CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/iso27001-test-patterns

Reference catalog of ISO/IEC 27001:2022 Annex A test patterns: testable technical controls with code-level assertions for access control (A.8.2-A.8.5), logging and monitoring (A.8.15-A.8.16), cryptography (A.8.24), and secure development (A.8.25-A.8.31), plus evidence patterns for Stage 1 and Stage 2 certification audits and Statement of Applicability scoping. The full 93-control Annex A index (four themes: organizational A.5, people A.6, physical A.7, technological A.8) and the exhaustive per-control test code live in references/. Use when authoring ISMS test coverage for an ISO 27001:2022 certification engagement or gap assessment.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

annex-a-control-index.mdreferences/

Annex A control index (ISO/IEC 27001:2022)

Deep reference for iso27001-test-patterns SKILL.md. The full 93-control enumeration across the four Annex A themes. Consult when scoping a Statement of Applicability or checking which theme a control belongs to; the SKILL.md keeps only the four-theme summary and the testable-control shortlist.

ISO/IEC 27001:2022 restructured Annex A from 114 controls (2013 edition) to 93 controls across four themes, adding 11 new controls for cloud, threat intelligence, secure coding, and monitoring. All control IDs, names, and counts below are sourced from isms.online/iso-27001/annex-a (fetched 2026-06-04); the canonical standard text is paywalled at iso.org and is cited by stable ID "ISO/IEC 27001:2022".

A.5 Organizational controls (37 controls)

Most A.5 controls are verified by document review, policy attestation, or access-control test. The exceptions with automated test patterns are A.5.3 (segregation of duties) and A.5.34 (PII protection) - both in technical-control-test-patterns.md.

IDControl name
A.5.1Policies for Information Security
A.5.2Information Security Roles and Responsibilities
A.5.3Segregation of Duties
A.5.4Management Responsibilities
A.5.5Contact With Authorities
A.5.6Contact With Special Interest Groups
A.5.7Threat Intelligence (NEW 2022)
A.5.8Information Security in Project Management
A.5.9Inventory of Information and Other Associated Assets
A.5.10Acceptable Use of Information and Other Associated Assets
A.5.11Return of Assets
A.5.12Classification of Information
A.5.13Labelling of Information
A.5.14Information Transfer
A.5.15Access Control
A.5.16Identity Management
A.5.17Authentication Information
A.5.18Access Rights
A.5.19Information Security in Supplier Relationships
A.5.20Addressing Information Security Within Supplier Agreements
A.5.21Managing Information Security in the ICT Supply Chain
A.5.22Monitoring, Review and Change Management of Supplier Services
A.5.23Information Security for Use of Cloud Services (NEW 2022)
A.5.24Information Security Incident Management Planning and Preparation
A.5.25Assessment and Decision on Information Security Events
A.5.26Response to Information Security Incidents
A.5.27Learning From Information Security Incidents
A.5.28Collection of Evidence
A.5.29Information Security During Disruption
A.5.30ICT Readiness for Business Continuity (NEW 2022)
A.5.31Legal, Statutory, Regulatory and Contractual Requirements
A.5.32Intellectual Property Rights
A.5.33Protection of Records
A.5.34Privacy and Protection of PII
A.5.35Independent Review of Information Security
A.5.36Compliance With Policies, Rules and Standards for Information Security
A.5.37Documented Operating Procedures

A.6 People controls (8 controls)

A.6 controls are verified by HR records, contract review, training completion records, and offboarding audits. A.6.8 (Information Security Event Reporting) has an automated test pattern - see technical-control-test-patterns.md.

IDControl name
A.6.1Screening
A.6.2Terms and Conditions of Employment
A.6.3Information Security Awareness, Education and Training
A.6.4Disciplinary Process
A.6.5Responsibilities After Termination or Change of Employment
A.6.6Confidentiality or Non-Disclosure Agreements
A.6.7Remote Working
A.6.8Information Security Event Reporting

A.7 Physical controls (14 controls)

A.7 controls are verified by site inspection, physical access-log review, and equipment maintenance records. No automated code-level test patterns exist for A.7; evidence is operational.

IDControl name
A.7.1Physical Security Perimeters
A.7.2Physical Entry
A.7.3Securing Offices, Rooms and Facilities
A.7.4Physical Security Monitoring (NEW 2022)
A.7.5Protecting Against Physical and Environmental Threats
A.7.6Working In Secure Areas
A.7.7Clear Desk and Clear Screen
A.7.8Equipment Siting and Protection
A.7.9Security of Assets Off-Premises
A.7.10Storage Media
A.7.11Supporting Utilities
A.7.12Cabling Security
A.7.13Equipment Maintenance
A.7.14Secure Disposal or Re-Use of Equipment

A.8 Technological controls (34 controls)

NEW = added in the 2022 revision. The A.8.x controls verifiable through automated tests have code patterns in technical-control-test-patterns.md.

A.8.1 User Endpoint Devices / A.8.2 Privileged Access Rights / A.8.3 Information Access Restriction / A.8.4 Access to Source Code / A.8.5 Secure Authentication / A.8.6 Capacity Management / A.8.7 Protection Against Malware / A.8.8 Management of Technical Vulnerabilities / A.8.9 Configuration Management (NEW) / A.8.10 Information Deletion (NEW) / A.8.11 Data Masking (NEW) / A.8.12 Data Leakage Prevention (NEW) / A.8.13 Information Backup / A.8.14 Redundancy of Information Processing Facilities / A.8.15 Logging / A.8.16 Monitoring Activities (NEW) / A.8.17 Clock Synchronization / A.8.18 Use of Privileged Utility Programs / A.8.19 Installation of Software on Operational Systems / A.8.20 Networks Security / A.8.21 Security of Network Services / A.8.22 Segregation of Networks / A.8.23 Web Filtering (NEW) / A.8.24 Use of Cryptography / A.8.25 Secure Development Life Cycle / A.8.26 Application Security Requirements / A.8.27 Secure System Architecture and Engineering Principles / A.8.28 Secure Coding (NEW) / A.8.29 Security Testing in Development and Acceptance / A.8.30 Outsourced Development / A.8.31 Separation of Development, Test and Production Environments / A.8.32 Change Management / A.8.33 Test Information / A.8.34 Protection of Information Systems During Audit Testing

Source

  • isms.online/iso-27001/annex-a - community Annex A reference (control IDs, names, counts; fetched 2026-06-04)
  • iso.org/standard/27001 - canonical ISO/IEC 27001:2022 standard text (paywalled; cite by stable ID "ISO/IEC 27001:2022")

SKILL.md

tile.json