Cyber Resilience

← ISO 27001 Annex A

A.5.25 Organizational

Assessment and decision on information security events

AttributesDetectiveC·I·ADetectRespondInformation security event managementDefence

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (10)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (17)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (5)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Mitigated MITRE ATT&CK techniques (901)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←MT1003→MT1003.001→MT1003.003→MT1003.006→MT1006←MT1014←MT1020→MT1020.001→MT1021.001→MT1021.002→MT1021.004→MT1021.005→MT1021.006→MT1021.007→MT1027.001←MT1027.002←MT1027.003←MT1027.005←MT1027.006←M →MT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←MT1027.013←MT1027.014←MT1027.016←MT1027.017←MT1027.018←MT1030←MT1036←M →MT1036.001→MT1036.002←MT1036.003←M →MT1036.004←M →MT1036.005←MT1036.006←MT1036.007←MT1036.008←MT1036.009←MT1036.010→MT1036.011←MT1036.012←MT1040→MT1041→MT1047→MT1048→MT1048.001→MT1048.002→MT1048.003→MT1052.001→MT1053.002→MT1053.005←M →MT1053.007→MT1055←M →MT1055.001←M →MT1055.002←M →MT1055.003←M →MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←M →MT1055.013←MT1055.014←MT1055.015←M →MT1056.003→MT1059→MT1059.001→MT1059.004→MT1059.006→MT1059.009→MT1068→MT1070←MT1070.003←MT1070.004→MT1070.006←MT1070.007←M →MT1070.008←M →PT1070.009→MT1070.010←M →MT1071←MT1071.001←MT1071.004←M →MT1071.005←MT1072→MT1074→MT1078←P →MT1078.002→MT1078.003→MT1078.004→MT1090←MT1090.001←MT1090.002←MT1090.003←MT1095←MT1098→MT1098.003→MT1098.005←M →MT1102←MT1102.001←M →PT1102.002→MT1104←MT1110→MT1110.001→MT1110.002→MT1110.003→MT1110.004→MT1111→MT1114→MT1114.002→MT1114.003→MT1127←MT1127.001←MT1127.003←PT1132.002←MT1133←MT1134←MT1134.001←M →MT1134.003←MT1134.004←MT1136→MT1136.003→MT1137.003→MT1137.004→MT1137.005→MT1137.006→MT1185→MT1189→MT1190→MT1202←MT1203→MT1204→MT1204.001→MT1204.002→MT1204.004←M →MT1204.005→MT1205.001←MT1207←M →MT1210→MT1211←MT1213.005←M →MT1216←MT1216.002←MT1218←MT1218.003→MT1218.005←M →MT1218.007←MT1218.008←MT1218.010←M →MT1218.011←MT1218.012←MT1218.013←M →MT1218.014→MT1219→MT1219.002→MT1219.003←MT1220←PT1221←MT1222←MT1222.001←MT1222.002←MT1480.001←MT1484←MT1484.001→MT1484.002←M →MT1485→MT1486→MT1489←M →MT1490←M →MT1491→MT1491.001→MT1491.002→MT1496→MT1496.001→MT1496.002→MT1496.003→MT1496.004→MT1497←MT1497.001←MT1498←M →MT1498.001→MT1498.002→MT1499←F →MT1499.001→MT1499.002→MT1499.003→MT1499.004→PT1505→MT1505.003→MT1505.004→MT1528→MT1529←M →MT1530→MT1531←M →MT1534→MT1535←MT1537←M →MT1539←F →MT1542←MT1542.002←MT1542.003→PT1543.002→MT1543.003←M →MT1543.004→MT1546→MT1546.003→MT1546.007→MT1546.009→MT1546.012←MT1546.014→PT1546.015→MT1546.016→MT1547.014→MT1548.002→MT1548.005→MT1548.006←MT1550←FT1550.002←FT1550.003←F →MT1550.004←F →MT1553.001←MT1553.002←MT1553.003←MT1553.004←MT1553.005←MT1553.006←MT1554→MT1555.006→MT1556←MT1556.001←MT1556.003→MT1556.006←MT1556.007←MT1556.008→MT1556.009←MT1557→MT1557.002→MT1557.003→MT1557.004→MT1558→MT1558.001→MT1558.002←M →MT1559.001→MT1559.002→MT1561→MT1561.001→MT1561.002→MT1563→MT1563.001→MT1563.002→MT1564←MT1564.004←MT1564.008→MT1565→MT1565.001→MT1565.002→MT1566→MT1566.001→MT1566.002→MT1566.003←M →MT1566.004→MT1567→MT1567.001→MT1567.002→MT1567.003→MT1567.004→MT1568←MT1568.002←MT1568.003←MT1569→MT1569.001→MT1569.002→MT1569.003→MT1570→MT1571←M →MT1572←MT1574←MT1574.001←MT1574.004←M →MT1574.013←MT1578←M →MT1578.001←MT1578.002←M →MT1578.003←M →MT1578.004←M →MT1578.005←MT1587.001←MT1598.003←M →MT1599←MT1599.001←MT1601.001←PT1601.002←MT1606.001←MT1606.002→MT1610←PT1612←MT1620←MT1621←M →MT1622←MT1647←PT1649→MT1654→MT1657→MT1659→MT1665←M →MT1666←MT1667→MT1678←MT1684.001→MT1684.002←MT1685←M →MT1685.001←MT1685.002←MT1685.003←MT1685.004←MT1685.005←M →MT1685.006←M →MT1686←F →MT1686.001→MT1686.002←MT1686.003←MT1687←MT1688←MT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (4)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.