Cyber Resilience

← ISO 27001 Annex A

A.5.8 Organizational

Information security in project management

AttributesPreventiveC·I·AIdentifyProtectGovernanceGovernance and EcosystemProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (15)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (20)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (13)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (12)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (490)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←M →PT1001.003←MT1003.003→PT1003.006→PT1003.008→PT1005→PT1006←MT1011←MT1014←MT1020→PT1021→PT1021.004→PT1021.007→PT1021.008→PT1027.001←MT1027.002←MT1027.003→PT1027.006←MT1027.008←MT1027.009←M →PT1027.010←M →PT1027.011←MT1027.014←MT1027.016←MT1027.017→PT1027.018←M →PT1030←MT1036←M →PT1036.002→PT1036.003←MT1036.004→PT1036.005←MT1036.008←M →PT1036.009←MT1036.010→PT1036.012←MT1037→PT1037.001→PT1037.003→PT1040→PT1041→PT1048→PT1048.001→PT1048.003→PT1052→PT1052.001→PT1053.007→PT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056.002→PT1056.003→PT1059→PT1059.005→PT1059.007→PT1059.008→PT1059.009→PT1059.013→PT1068←M →PT1069.003→PT1070←MT1070.010←MT1071←MT1071.001←MT1071.004←MT1071.005←MT1072→PT1078→PT1078.001→PT1078.002→PT1078.003→PT1078.004→PT1080→PT1087.004→PT1090←MT1090.002←MT1090.003←MT1090.004←MT1092→PT1095←MT1098→PT1098.001→PT1098.002→PT1098.003→PT1098.004→PT1098.005←M →PT1098.006→PT1098.007→PT1102←MT1102.002→PT1102.003←M →PT1104→PT1110→PT1110.001→PT1110.002→PT1110.003→PT1110.004→PT1111←M →PT1114.001→PT1114.002→PT1114.003→PT1127←M →PT1127.001←M →PT1127.002→PT1127.003←P →PT1132.001←MT1132.002←MT1133←M →PT1134←MT1134.001←MT1134.004←MT1136→PT1136.001→PT1136.002→PT1136.003→PT1137→PT1137.001→PT1137.002→PT1137.003→PT1137.004→PT1137.005→PT1137.006→PT1176→PT1176.001→PT1176.002→PT1185←M →PT1187→PT1189→PT1190→PT1195→PT1195.001→PT1195.002←P →PT1195.003→PT1199→PT1202←MT1203→PT1204→PT1204.001→PT1204.002→PT1204.003→PT1204.004←MT1204.005→PT1207←M →PT1210→PT1211←M →PT1212→PT1213→PT1213.001→PT1213.002→PT1213.003→PT1213.004→PT1213.005→PT1213.006→PT1216←MT1218←MT1218.005←M →PT1218.007←MT1218.008←MT1218.010←MT1218.011←MT1218.012←MT1218.013←MT1218.015→PT1219.001→PT1219.003←MT1221←P →PT1222←MT1222.001←PT1222.002←MT1480.001←MT1484←M →PT1484.001→PT1484.002←M →PT1485→PT1486→PT1491→PT1491.001→PT1491.002→PT1495→PT1496→PT1496.001→PT1496.002→PT1496.003→PT1496.004→PT1497←PT1497.002←MT1498→PT1499←P →PT1499.002→PT1499.003→PT1499.004→PT1505→PT1505.001→PT1505.002→PT1505.003→PT1505.004→PT1525→PT1528→PT1530→PT1534→PT1535←MT1537←M →PT1538→PT1539←F →PT1542←MT1542.002←M →PT1542.004→PT1542.005→PT1543.002→PT1543.003→PT1543.005→PT1546→PT1546.001→PT1546.004→PT1546.007→PT1546.008→PT1546.013→PT1546.015→PT1546.016→PT1547.001→PT1547.006→PT1547.007→PT1547.012→PT1548→PT1548.001→PT1548.002←MT1548.003→PT1548.005→PT1548.006→PT1550←F →PT1550.001←F →PT1550.002←FT1550.003←F →PT1550.004←F →PT1552→PT1552.001→PT1552.004→PT1552.005→PT1552.006→PT1552.007→PT1552.008→PT1553.001←FT1553.002←PT1553.003←M →PT1553.004←M →PT1553.005←MT1553.006←M →PT1554→PT1555.006→PT1556←M →PT1556.003→PT1556.005←P →PT1556.006←P →PT1556.007←M →PT1556.008→PT1556.009←M →PT1557→PT1557.001→PT1557.003→PT1558→PT1558.001→PT1558.002→PT1558.004→PT1559.002→PT1559.003→PT1561.002→MT1563→PT1563.001→PT1564←MT1564.001←MT1564.004←MT1564.006→PT1565→PT1565.001→PT1565.002→PT1565.003→PT1566→PT1566.001→PT1566.002→PT1566.003←M →PT1566.004→PT1567→PT1567.001→PT1567.002→PT1567.003→PT1567.004→PT1568←MT1571←MT1572←M →PT1574←P →PT1574.001←M →PT1574.005→PT1574.007→PT1574.008→PT1574.009→PT1574.010→PT1574.011→PT1574.012→PT1574.013←PT1578←MT1578.001←MT1578.002←M →PT1578.003←MT1578.004←MT1578.005←M →PT1580→PT1583.001→PT1584→PT1584.001→PT1586→PT1586.003→PT1587.001→PT1587.004→PT1588.005→PT1589→PT1589.001→PT1589.003→PT1590.003→PT1591.002→PT1593.003→PT1598→PT1598.001→PT1598.002→PT1598.003→PT1598.004→PT1599←M →PT1599.001←MT1600←P →PT1600.001→PT1601→PT1601.001←P →PT1601.002←PT1602→PT1602.001→PT1602.002→PT1606←M →PT1606.001←F →PT1606.002←M →PT1608.004→PT1608.005→PT1609→PT1610←P →PT1611→PT1612←P →PT1620←MT1621←M →PT1622←PT1647←PT1648→PT1649→PT1650→PT1653←PT1657→PT1665←PT1666←M →PT1671→PT1675→PT1677←P →PT1678←PT1684→PT1684.001→PT1684.002←M →PT1685←MT1685.001→PT1685.002←M →PT1685.003←MT1685.004←MT1685.005←MT1686←FT1686.001←M →PT1686.002→PT1686.003←MT1687←P →PT1688←MT1689←M →PT1690←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (15)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.