Cyber Resilience

← ISO 27001 Annex A

A.8.1 Technological

User end point devices

AttributesPreventiveC·I·AProtectAsset managementInformation protectionProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (24)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (25)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (6)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Related weaknesses / CWE (7)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (896)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←MT1003→PT1003.001→PT1003.002→PT1003.004→PT1003.005→PT1003.008→PT1005←P →PT1006←M →PT1011←M →PT1011.001←M →PT1014←M →PT1016.002←M →PT1020→PT1021←M →PT1021.001←P →PT1021.002→PT1021.004→PT1021.005→PT1021.006→PT1025←M →PT1027→PT1027.001←MT1027.002←MT1027.003←PT1027.004→PT1027.005←MT1027.006←M →PT1027.007←MT1027.008←MT1027.009←M →PT1027.010←MT1027.011←M →PT1027.012←PT1027.013←MT1027.014←MT1027.015←PT1027.016←MT1027.017←M →PT1027.018←MT1030←MT1036←MT1036.002←MT1036.003←M →PT1036.004→PT1036.005←MT1036.007←M →PT1036.008←M →PT1036.009←M →PT1036.012←MT1037→PT1037.001→PT1037.002←P →PT1037.003→PT1037.004→PT1037.005→PT1040←M →PT1041→PT1046→PT1047→PT1048←M →PT1048.001→PT1048.002→PT1048.003←M →PT1052←M →PT1052.001←M →PT1053→PT1053.002→PT1053.005←M →PT1055←M →PT1055.001←M →PT1055.002←M →PT1055.003←M →PT1055.004←M →PT1055.005←MT1055.008←M →PT1055.009←M →PT1055.011←MT1055.012←M →PT1055.013←M →PT1055.014←M →PT1055.015←M →PT1056←P →PT1056.001←P →PT1056.002←M →PT1056.004←P →PT1059←M →PT1059.001→PT1059.002→PT1059.004→PT1059.005→PT1059.006→PT1059.007→PT1059.008←PT1059.010→PT1068←M →PT1070←MT1070.003←MT1070.006←MT1070.010←MT1071←MT1071.001←M →PT1071.002←MT1071.004←M →PT1071.005←PT1072←M →PT1074→PT1074.001→PT1074.002→PT1078→PT1078.001→PT1078.002←PT1078.003←P →PT1078.004←MT1080←P →PT1083→PT1090←MT1090.002←M →PT1090.003←MT1090.004←MT1091→PT1092←M →PT1095←MT1098.004→PT1098.005→PT1102→PT1102.001←MT1102.002←M →PT1102.003←M →PT1105←P →PT1110←P →PT1110.001→MT1110.002→PT1110.003←M →PT1110.004→PT1111←P →PT1112←PT1113→PT1114.001←P →PT1119→PT1120→PT1123←P →PT1125←P →PT1127←M →PT1127.001←M →PT1127.002←M →PT1127.003→PT1132.001←PT1132.002←PT1133←M →PT1134←MT1134.001←PT1134.002←PT1134.003←P →PT1134.004←MT1137→PT1137.001→PT1137.002→PT1137.004→PT1137.006←P →PT1176←M →PT1176.001←M →PT1176.002←P →PT1185→PT1187→PT1189←M →PT1195←PT1197→PT1200→PT1202←MT1203←M →PT1204→PT1204.001←M →PT1204.002←M →PT1204.003←M →PT1204.004←M →PT1204.005←M →PT1205←MT1205.001←P →PT1207←MT1210←P →PT1211←PT1216←M →PT1216.001←M →PT1216.002←P →PT1217→PT1218←M →PT1218.001←P →PT1218.002←M →PT1218.003←M →PT1218.004←M →PT1218.005←M →PT1218.007←M →PT1218.008←M →PT1218.009←P →PT1218.010←M →PT1218.011←M →PT1218.012←P →PT1218.013←M →PT1218.014→PT1218.015←P →PT1219←M →PT1219.001←P →PT1219.002←M →PT1219.003←M →PT1220←M →PT1221←M →PT1222←MT1222.001←M →PT1222.002←M →PT1480←PT1480.001←MT1484←MT1484.001←MT1484.002←PT1485←P →PT1485.001→MT1486→MT1489←P →PT1490←M →MT1491.001→PT1496←P →PT1496.001→PT1496.002←P →PT1497←MT1497.001←PT1497.002←PT1498→PT1499←P →PT1499.001→PT1499.004←PT1505.005←PT1518.001→PT1518.002→PT1528←P →PT1529→PT1530→PT1534→PT1535←MT1537←MT1539→PT1542←MT1542.001←PT1542.002←MT1542.003←M →PT1543→PT1543.001←P →PT1543.002→PT1543.003←PT1543.004←P →PT1546.001←M →PT1546.002←P →PT1546.003→PT1546.004→PT1546.006←P →PT1546.007→PT1546.008→PT1546.009→PT1546.010→PT1546.011←P →PT1546.012←PT1546.013→PT1546.014→PT1546.016←P →PT1546.017→PT1547←P →PT1547.001←M →PT1547.003→PT1547.004→PT1547.005←P →PT1547.006←P →PT1547.007→PT1547.009←P →PT1547.010→PT1547.012→PT1547.013→PT1547.015←P →PT1548←M →PT1548.002←P →PT1548.003←P →PT1548.004←P →PT1548.006←M →PT1550←MT1550.001←MT1550.002←MT1550.003←MT1550.004←F →PT1552←P →PT1552.001←P →PT1552.003→PT1552.004←P →PT1552.008←P →PT1553←M →PT1553.001←M →PT1553.002←PT1553.003←MT1553.004←M →PT1553.005←M →PT1553.006←M →PT1554←P →PT1555←P →PT1555.001→PT1555.003→PT1555.004→PT1555.005→PT1555.006→PT1556←MT1556.001←PT1556.002←FT1556.003←PT1556.006←MT1556.007←MT1556.008←P →PT1556.009←MT1557←M →PT1557.001→PT1557.003←MT1557.004→PT1558.005→PT1559.002→PT1560.001→PT1561←P →MT1561.001→MT1561.002←P →MT1563→PT1563.001→PT1563.002←M →PT1564→PT1564.004←PT1564.006→PT1564.009→PT1564.012→PT1565.001→MT1566→PT1566.001→PT1566.002→PT1566.003←M →PT1567→PT1567.001→PT1567.002←P →PT1567.003→PT1567.004→PT1568←PT1568.002←MT1569→PT1570→PT1571←M →PT1572←M →PT1573←MT1574←M →PT1574.001←M →PT1574.004←M →PT1574.005←P →PT1574.006→PT1574.007←P →PT1574.008←P →PT1574.009←P →PT1574.010←PT1574.012←PT1574.013←PT1574.014→PT1578←MT1578.001←PT1578.002←MT1578.003←MT1578.004←MT1578.005←PT1583.008←PT1587.001←MT1588.001←MT1588.002←PT1589.001→PT1598.002←PT1598.003←M →PT1599←MT1599.001←PT1600←PT1600.001←PT1600.002←PT1601.001←PT1601.002←MT1606←MT1606.001←MT1608.004←M →PT1608.005←PT1610←PT1611←P →PT1612←PT1620←M →PT1621←M →PT1622←PT1647←P →PT1649→PT1653←P →PT1657→PT1659→PT1669←M →PT1674←P →PT1678←PT1679←PT1680→PT1684←M →PT1685←M →PT1685.002←MT1685.003←MT1685.004←MT1685.005←MT1685.006←MT1686←M →PT1686.001←MT1686.002←MT1686.003←M →PT1687←P →PT1688←MT1689←M →PT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (10)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.