Cyber Resilience

← ISO 27001 Annex A

A.8.3 Technological

Information access restriction

AttributesPreventiveC·I·AProtectIdentity and access managementProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (12)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (11)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (14)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (242)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

CWE-1057←PCWE-1083←P →PCWE-1191←P →PCWE-1220←M →PCWE-1230←P →PCWE-1231←PCWE-1244←P →PCWE-1256←P →PCWE-1257←P →PCWE-1259←P →MCWE-1260→PCWE-1262←P →PCWE-1268←P →PCWE-1272←PCWE-1274←P →PCWE-1280←P →PCWE-1299←P →PCWE-1323←P →MCWE-15←P →MCWE-178←PCWE-200→FCWE-202←P →MCWE-213←P →PCWE-214←P →PCWE-219←P →MCWE-22←P →PCWE-23→PCWE-24→PCWE-25→PCWE-266←P →PCWE-267→PCWE-268←P →PCWE-269→MCWE-27→PCWE-270←P →PCWE-272→PCWE-274←P →MCWE-277←PCWE-278←P →PCWE-279←PCWE-28←P →PCWE-280←PCWE-281←PCWE-282←PCWE-283←P →PCWE-284→FCWE-285→MCWE-286→PCWE-288←P →PCWE-289←P →PCWE-290←P →PCWE-291←P →PCWE-30→PCWE-302←P →PCWE-304←P →PCWE-305←P →PCWE-308←PCWE-314→PCWE-317←PCWE-32→PCWE-35→PCWE-36→PCWE-37→PCWE-378→PCWE-379→PCWE-38→PCWE-40←P →PCWE-402←P →FCWE-408←P →PCWE-412←P →PCWE-419←P →MCWE-420→MCWE-421←P →PCWE-424←P →MCWE-425←M →MCWE-441←PCWE-454→PCWE-471←P →PCWE-488←P →PCWE-507→PCWE-520←P →PCWE-524←P →MCWE-527←P →MCWE-528←P →PCWE-529←P →MCWE-530←P →MCWE-548←P →FCWE-551←P →PCWE-556←P →PCWE-564←PCWE-566←P →MCWE-57←P →PCWE-602→MCWE-603←P →PCWE-61←P →PCWE-610→PCWE-612←P →FCWE-62←P →PCWE-638←P →PCWE-639←P →MCWE-64→PCWE-642←P →MCWE-647←P →PCWE-65←P →MCWE-653←P →PCWE-654←P →PCWE-669←P →PCWE-671←PCWE-673←PCWE-689←P →PCWE-69←P →PCWE-706←P →PCWE-708←P →PCWE-73→PCWE-732→MCWE-749←P →PCWE-767←PCWE-782←P →PCWE-784←P →MCWE-807→PCWE-837←PCWE-842→PCWE-862→MCWE-863→PCWE-915→PCWE-921←P →MCWE-926←P →MCWE-939←P →MCWE-99→P
Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (6)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (4)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.