Cyber Resilience

← ISO 27001 Annex A

A.5.16 Organizational

Identity management

AttributesPreventiveC·I·AProtectIdentity and access managementProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (21)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (16)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (12)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (24)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (420)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001.003←MT1003→PT1003.001←PT1003.006→PT1003.008←PT1006←MT1014←MT1021←P →PT1021.001←P →PT1021.002←P →PT1021.003→PT1021.004←P →MT1021.005→PT1021.006←P →PT1021.007←M →PT1021.008←P →PT1027.011←PT1027.014←MT1036←MT1036.002←MT1036.003←MT1036.004←MT1036.005←MT1036.008←MT1036.009←MT1036.010←M →PT1036.011←MT1036.012←MT1037.001→PT1037.003→PT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056←MT1056.002←MT1056.004←MT1059.009→PT1068←MT1070←MT1070.003←MT1071←MT1071.001←MT1071.004←MT1072→PT1078→PT1078.001→MT1078.002→PT1078.003→MT1078.004→MT1090←MT1090.002←MT1090.003←MT1095←MT1098←P →PT1098.001←M →PT1098.002←P →PT1098.003←M →PT1098.004←P →PT1098.005→PT1098.006←M →PT1098.007←M →PT1102←MT1102.001←MT1102.002←MT1110→PT1110.001→MT1110.002→MT1110.003→MT1110.004→PT1111←MT1127←MT1127.001←MT1133→PT1134←MT1134.001←M →PT1134.002←MT1134.003←M →PT1134.004←MT1134.005←MT1136←P →PT1136.001←P →PT1136.002←M →PT1136.003←M →PT1137.001→PT1185←MT1199←M →PT1202←MT1204←MT1204.004←MT1207←MT1211←PT1212←PT1216←MT1216.001←MT1218←MT1218.003←MT1218.004←MT1218.005←MT1218.007←MT1218.008←M →PT1218.009←MT1218.010←MT1218.011←MT1218.012←MT1218.013←MT1219.003←MT1221←MT1222←MT1222.001←MT1222.002←MT1480.001←MT1484←M →PT1484.001←MT1484.002←M →PT1489←PT1496.004→PT1497←MT1528←M →PT1530←M →MT1531→PT1534→PT1535←MT1537←M →PT1538→PT1539→PT1542←MT1542.002←MT1542.003←MT1546.003→PT1546.012←PT1548←M →PT1548.002←MT1548.003←PT1548.005→PT1548.006←MT1550←M →PT1550.001←F →PT1550.002←F →PT1550.003←F →PT1550.004←FT1552.008→PT1553.001←MT1553.002←PT1553.003←MT1553.004←PT1553.006←MT1555.006→PT1556←M →PT1556.001←M →PT1556.002←FT1556.003←MT1556.004←MT1556.005←P →PT1556.006←MT1556.007←M →PT1556.008←M →PT1556.009←MT1557.001←MT1558←M →PT1558.001←M →PT1558.002←M →PT1558.003→PT1558.004→PT1563→PT1563.001←M →PT1563.002←M →PT1564←PT1564.001←MT1566.003←MT1568←MT1568.002←MT1571←MT1572←MT1574←MT1574.001←MT1574.013←MT1578←MT1578.001←MT1578.002←MT1578.003←M →PT1578.004←MT1578.005←MT1583.006←MT1583.007←MT1584.006←MT1585←MT1585.001←MT1585.002←MT1586→PT1586.001←M →PT1586.002←M →PT1586.003←M →PT1589.001←M →PT1598.003←MT1599←MT1599.001←PT1600←PT1601.001←PT1601.002←PT1606←M →PT1606.001←F →PT1606.002←MT1610←PT1620←MT1621←MT1647←PT1649←P →PT1650←MT1665←PT1666←MT1671←M →PT1683←MT1683.002←MT1684←M →PT1684.001→PT1684.002←MT1685←MT1685.001←MT1685.002←MT1685.003←MT1685.004←MT1685.005←MT1685.006←MT1686←FT1687←PT1688←MT1689←PT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (7)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.