allocation and use of privileged access rights shall be restricted and managed.
Purpose - To ensure only authorized users, software components and services are provided with privileged access rights.
Guidance - The allocation of privileged access rights should be controlled through an authorization process in accordance with the relevant topic-specific policy on access control (see 5.15). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.3 - Information access restriction
|
Control - Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.
Purpose - To ensure only authorized access and to prevent unauthorized access to information and other associated assets.
Guidance - Access to information and other associated assets should be restricted in accordance with the established topic-specific policies. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.4 - Access to source code
|
Control - Read and write access to source code, development tools and software libraries shall be appropriately managed.
Purpose - To prevent the introduction of unauthorized functionality, avoid unintentional or malicious changes and to maintain the confidentiality of valuable intellectual property.
Guidance - Access to source code and associated items (such as designs, specifications, verification plans and validation plans) and development tools (e.g. compilers, builders, integration tools, test platforms and environments) should be strictly controlled. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.5 - Secure authentication
|
Control - Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.
Purpose - To ensure a user or an entity is securely authenticated, when access to systems, applications and services is granted.
Guidance - A suitable authentication technique should be chosen to substantiate the claimed identity of a user, software, messages and other entities. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.6 - Capacity management
|
Control - The use of resources shall be monitored and adjusted in line with current and expected capacity requirements.
Purpose - To ensure the required capacity of information processing facilities, human resources, offices and other facilities.
Guidance - Capacity requirements for information processing facilities, human resources, offices and other facilities should be identified, taking into account the business criticality of the concerned systems and processes. Additional guidance can be obtained by refering to ISO 27002:2022
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.7 - Protection against malware
|
Control - Protection against malware shall be implemented and supported by appropriate user awareness.
Purpose - To ensure information and other associated assets are protected against malware.
Guidance - Protection against malware should be based on malware detection and repair software, information security awareness, appropriate system access and change management controls. Use of malware detection and repair software alone is not usually adequate. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.8 - Management of technical vulnerabilities
|
Control - Information about technical vulnerabilities of information systems in use shall be obtained, the organization’s exposure to such vulnerabilities shall be evaluated and appropriate measures shall be taken.
Purpose - To prevent exploitation of technical vulnerabilities.
Guidance - The organization should have an accurate inventory of assets (see 5.9 to 5.14) as a prerequisite for effective technical vulnerability management; the inventory should include the software vendor, software name, version numbers, current state of deployment (e.g. what software is installed on what systems) and the person(s) within the organization responsible for the software. Additional guidance can be obtained by refering to ISO 27002:2022
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.9 - Configuration management
|
Control - Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed.
Purpose - To ensure hardware, software, services and networks function correctly with required security settings, and configuration is not altered by unauthorized or incorrect changes.
Guidance - The organization should define and implement processes and tools to enforce the defined configurations (including security configurations) for hardware, software, services (e.g. cloud services) and networks, for newly installed systems as well as for operational systems over their lifetime. Additional guidance can be obtained by refering to ISO 27002:2022
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.10 - Information deletion
|
Control - Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.
Purpose - To prevent unnecessary exposure of sensitive information and to comply with legal, statutory, regulatory and contractual requirements for information deletion.
Guidance - Sensitive information should not be kept for longer than it is required to reduce the risk of undesirable disclosure. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.11 - Data masking
|
Control - Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.
Purpose - To limit the exposure of sensitive data including PII, and to comply with legal, statutory, regulatory and contractual requirements.
Guidance - Where the protection of sensitive data (e.g. PII) is a concern, the organization should consider hiding such data by using techniques such as data masking, pseudonymization or anonymization. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.12 - Data leakage prevention
|
Control - Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information.
Purpose - To detect and prevent the unauthorized disclosure and extraction of information by individuals or systems.
Guidance - The organization should consider the following to reduce the risk of data leakage for example identifying and classifying information to protect against leakage (e.g. personal information, pricing models and product designs). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.13 - Information backup
|
Control - Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
Purpose - To enable recovery from loss of data or systems.
Guidance - A topic-specific policy on backup should be established to address the organization’s data retention and information security requirements. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.14 - Redundancy of information processing facilities
|
Control - Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
Purpose - To ensure the continuous operation of information processing facilities.
Guidance - The organization should identify requirements for the availability of business services and information systems. The organization should design and implement systems architecture with appropriate redundancy to meet these requirements. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.15 - Logging
|
Control - Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed.
Purpose - unauthorized access, identify information security events that can lead to an information security incident and to support investigations.
Guidance - The organization should determine the purpose for which logs are created, what data is collected and logged, and any log-specific requirements for protecting and handling the log data. This should be documented in a topic-specific policy on logging. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.16 - Monitoring activities
|
Control - Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
Purpose - To detect anomalous behaviour and potential information security incidents.
Guidance - The monitoring scope and level should be determined in accordance with business and information security requirements and taking into consideration relevant laws and regulations. Monitoring records should be maintained for defined retention periods. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.17 - Clock synchronization
|
Control - The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
Purpose - To enable the correlation and analysis of security-related events and other recorded data, and to support investigations into information security incidents.
Guidance - External and internal requirements for time representation, reliable synchronization and accuracy should be documented and implemented. Such requirements can be from legal, statutory, regulatory, contractual, standards and internal monitoring needs. A standard reference time for use within the organization should be defined and considered for all systems, including building management systems, entry and exit systems and others that can be used to aid investigations. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.18 - Use of privileged utility programs
|
Control - The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
Purpose - To ensure the use of utility programs does not harm system and application controls for information security.
Guidance - The Organisation should consider specific guidelines for the use of utility programs that can be capable of overriding system and application controls should be considered. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.19 - Installation of software on operational systems
|
Control - Procedures and measures shall be implemented to securely manage software installation on operational systems.
Purpose - To ensure the integrity of operational systems and prevent exploitation of technical vulnerabilities.
Guidance - The Organisation should consider specific guidelines to securely manage changes and installation of software on operational systems. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.20 - Networks security
|
Control - Networks and network devices shall be secured, managed and controlled to protect information in systems and applications.
Purpose - To protect information in networks and its supporting information processing facilities from compromise via the network.
Guidance - Controls should be implemented to ensure the security of information in networks and to protect connected services from unauthorized access. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.21 - Security of network services
|
Control - Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored.
Purpose - To ensure security in the use of network services.
Guidance - The security measures necessary for particular services, such as security features, service levels and service requirements, should be identified and implemented (by internal or external network service providers). The organization should ensure that network service providers implement these measures. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - 2025-07-17, AutoHealRules Report, Software Report.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.22 - Segregation of networks
|
Control - Groups of information services, users and information systems shall be segregated in the organization’s networks.
Purpose - To split the network in security boundaries and to control traffic between them based on business needs.
Guidance - The organization should consider managing the security of large networks by dividing them into separate network domains and separating them from the public network (i.e. internet). The domains can be chosen based on levels of trust, criticality and sensitivity (e.g. public access domain, desktop domain, server domain, low- and high-risk systems), along organizational units (e.g. human resources, finance, marketing) or some combination (e.g. server domain connecting to multiple organizational units). The segregation can be done using either physically different networks or by using different logical networks. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.23 - Web filtering
|
Control - Access to external websites shall be managed to reduce exposure to malicious content.
Purpose - To protect systems from being compromised by malware and to prevent access to unauthorized web resources.
Guidance - The organization should reduce the risks of its personnel accessing websites that contain illegal information or are known to contain viruses or phishing material. A technique for achieving this works by blocking the IP address or domain of the website(s) concerned. Some browsers and anti-malware technologies do this automatically or can be configured to do so. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.24 - Use of cryptography
|
Control - Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.
Purpose - To ensure proper and effective use of cryptography to protect the confidentiality, authenticity or integrity of information according to business and information security requirements, and taking into consideration legal, statutory, regulatory and contractual requirements related to cryptography.
Guidance - The Organisation should consider specific guidelines When using cryptography. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.25 - Secure development life cycle
|
Control - Rules for the secure development of software and systems shall be established and applied.
Purpose - To ensure information security is designed and implemented within the secure development life cycle of software and systems.
Guidance - Secure development is a requirement to build up a secure service, architecture, software and system. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.26 - Application security requirements
|
Control - Information security requirements shall be identified, specified and approved when developing or acquiring applications.
Purpose - To ensure all information security requirements are identified and addressed when developing or acquiring applications.
Guidance - Application security requirements should be identified and specified. These requirements are usually determined through a risk assessment. The requirements should be developed with the support of information security specialists. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.27 - Secure system architecture and engineering principles
|
Control - Principles for engineering secure systems shall be established, documented, maintained and applied to any information system development activities.
Purpose - To ensure information systems are securely designed, implemented and operated within the development life cycle.
Guidance - Security engineering principles should be established, documented and applied to information system engineering activities. Security should be designed into all architecture layers (business, data, applications and technology). New technology should be analysed for security risks and the design should be reviewed against known attack patterns. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.28 - Secure coding
|
Control - Secure coding principles shall be applied to software development.
Purpose - To ensure software is written securely thereby reducing the number of potential information security vulnerabilities in the software.
Guidance - The organization should establish organization-wide processes to provide good governance for secure coding. A minimum secure baseline should be established and applied. Additionally, such processes and governance should be extended to cover software components from third parties and open source software. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.29 - Security testing in development and acceptance
|
Control - Security testing processes shall be defined and implemented in the development life cycle.
Purpose - To validate if information security requirements are met when applications or code are deployed to the production environment.
Guidance - New information systems, upgrades and new versions should be thoroughly tested and verified during the development processes. Security testing should be an integral part of the testing for systems or components. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.30 - Outsourced development
|
Control - The organization shall direct, monitor and review the activities related to outsourced system development.
Purpose - To ensure information security measures required by the organization are implemented in outsourced system development.
Guidance - Where system development is outsourced, the organization should communicate and agree requirements and expectations, and continually monitor and review whether the delivery of outsourced work meets these expectations. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.31 - Separation of development, test and production environments
|
Control - Development, testing and production environments shall be separated and secured.
Purpose - To protect the production environment and data from compromise by development and test activities.
Guidance - The level of separation between production, testing and development environments that is necessary to prevent production problems should be identified and implemented. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.32 - Change management
|
Control - Changes to information processing facilities and information systems shall be subject to change management procedures.
Purpose - To preserve information security when executing changes.
Guidance - Introduction of new systems and major changes to existing systems should follow agreed rules and a formal process of documentation, specification, testing, quality control and managed implementation. Management responsibilities and procedures should be in place to ensure satisfactory control of all changes. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.33 - Test information
|
Control - Test information shall be appropriately selected, protected and managed.
Purpose - To ensure relevance of testing and protection of operational information used for testing.
Guidance - Test information should be selected to ensure the reliability of tests results and the confidentiality of the relevant operational information. Sensitive information (including personally identifiable information) should not be copied into the development and testing environments (see 8.31). Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
|
8.34 - Protection of information systems during audit testing
|
Control - Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.
Purpose - To minimize the impact of audit and other assurance activities on operational systems and business processes.
Guidance - The Organisation should consider specific guidelines in line with Conformity Assessment Principles. Additional guidance can be obtained by refering to ISO 27002:2022.
Evidence of Conformance - ISO Certified Educational Organisations Management System, ISO 27001:2022, ISO 27002:2022, Strata Management Full Vulnerability Report 2026/06/30, including AV Report, Vulnerabilities External Report, Software Report, AutoHealRules Report, Vulnerability Report and Bitlocker Reports
|
Make it a wonderful Day, and ensure you keep smiling as this will pass on strength and enthusiasm, love, good will and don’t forget the Smile as it’s so much easier than a frown, Laughter is the best tonic for you and your Family!
This way we will all end the day more enthused, on a high and ensuring we have exhausted our deposit of $86,400 in our memory bank as there is no carry over of your daily deposit.
Ready to start a New Days Adventure with the Family! Remember great things await you, Inspire and be inspired with a fresh deposit Cheers Erko.