Cyber Resilience

← ISO 27001 Annex A

A.8.24 Technological

Use of cryptography

AttributesPreventiveC·I·AProtectSecure configurationProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (18)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (18)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (12)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (152)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (284)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←MT1006←MT1011←MT1014←MT1021.004→PT1027→PT1027.001←MT1027.002←MT1027.003←MT1027.005←MT1027.006←MT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←PT1027.012←MT1027.013←MT1027.014←MT1027.015←MT1027.016←MT1027.017←MT1027.018←MT1030←MT1036←MT1036.003←MT1036.005←MT1036.008←MT1036.009←PT1040→MT1041→PT1048→PT1048.001→PT1048.003←M →PT1052←MT1055←M →PT1055.001←MT1055.002←MT1055.003←M →PT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1068←PT1070←MT1071.001←MT1071.004←MT1071.005←MT1078←P →PT1090←MT1090.002←MT1090.003←MT1090.004←MT1095←MT1098.001←MT1098.004←MT1098.005←MT1102←MT1102.001←MT1102.002←MT1102.003←MT1110→MT1110.001→MT1110.002→MT1110.003→MT1110.004→MT1111←M →PT1127←MT1127.001←MT1132←PT1132.001←MT1132.002←MT1133←MT1134←MT1185←MT1204.004←PT1205←PT1207←MT1211←PT1216←MT1218←MT1218.005←MT1218.007←MT1218.008←MT1218.009←MT1218.010←MT1218.011←PT1218.012←MT1218.013←MT1219.003←MT1220←PT1221←PT1222.002←MT1480.001←MT1484←PT1484.002←PT1485→PT1486→MT1490←MT1497←PT1499.002←PT1528→PT1530→PT1535←MT1537←MT1539←F →PT1542←MT1542.002←MT1542.003←MT1548←PT1550←FT1550.001←FT1550.002←FT1550.003←F →PT1550.004←FT1552←M →PT1552.001←P →PT1552.004→PT1553←P →PT1553.001←MT1553.002←PT1553.003←MT1553.004←MT1553.005←PT1553.006←MT1555→PT1555.001←M →PT1555.002←PT1555.003←MT1555.004→PT1555.005←P →PT1555.006←M →PT1556←MT1556.001←MT1556.003←PT1556.005←P →PT1556.006←MT1556.007←MT1556.008←MT1556.009←MT1557←M →MT1557.004←M →PT1558←M →PT1558.001←PT1558.002←MT1558.003→PT1558.004→PT1560←P →PT1561→PT1561.001→MT1561.002→MT1565→PT1565.001→PT1565.002←P →PT1567.004←PT1568.003←MT1571←MT1572←M →PT1573←MT1573.001→PT1573.002→PT1574←PT1574.001←MT1574.004←MT1574.013←MT1578←PT1578.002←MT1578.003←MT1578.004←MT1588.004←PT1589.001→PT1599←MT1599.001←PT1600←M →PT1600.001→MT1600.002←MT1601.001←MT1601.002←MT1606←MT1606.001←F →PT1606.002←M →PT1610←PT1612←PT1620←MT1621←M →MT1622←MT1647←PT1649→PT1665←PT1666←PT1678←PT1684.002→PT1685←MT1685.002←MT1685.003←PT1685.004←MT1685.005←MT1686←FT1686.001←MT1686.003←MT1687←PT1688←MT1689←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (5)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.