FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / ISO/IEC 27001:2022

ISO/IEC 27001:2022: the rules AI agent steps rest on

Edition
ISO/IEC 27001:2022 (third edition, October 2022) with Amendment 1:2024
Checked current
2026-10-07
Official source
https://www.iso.org/standard/27001
Licence
The standard is licensed: each rule is our statement of its clause, cited, never quoted.
RuleOur statementSteps that cite it
ISO/IEC 27001:2022 Annex A 5.12 Classification of informationInformation is to be classified according to the organization's security needs, judged on confidentiality, integrity, availability and the requirements of relevant interested parties. Purpose (stated in ISO/IEC 27002:2022): ensures the protection needs of information are identified and understood according to its importance.KC-01 S1 Classify the information the vendor will handle
ISO/IEC 27001:2022 Annex A 5.16 Identity managementIdentities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights.KC-01 S6 Decide the vendor's access
ISO/IEC 27001:2022 Annex A 5.18 Access rightsAccess rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs.KC-01 S6 Decide the vendor's access; KC-08 S1 Find the leaver exceptions; KC-08 S3 Fix the still-open access
ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationshipsThe organization is to define and run processes and procedures that manage the information security risks arising from using suppliers' products or services. Purpose (stated in ISO/IEC 27002:2022): keeps security in supplier dealings at the level agreed with the supplier.KC-01 S2 Set the supplier tier; KC-01 S5 Assess the vendor's assurance report; KC-01 S8 Decide the onboarding outcome
ISO/IEC 27001:2022 Annex A 5.20 Addressing information security within supplier agreementsThe information security requirements that matter for each supplier are to be set and agreed with that supplier, depending on the type of relationship. Purpose (stated in ISO/IEC 27002:2022): makes the agreed security level for each supplier binding through written terms.KC-01 S4 Find the contract clause gaps
ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chainProcesses and procedures are to be defined and put in place to manage information security risks in the supply chain for ICT products and services. Purpose (stated in ISO/IEC 27002:2022): keeps security across the ICT product and service supply chain at the agreed level.KC-01 S5 Assess the vendor's assurance report
ISO/IEC 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier servicesOn a regular basis the organization is to monitor, review and evaluate suppliers' security practices and service delivery and to manage changes to them. Purpose (stated in ISO/IEC 27002:2022): keeps security and service delivery at the levels the supplier agreements set.KC-01 S5 Assess the vendor's assurance report
ISO/IEC 27001:2022 Annex A 5.23 Information security for use of cloud servicesProcesses for buying, using, managing and leaving cloud services are to be set up so that they satisfy what the organization requires for information security. Purpose (stated in ISO/IEC 27002:2022): specifies and manages information security for the organization's use of cloud services.KC-01 S3 Decide whether cloud service requirements apply
ISO/IEC 27001:2022 Annex A 5.33 Protection of recordsRecords are to be safeguarded against being lost, destroyed, falsified, accessed without authorization or released without authorization. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with legal, regulatory and contractual obligations and societal expectations for protecting and keeping records available.KC-08 S2 What does the auditor get?
ISO/IEC 27001:2022 Annex A 8.2 Privileged access rightsThe granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services.KC-01 S6 Decide the vendor's access
ISO/IEC 27001:2022 Annex A 8.5 Secure authenticationSecure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services.KC-01 S6 Decide the vendor's access