Cyber Resilience

← ISO 27001 Annex A

A.6.7 People

Remote working

AttributesPreventiveC·I·AProtectAsset managementInformation protectionPhysical securitySystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (19)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (30)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (11)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (3)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (287)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.003←MT1005→PT1006←MT1011←M →PT1011.001←PT1016.002→PT1021→PT1021.001→PT1021.004→PT1021.005←M →PT1021.006→PT1021.008→PT1027.002←MT1027.006←PT1027.008←PT1027.011←PT1027.014←MT1030←PT1036←MT1036.003←MT1036.005←MT1036.008←MT1040→PT1041→PT1048→PT1048.003←M →PT1052←P →PT1052.001←P →PT1055←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056.001→PT1070←MT1070.010←MT1071←MT1071.001←MT1071.004←M →PT1078→PT1078.004←M →PT1090←PT1090.002←MT1090.003←MT1095←MT1098.005←M →PT1102←MT1102.001←MT1102.002←MT1110→PT1110.001→MT1110.003→PT1110.004→PT1111←M →PT1123→PT1127←MT1133→PT1134←PT1137.001→PT1185←MT1187→PT1189←M →PT1200←P →PT1204→PT1204.001←M →PT1204.002→PT1204.004→PT1205←PT1207←PT1210→PT1218←PT1218.005←P →PT1218.013←PT1219→PT1219.001→PT1219.002←M →PT1219.003←M →PT1221←PT1222←PT1222.001←PT1222.002←MT1480.001←MT1484←PT1484.002←PT1485→PT1486→PT1490←P →PT1498→PT1499←P →PT1528→PT1530→PT1534→PT1535←MT1537←MT1539←M →PT1542←MT1542.002←PT1546.002→PT1550←MT1550.001←MT1550.002←MT1550.003←MT1550.004←FT1552.001→PT1552.008→PT1553.001←PT1553.003←PT1553.004←PT1553.005←MT1553.006←PT1556←MT1556.006←MT1556.007←MT1556.009←MT1557←M →PT1557.001→PT1557.002→PT1557.004→PT1561←P →MT1561.001→PT1561.002→MT1563→PT1563.001→PT1563.002←P →PT1565.001→PT1565.002→PT1566→PT1566.001→PT1566.002→PT1566.003←P →PT1566.004→PT1567→PT1567.001→PT1567.002→PT1567.004→PT1568←PT1571←MT1572←MT1574←PT1574.001←PT1574.013←PT1578←PT1578.001←MT1578.002←MT1578.003←PT1578.004←MT1578.005←PT1584←PT1584.008←MT1587.001←PT1588.001←PT1589.001→PT1598→PT1598.001→PT1598.002→PT1598.003←M →PT1598.004→PT1599←MT1599.001←PT1600←PT1600.001←PT1601.001←PT1601.002←MT1606←MT1606.001←FT1608.004←PT1610←PT1620←MT1621←PT1647←PT1653←PT1665←PT1666←PT1669→PT1684→PT1684.001→PT1685←MT1685.003←PT1685.005←MT1686←M →PT1686.001←PT1686.002←MT1686.003←MT1687←PT1688←MT1689←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (2)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.