Cyber Resilience

← ISO 27001 Annex A

A.8.21 Technological

Security of network services

AttributesPreventiveC·I·AProtectSystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (26)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (23)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (12)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (49)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (1023)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←M →PT1001.001←M →PT1001.002←M →PT1001.003←M →PT1003.003→PT1003.005←M →PT1003.006→PT1003.008→PT1006←MT1007→PT1008←M →PT1011←M →PT1011.001←M →PT1014←MT1016.001→PT1016.002→PT1018→PT1020←M →PT1020.001←P →PT1021→PT1021.001→PT1021.002←M →PT1021.003→PT1021.004←P →PT1021.005→PT1021.006←P →PT1021.007←M →PT1021.008←M →PT1027.001←MT1027.002←MT1027.003←MT1027.005←MT1027.006←M →PT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←MT1027.014←MT1027.016←MT1027.017←MT1027.018←MT1029←P →PT1030←M →PT1036←MT1036.003←MT1036.005←MT1036.007←MT1036.008←MT1036.009←MT1036.012←M →PT1037.001→PT1037.003→PT1037.004→PT1039←M →PT1040→PT1041←M →PT1046←M →PT1047←M →PT1048←M →PT1048.001←M →PT1048.002←M →PT1048.003←M →PT1049→PT1052←MT1052.001←P →PT1053→PT1053.002→PT1053.003→PT1053.005→PT1053.007→PT1055←M →PT1055.001←M →PT1055.002←M →PT1055.003←M →PT1055.004←M →PT1055.005←M →PT1055.008←M →PT1055.009←M →PT1055.011←M →PT1055.012←MT1055.013←M →PT1055.014←M →PT1055.015←M →PT1056←M →PT1056.001→PT1056.003→PT1056.004←P →PT1057→PT1059→PT1059.004→PT1059.007→PT1059.008←M →PT1059.009←M →PT1059.013→PT1068←MT1069.002→PT1069.003→PT1070←MT1070.007←MT1070.010←MT1071←M →PT1071.001←M →PT1071.002←M →PT1071.003←M →PT1071.004←M →PT1071.005←M →PT1072←M →PT1074→PT1074.002←MT1078→PT1078.001←P →PT1078.002←P →PT1078.003←P →PT1078.004←M →PT1080←M →PT1087→PT1087.002→PT1087.003→PT1087.004→PT1090←M →PT1090.001←M →PT1090.002←M →PT1090.003←M →PT1090.004←M →PT1095←M →PT1098←P →PT1098.001←M →PT1098.003→PT1098.004←M →PT1098.005←M →PT1098.006→PT1098.007←P →PT1102←M →PT1102.001←M →PT1102.002←M →PT1102.003←M →PT1104←M →PT1105←M →PT1110→MT1110.001→MT1110.002→MT1110.003→MT1110.004→PT1111←M →PT1114.002←M →PT1114.003→PT1119→PT1123→PT1127←M →PT1127.001←M →PT1127.002→PT1127.003→PT1132←M →PT1132.001←P →PT1132.002←M →PT1133→PT1134←MT1134.001←MT1134.002←MT1134.003←P →PT1134.004←MT1134.005←MT1135←M →PT1137.001→PT1137.003→PT1137.004→PT1137.005→PT1176.001←P →PT1185←M →PT1187←P →PT1189←M →PT1190←M →PT1197←M →PT1199→PT1200←MT1202←MT1204←PT1204.001←M →PT1204.002←MT1204.004←PT1205←M →PT1205.001←M →PT1205.002←M →PT1207←MT1210←M →PT1211←MT1212←M →PT1213←M →PT1213.001→PT1213.002→PT1213.003←M →PT1213.005←P →PT1213.006→PT1216←M →PT1216.001←MT1216.002←M →PT1218←M →PT1218.003←P →PT1218.004←M →PT1218.005←M →PT1218.007←MT1218.008←P →PT1218.009→PT1218.010←PT1218.011←MT1218.012←M →PT1218.013←M →PT1218.014→PT1219→PT1219.001←M →PT1219.002←M →PT1219.003←M →PT1220←PT1221←PT1222←MT1222.001←MT1222.002←MT1480←PT1480.001←MT1484←M →PT1484.001→PT1484.002←M →PT1485.001←PT1486→MT1489←P →PT1490→MT1491.001→PT1491.002→PT1496←P →PT1496.001←P →PT1496.002→PT1496.003→PT1496.004←P →PT1497←MT1497.002←PT1498←M →PT1498.001←M →PT1498.002←M →PT1499←P →PT1499.001←M →PT1499.002←M →PT1499.003←P →PT1505.003←M →PT1505.005←MT1526→PT1528←M →PT1529→PT1530←M →PT1531←PT1534→PT1535←M →PT1537←M →PT1538←P →PT1539←M →PT1542←MT1542.002←MT1542.003←MT1542.005←M →PT1543.002→PT1543.003←M →PT1546→PT1546.002→PT1546.003→PT1546.004→PT1546.007→PT1546.010→PT1546.014→PT1546.017→PT1547.001→PT1547.003→PT1547.012→PT1548←PT1548.002←PT1548.003←P →PT1548.005→PT1548.006←M →PT1550←M →PT1550.001←M →PT1550.002←M →PT1550.003←M →PT1550.004→PT1552.001→PT1552.004←P →PT1552.005←M →PT1552.006→PT1552.007→PT1552.008←M →PT1553←PT1553.001←MT1553.002←PT1553.003←M →PT1553.004←M →PT1553.005←MT1553.006←MT1555.003→PT1555.006→PT1556→PT1556.001←M →PT1556.002←PT1556.003←M →PT1556.004←MT1556.005←P →PT1556.006←M →PT1556.007←M →PT1556.008←M →PT1556.009←M →PT1557←M →PT1557.001←M →PT1557.002←M →PT1557.003←M →PT1557.004←M →PT1558←M →PT1558.001←M →PT1558.002←M →PT1558.003←M →PT1558.004→PT1558.005←M →PT1560←PT1561←P →PT1561.002→MT1563→PT1563.001→PT1563.002←M →PT1564.006→PT1565.002←P →PT1566→PT1566.001→PT1566.002←M →PT1566.003←M →PT1566.004←MT1567→PT1567.001←M →PT1567.002←M →PT1567.003←M →PT1567.004←M →PT1568←M →PT1568.001←M →PT1568.002←M →PT1568.003←M →PT1569→PT1569.002→PT1569.003→PT1570←M →PT1571←M →PT1572←M →PT1573←M →PT1573.001←MT1573.002←M →PT1574←MT1574.001←M →PT1574.004→PT1574.005→PT1574.007→PT1574.008→PT1574.009→PT1574.010←M →PT1574.013←MT1578←M →PT1578.001←MT1578.002←M →PT1578.003←M →PT1578.004←MT1578.005←M →PT1580→PT1583←MT1583.001←MT1583.002←MT1583.006←MT1583.007←MT1583.008←MT1584←MT1584.001←M →PT1584.002←MT1584.003←MT1584.004←MT1584.006←MT1584.007←MT1584.008←M →PT1586←MT1586.002→PT1586.003←M →PT1587.001←PT1587.003←PT1588.004←PT1588.005←MT1589.001←M →PT1590.004→PT1595←M →PT1595.001→PT1595.002→PT1595.003→PT1598.001←MT1598.003←MT1599←M →PT1599.001←M →PT1600←M →PT1600.001←PT1600.002←PT1601←PT1601.001←M →PT1601.002←MT1602→PT1602.001←M →PT1602.002←M →PT1606←M →PT1606.001←M →PT1606.002←M →PT1608.004←MT1608.005←MT1608.006←PT1609→PT1610←P →PT1611←M →PT1612←M →PT1619←PT1620←M →PT1621←M →PT1622←FT1647←PT1648→PT1649←P →PT1651→PT1653←PT1659←M →PT1665←M →PT1666←MT1667→PT1669←M →MT1671←M →PT1675→PT1677→PT1678←MT1684←MT1684.002←M →PT1685←MT1685.001←M →PT1685.002←M →PT1685.003←MT1685.004←M →PT1685.005←MT1685.006←MT1686←M →PT1686.001←M →PT1686.002←M →PT1686.003←M →PT1687←MT1688←MT1689→PT1690←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (13)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.