Cyber Resilience

← ISO 27001 Annex A

A.8.27 Technological

Secure system architecture and engineering principles

AttributesPreventiveC·I·AProtectApplication securitySystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (14)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (11)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (15)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (776)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

CWE-1007←P →PCWE-1021←P →PCWE-1022←P →PCWE-1023←P →PCWE-1024←PCWE-1037←PCWE-1038←P →PCWE-1039←P →PCWE-1049←P →PCWE-1051→PCWE-1055←P →PCWE-1057→PCWE-1058←P →PCWE-1059←P →MCWE-1066←P →PCWE-1067←P →PCWE-1068→PCWE-1072→PCWE-1076←P →MCWE-1083←P →MCWE-1088←P →PCWE-1091←P →PCWE-1100←P →MCWE-1102←PCWE-1103←P →PCWE-1106→PCWE-1107←P →PCWE-1108←P →PCWE-111←P →PCWE-112→PCWE-1124←PCWE-1125←P →MCWE-113→PCWE-114←P →PCWE-115←P →PCWE-116→PCWE-1173→PCWE-1176←PCWE-118←P →PCWE-1189←P →MCWE-119←P →PCWE-1190←P →MCWE-1191←P →PCWE-120←P →PCWE-121←P →PCWE-122←P →PCWE-1221←P →PCWE-1222←P →PCWE-1223←P →MCWE-1224←P →PCWE-123←P →PCWE-1231←P →PCWE-1233←P →PCWE-1234←P →PCWE-1236→PCWE-124←P →PCWE-1240←P →PCWE-1241→PCWE-1242←P →PCWE-1244←P →PCWE-1245←P →PCWE-1246←P →PCWE-1247←P →PCWE-125←P →PCWE-1250←P →MCWE-1251←P →PCWE-1253←P →PCWE-1254←P →PCWE-1255←P →PCWE-1256←P →PCWE-1257←P →MCWE-1258←P →PCWE-1259→PCWE-126←P →PCWE-1260←P →PCWE-1262→PCWE-1264←P →PCWE-1265←P →PCWE-127←P →PCWE-1274←P →PCWE-1278←P →PCWE-1279←P →PCWE-128←P →PCWE-1280→PCWE-1281←P →PCWE-1282←P →PCWE-1283←P →PCWE-1284→PCWE-1285←P →PCWE-1286→PCWE-1287←P →PCWE-1288→PCWE-1289←P →PCWE-129→PCWE-1298←P →PCWE-1299←P →MCWE-130←P →PCWE-1300→PCWE-1303←P →PCWE-131←P →PCWE-1310→PCWE-1312←P →PCWE-1313←P →PCWE-1314←P →MCWE-1316←P →MCWE-1319→PCWE-1320←P →PCWE-1321→PCWE-1322←P →PCWE-1323←P →PCWE-1325→PCWE-1326←P →PCWE-1327←P →MCWE-1328→PCWE-1332←P →PCWE-1333→PCWE-1334→PCWE-1335←PCWE-1336→PCWE-134←P →PCWE-1341←PCWE-1342→PCWE-135←P →PCWE-138→PCWE-1385←P →PCWE-1386←P →PCWE-141→PCWE-142←P →PCWE-143→PCWE-144→PCWE-145→PCWE-146→PCWE-147→PCWE-148←P →PCWE-149→PCWE-150→PCWE-154→PCWE-155→PCWE-156→PCWE-157→PCWE-158→PCWE-159→PCWE-160→PCWE-162→PCWE-164→PCWE-166→PCWE-167←P →PCWE-168→PCWE-170←PCWE-172←P →PCWE-173←P →PCWE-176←P →PCWE-178←P →PCWE-179→PCWE-180→PCWE-182←P →PCWE-183←P →PCWE-184←P →PCWE-187←PCWE-188←P →PCWE-190←PCWE-191←P →PCWE-192←P →PCWE-193←P →PCWE-194←P →PCWE-195←P →PCWE-196←P →PCWE-197←PCWE-198←P →PCWE-20→PCWE-200→PCWE-204←P →PCWE-205←P →PCWE-207→PCWE-209→PCWE-210→PCWE-219←P →MCWE-22←P →PCWE-228→PCWE-229→PCWE-23←P →PCWE-231→PCWE-232←P →PCWE-234←PCWE-237←P →PCWE-24→PCWE-240←P →PCWE-241→PCWE-248←P →PCWE-25→PCWE-252←PCWE-253←P →PCWE-26→PCWE-267→PCWE-269→PCWE-27→PCWE-270←P →PCWE-277←P →PCWE-28←P →PCWE-284→PCWE-287→PCWE-288→PCWE-29←P →PCWE-290←P →PCWE-297←P →PCWE-30→PCWE-301→PCWE-306→PCWE-31→PCWE-32→PCWE-322→PCWE-329→PCWE-332→PCWE-333→PCWE-337→PCWE-338→PCWE-34→PCWE-342→PCWE-343→PCWE-344→PCWE-346→PCWE-348→MCWE-349←P →PCWE-35←P →PCWE-350←P →PCWE-351←P →PCWE-353←P →PCWE-356→PCWE-357←P →PCWE-358←P →PCWE-36←P →PCWE-360←P →PCWE-362←P →PCWE-363←P →PCWE-364←PCWE-366←P →PCWE-368←P →PCWE-369←P →PCWE-37←P →PCWE-372←P →PCWE-374←P →PCWE-377→PCWE-378←P →PCWE-379←P →PCWE-38→PCWE-385→PCWE-386←P →PCWE-39←P →PCWE-391←PCWE-40←P →PCWE-401←P →PCWE-407←P →PCWE-409→PCWE-41←P →PCWE-410→PCWE-412→PCWE-413←P →PCWE-415→PCWE-416←P →PCWE-419←P →PCWE-42←P →PCWE-421←P →PCWE-422←P →PCWE-424←P →PCWE-426←P →PCWE-427←P →PCWE-428←PCWE-43←P →PCWE-430←P →PCWE-431←P →PCWE-433→PCWE-435←P →MCWE-436←P →PCWE-437←P →PCWE-44←P →PCWE-441←P →PCWE-444←P →PCWE-446→PCWE-450←P →PCWE-453←P →PCWE-454←P →PCWE-455←P →PCWE-456←PCWE-46←P →PCWE-460←P →PCWE-462←PCWE-466←PCWE-469←PCWE-470←P →PCWE-471→PCWE-474←PCWE-475←P →PCWE-476←P →PCWE-479←PCWE-488←P →PCWE-491←P →PCWE-495←P →PCWE-499←P →PCWE-50←P →PCWE-501←P →MCWE-514←P →PCWE-515←P →PCWE-523→PCWE-526←P →PCWE-535→PCWE-544←P →PCWE-548←P →PCWE-550←P →PCWE-551←P →PCWE-553→PCWE-556→PCWE-562←PCWE-564→PCWE-566→PCWE-567←P →PCWE-57→PCWE-573←P →PCWE-587←P →PCWE-588←P →PCWE-59←P →PCWE-590←P →PCWE-598→PCWE-600←P →PCWE-602→MCWE-603←P →MCWE-605←P →PCWE-61←P →PCWE-610←P →PCWE-611→PCWE-616→PCWE-617←P →PCWE-618←P →PCWE-62←P →PCWE-621→PCWE-622←P →PCWE-623→PCWE-624←PCWE-626←P →PCWE-627←P →PCWE-637←P →MCWE-641→PCWE-642→MCWE-643→PCWE-644→PCWE-646←P →PCWE-648←P →PCWE-649←P →PCWE-65←P →PCWE-650←P →PCWE-652→PCWE-653←P →MCWE-656←P →MCWE-657←F →FCWE-66←P →PCWE-662←P →PCWE-663←P →PCWE-664→PCWE-665←P →PCWE-667←P →PCWE-669←P →PCWE-67→PCWE-674→PCWE-675←P →PCWE-680←P →PCWE-681←P →PCWE-682←PCWE-686←PCWE-687←P →PCWE-689←P →PCWE-690←P →PCWE-691←P →PCWE-695←P →PCWE-696←P →PCWE-697←P →PCWE-698←P →PCWE-704←PCWE-706←P →PCWE-707←P →PCWE-73→PCWE-732→PCWE-74→PCWE-749←P →PCWE-75→PCWE-754←P →PCWE-755←P →PCWE-757→PCWE-758←PCWE-76←P →PCWE-760→PCWE-762←PCWE-763←P →PCWE-764←P →PCWE-765←P →PCWE-767←P →PCWE-768←PCWE-77→PCWE-771←P →PCWE-774←P →PCWE-776→PCWE-780→PCWE-782→PCWE-786←P →PCWE-787←P →PCWE-788←P →PCWE-789←P →PCWE-790←P →PCWE-791←P →PCWE-792→PCWE-794→PCWE-799→PCWE-805←P →PCWE-807←P →PCWE-81→PCWE-82←P →PCWE-820←P →PCWE-821←P →PCWE-822←P →PCWE-823←PCWE-824←PCWE-825→PCWE-826←P →PCWE-827←P →PCWE-828←PCWE-83→PCWE-830←P →MCWE-832←P →PCWE-833←P →PCWE-834←P →PCWE-839←P →PCWE-841←P →PCWE-843←P →PCWE-862→PCWE-87→PCWE-88←P →PCWE-908←P →PCWE-909→PCWE-91→PCWE-910←PCWE-911←P →PCWE-912←P →PCWE-913←P →PCWE-914←P →PCWE-915←P →PCWE-917→PCWE-923→PCWE-925←P →PCWE-926→PCWE-927←P →PCWE-93→PCWE-941→PCWE-942←P →PCWE-943→PCWE-95→PCWE-96→PCWE-97→PCWE-98→PCWE-99→P
Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (9)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (6)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.