Control Coverage

How the InfraTrace360 application supports and provides evidence for Annex A controls. InfraTrace360 is a management & evidence tool — it helps you operate and demonstrate these controls; it does not by itself grant certification, which also requires policies, processes and people.

 

Annex A Control Control Name

A.5.9 Inventory of information & associated assets
A.5.12 Classification of information
A.5.15 Access control
A.5.16 Identity management
A.5.18 Access rights (provisioning & review)
A.5.19 Information security in supplier relationships
A.5.22 Monitoring & review of supplier services
A.5.24 Incident management planning & preparation
A.5.25 Assessment & decision on security events
A.5.26 Response to information security incidents
A.5.27 Learning from incidents
A.5.28 Collection of evidence
A.5.37 Documented operating procedures
A.6.5 Responsibilities after termination/change
A.8.2 Privileged access rights
A.8.3 Information access restriction
A.8.15 Logging
A.8.16 Monitoring activities
A.8.19 Installation of software on operational systems
A.5.10 Acceptable use & handling of assets
A.5.17 Authentication information
A.5.20 Addressing security within supplier agreements
A.5.29 Continuity & readiness of ICT
A.5.30 ICT readiness for business continuity
A.5.36 Compliance with policies & standards
A.6.1 Screening
A.6.2 Terms & conditions of employment
A.6.6 Confidentiality / non-disclosure agreements
A.8.8 Management of technical vulnerabilities
A.8.9 Configuration management

 

Clause 9.1 Monitoring, measurement & evaluation
Clause 6.1 Actions to address risks & opportunities
Clause 8.2/8.3 Risk assessment & treatment

 

Download the control coverage in PDF

Chat with us