Cyber Resilience

← ISO 27001 Annex A

A.5.36 Organizational

Compliance with policies, rules and standards for information security

AttributesPreventiveC·I·AIdentifyProtectLegal and complianceInformation security assuranceGovernance and Ecosystem

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (15)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (18)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (5)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Related weaknesses / CWE (9)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (434)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←MT1003→PT1003.001→PT1003.003→PT1003.005→PT1003.006→PT1006←M →PT1014←MT1021.004→PT1027.001←MT1027.002←MT1027.004→PT1027.005←MT1027.006←MT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←MT1027.013←MT1027.014←MT1027.016←MT1027.018←MT1030←MT1036←MT1036.001→PT1036.003←M →PT1036.005←MT1036.007←MT1036.008←MT1036.009←MT1036.011←M →PT1036.012←MT1037.003→PT1037.004→PT1037.005→PT1041→PT1046→PT1048.002→PT1053→PT1053.003→PT1053.005←M →PT1053.007→PT1055←M →PT1055.001←MT1055.002←M →PT1055.003←M →PT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056.004→PT1059.008→PT1068←MT1070←M →PT1070.003←MT1070.004←M →PT1070.006←MT1070.007←M →PT1070.008←MT1070.009→PT1070.010←MT1071←MT1071.001←MT1071.004←MT1078→PT1078.001←M →PT1078.002→PT1087.003→PT1090←MT1090.001→PT1090.003←MT1095←MT1098←P →PT1098.001→PT1098.003→PT1098.004→PT1098.005←M →PT1102←MT1102.001→PT1102.002←M →PT1102.003→PT1110.001→MT1110.004→PT1111←M →PT1112←MT1114.002→PT1114.003→PT1127←MT1127.001←M →PT1127.003←M →PT1132.002←MT1133←MT1134←MT1134.001←MT1134.002←MT1134.003←MT1134.004←MT1134.005←M →PT1136.003→PT1137.001→PT1137.002→PT1137.003→PT1137.004→PT1137.005→PT1137.006→PT1202←MT1204.004←MT1205.002→PT1207←MT1211←MT1213.005→PT1216←M →PT1216.001←MT1216.002←MT1218←MT1218.002→PT1218.003→PT1218.004→PT1218.005←M →PT1218.007←MT1218.008←M →PT1218.009←M →PT1218.010←MT1218.011←MT1218.012←M →PT1218.013←MT1218.014→PT1219.002→PT1219.003←MT1220←MT1221←MT1222←MT1222.001←M →PT1222.002←M →PT1480.001←MT1484←M →PT1484.001←M →PT1484.002←M →PT1485.001←M →PT1486→MT1489←MT1490←M →PT1491.001→PT1496→PT1496.001→PT1496.002→PT1496.003→PT1497←MT1498.002→PT1499←F →PT1499.004→PT1505.002→PT1505.003→PT1505.004→PT1525→PT1530→PT1531→PT1535←M →PT1537←MT1538→PT1539←FT1542←MT1542.002←MT1542.003←M →PT1542.005→PT1543.002→PT1543.003→PT1543.004→PT1546→PT1546.001→PT1546.002→PT1546.003→PT1546.006→PT1546.007→PT1546.008→PT1546.009→PT1546.010→PT1546.011→PT1546.012←P →PT1546.013→PT1546.015→PT1546.016→PT1546.017→PT1547.001→PT1547.002→PT1547.003→PT1547.004→PT1547.010→PT1547.012→PT1547.013→PT1547.014→PT1547.015→PT1548.002←M →PT1548.003←M →PT1548.005→PT1548.006←M →PT1550←FT1550.001←FT1550.002←FT1550.003←FT1552.001→PT1552.006→PT1552.008→PT1553←M →PT1553.001←FT1553.002←MT1553.003←M →PT1553.004←M →PT1553.005←MT1553.006←M →PT1554→PT1555.004→PT1555.006→PT1556←M →PT1556.001←M →PT1556.002→PT1556.003←M →PT1556.005→PT1556.006←M →PT1556.007←M →PT1556.008→PT1556.009←M →PT1557.001→PT1558.001→PT1561→PT1561.001→MT1561.002→PT1563.002→PT1564←MT1564.004←MT1564.009→PT1565→PT1565.001→PT1565.002→PT1566.003←MT1567.001→PT1567.004→PT1568←MT1568.001→PT1568.003←MT1569→PT1569.003→PT1571←M →PT1572←MT1574←MT1574.001←M →PT1574.004←MT1574.005→PT1574.008→PT1574.009→PT1574.010→PT1574.013←MT1578←M →PT1578.001←MT1578.002←MT1578.003←M →MT1578.004←M →PT1578.005←M →PT1599←MT1599.001←MT1600←MT1600.001←PT1601.001←MT1601.002←MT1602.002→PT1606←MT1606.001←MT1606.002←MT1610←PT1612←M →PT1620←MT1621←M →PT1622←FT1647←PT1665←MT1666←MT1671→PT1677←M →PT1678←MT1679→PT1684.002←MT1685←M →MT1685.001←M →PT1685.002←M →PT1685.003←MT1685.004←M →PT1685.005←M →MT1685.006←M →PT1686←F →PT1686.001←M →PT1686.002←M →PT1686.003←M →PT1687←MT1688←MT1689←MT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (12)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.