Cyber Resilience

← ISO 27001 Annex A

A.5.15 Organizational

Access control

AttributesPreventiveC·I·AProtectIdentity and access managementProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (30)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (17)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (14)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (106)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (813)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←MT1003←M →PT1003.001←M →PT1003.002←M →PT1003.003←M →PT1003.004←M →PT1003.005→PT1003.006→PT1003.007→PT1003.008→PT1005→PT1006←M →PT1008←MT1011←M →PT1011.001←MT1014←MT1020→PT1021→PT1021.001→PT1021.002←M →PT1021.003←P →PT1021.004←M →PT1021.005←M →PT1021.006→PT1021.007→PT1021.008→PT1027.001←MT1027.002←MT1027.005←MT1027.006←MT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←MT1027.014←MT1027.016←MT1027.017←MT1027.018←MT1030←MT1036←MT1036.002←MT1036.003←MT1036.004←MT1036.005←MT1036.006←MT1036.007←MT1036.008←MT1036.009←MT1036.010←MT1036.011←MT1036.012←MT1037→PT1037.001→PT1037.002→PT1037.003→PT1037.004→PT1039←M →PT1040←M →PT1046→PT1047←M →PT1048←M →PT1049→PT1052←M →PT1052.001←M →PT1053→PT1053.002←M →PT1053.003→PT1053.005←M →PT1053.006→PT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056←MT1056.002←MT1056.003←M →PT1056.004←PT1057→PT1059←MT1059.001→PT1059.002→PT1059.003→PT1059.007→PT1059.008←M →PT1059.009←M →PT1059.012→PT1059.013←M →PT1068←M →PT1069→PT1069.001→PT1069.002→PT1069.003→PT1070←MT1070.003←MT1070.006←MT1070.010←MT1071←MT1071.001←MT1071.002←MT1071.003←MT1071.004←MT1071.005←MT1072←M →PT1074.002←PT1078→MT1078.001→PT1078.002→MT1078.003→PT1078.004→PT1080→PT1083→PT1087→PT1087.001→PT1087.002→PT1087.003→PT1087.004→PT1090←MT1090.001←MT1090.002←MT1090.003←MT1090.004←MT1091←M →PT1095←MT1098→PT1098.001←M →PT1098.002→PT1098.003→PT1098.004←M →PT1098.005→PT1098.006←M →PT1098.007→PT1102←MT1102.001←MT1102.002←MT1102.003←MT1110→PT1110.001→MT1110.002→MT1110.003→MT1110.004→MT1111←M →PT1112←P →PT1114→PT1114.001→PT1114.002←M →PT1114.003→PT1119→PT1127←MT1127.001←MT1127.002←M →PT1127.003←MT1132.001←PT1132.002←PT1133→PT1134→PT1134.001→PT1134.002→PT1134.003←M →PT1134.004←MT1134.005←MT1135→PT1136←P →PT1136.001←M →PT1136.002←M →PT1136.003←M →PT1137→PT1137.001→PT1137.002→PT1137.003→PT1137.004→PT1137.005→PT1137.006→PT1176←M →PT1176.001←P →PT1185←M →PT1187→PT1189←MT1190←M →PT1199←M →PT1200←M →PT1202←M →PT1203←PT1204←PT1204.001←MT1204.002←M →PT1204.003←MT1204.004←MT1204.005←MT1205←MT1205.001←MT1207←M →PT1210←M →PT1211←MT1212←MT1213→PT1213.001→PT1213.002←M →PT1213.003←M →PT1213.004→PT1213.005←M →PT1213.006→PT1216←MT1216.001←MT1216.002←MT1218←MT1218.002←M →PT1218.003←M →PT1218.004←M →PT1218.005←M →PT1218.007←MT1218.008←M →PT1218.009←MT1218.010←M →PT1218.011←MT1218.012←M →PT1218.013←MT1218.014→PT1219←M →PT1219.001←MT1219.002←M →PT1219.003←M →PT1220←MT1221←PT1222←M →PT1222.001←M →PT1222.002←M →PT1480.001←MT1484←M →PT1484.001→PT1484.002←M →PT1485.001→PT1489←PT1496.004→PT1497←MT1497.001←MT1497.002←PT1499←PT1505.001→PT1505.003←M →PT1505.005←MT1525→PT1526→PT1528←M →PT1529←PT1530→PT1531←MT1534←M →PT1535←MT1537←M →PT1538→PT1539→PT1542←MT1542.001←PT1542.002←MT1542.003←MT1542.005←MT1543.001→PT1543.002→PT1543.003←M →PT1543.004→PT1543.005→PT1546→PT1546.002→PT1546.003→PT1546.004→PT1546.008←M →PT1546.011←P →PT1546.012←P →PT1546.013→PT1546.014→PT1546.016→PT1546.017→PT1547→PT1547.001←M →PT1547.003→PT1547.004→PT1547.006→PT1547.007→PT1547.009→PT1547.010→PT1547.012→PT1547.013→PT1547.014→PT1547.015→PT1548→PT1548.001←M →PT1548.002←M →PT1548.003←M →PT1548.004←M →PT1548.005←M →PT1548.006←M →PT1550→PT1550.001←F →PT1550.002←F →PT1550.003→PT1550.004←F →PT1552←P →PT1552.001→PT1552.004→PT1552.005←M →PT1552.006←M →PT1552.007→PT1552.008←M →PT1553←MT1553.001←MT1553.002←PT1553.003←M →PT1553.004←MT1553.005←MT1553.006←M →PT1554←PT1555←M →PT1555.001→PT1555.003→PT1555.004→PT1555.005→PT1555.006→PT1556←M →PT1556.001←MT1556.002←PT1556.003←M →PT1556.004←MT1556.005←P →PT1556.006→PT1556.007←M →PT1556.008←M →PT1556.009→PT1557←M →PT1557.001←M →PT1557.002←MT1557.003←MT1557.004←M →PT1558←M →PT1558.001←M →PT1558.002←M →PT1558.003→PT1558.004→PT1558.005→PT1559.002→PT1559.003→PT1561←PT1561.002→MT1563→PT1563.001←M →PT1563.002←M →PT1564←MT1564.001←MT1564.004←MT1564.008→PT1565→PT1565.001→PT1566→PT1566.002→PT1566.003←M →PT1566.004→PT1567.001→PT1567.002→PT1567.003→PT1567.004→PT1568←MT1568.002←MT1568.003←MT1569→PT1569.002→PT1569.003→PT1570←P →PT1571←MT1572←M →PT1574←MT1574.001←M →PT1574.004←MT1574.005→PT1574.006←M →PT1574.007→PT1574.008←M →PT1574.009→PT1574.010←M →PT1574.011←P →PT1574.012→PT1574.013←MT1578←M →PT1578.001←MT1578.002←MT1578.003←MT1578.004←MT1578.005←M →PT1580→PT1583.007←MT1584←MT1584.006←MT1584.007←PT1584.008←MT1585←MT1586←M →PT1586.002←MT1586.003→PT1587.001←MT1589.001←P →PT1590.003←MT1595.003→PT1598.001→PT1598.003←MT1599←M →PT1599.001←MT1600←PT1600.001←PT1601←PT1601.001←M →PT1601.002←MT1602←M →PT1602.001→PT1602.002→PT1606←M →PT1606.001←F →PT1606.002←M →PT1609←M →PT1610←P →PT1611←M →PT1612←PT1619→PT1620←MT1621←M →PT1622←PT1647←MT1648→PT1649←M →PT1650←MT1651→PT1653←PT1654→PT1657→PT1659←MT1665←PT1666←M →PT1668←PT1669←M →PT1671←M →PT1675→PT1677→PT1678←MT1679←PT1684←M →PT1684.001←PT1684.002←MT1685←MT1685.001←M →PT1685.002←M →PT1685.003←MT1685.004←MT1685.005←MT1685.006←MT1686←FT1686.001←M →PT1686.002←M →PT1686.003←MT1687←MT1688←MT1689←MT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (8)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.