Control 8.1
User endpoint devices
Apply managed security baselines and lifecycle controls to endpoints that access organizational information and services.
Read the full guide →Annex A category 8
Technical safeguards across identity, systems, networks, applications, data and operations. Use this category page to understand the control family and move into detailed implementation guides.
Technological controls provide a structured reference for risk treatment. Applicability follows the organization’s risks, obligations, scope and chosen treatment. Record decisions in the Statement of Applicability and test selected controls in operation.
Use these guides to move from category-level planning into control-specific implementation, evidence and audit testing. The interactive lookup remains available for quick cross-control reference.
Control 8.1
Apply managed security baselines and lifecycle controls to endpoints that access organizational information and services.
Read the full guide →Control 8.2
Restrict, approve, monitor and review powerful access separately from routine user access.
Read the full guide →Control 8.3
Enforce access boundaries according to business need, classification and approved authorization rules.
Read the full guide →Control 8.4
Limit and monitor source-code access to protect integrity, confidentiality and controlled change.
Read the full guide →Control 8.5
Use authentication mechanisms and operating practices proportionate to account, system and transaction risk.
Read the full guide →Control 8.6
Monitor and plan capacity so services remain reliable and security controls continue to operate under expected demand.
Read the full guide →Control 8.7
Combine preventive, detective and recovery measures to reduce malware execution and impact.
Read the full guide →Control 8.8
Identify relevant technical vulnerabilities, determine exposure and drive risk-based remediation and exception decisions.
Read the full guide →Control 8.9
Define, deploy and monitor secure configuration baselines across relevant technology.
Read the full guide →Control 8.10
Delete information when authorized and no longer needed, including relevant copies and service-provider locations.
Read the full guide →Control 8.11
Reduce exposure of sensitive data by obscuring values where full detail is unnecessary.
Read the full guide →Control 8.12
Detect and reduce unauthorized movement or disclosure of sensitive information across people, endpoints and services.
Read the full guide →Control 8.13
Create protected, recoverable copies aligned with business recovery and information-retention needs.
Read the full guide →Control 8.14
Use proportionate redundancy to meet service availability and recovery needs.
Read the full guide →Control 8.15
Generate, protect and retain useful event records that support detection, investigation and accountability.
Read the full guide →Control 8.16
Review systems, networks and user activity for anomalies and indicators requiring investigation or response.
Read the full guide →Control 8.17
Maintain consistent time sources so records, alerts and investigations can be correlated reliably.
Read the full guide →Control 8.18
Restrict and monitor powerful utilities that can bypass normal system or application controls.
Read the full guide →Control 8.19
Authorize and control software installation to protect stability, licensing and security baselines.
Read the full guide →Control 8.20
Design, configure and operate networks to protect information flows and connected services.
Read the full guide →Control 8.21
Define and monitor security expectations for network services, whether internal, outsourced or cloud-delivered.
Read the full guide →Control 8.22
Separate networks, users and services where segmentation reduces exposure or limits movement.
Read the full guide →Control 8.23
Reduce exposure to malicious or prohibited web content through risk-based filtering and exception handling.
Read the full guide →Control 8.24
Govern cryptographic use, algorithms, certificates and keys according to information and service risk.
Read the full guide →Control 8.25
Embed security activities, ownership and assurance throughout development and acquisition.
Read the full guide →Control 8.26
Define testable security and privacy requirements before applications are designed, acquired or changed.
Read the full guide →Control 8.27
Apply documented security principles and risk decisions to system architecture and engineering.
Read the full guide →Control 8.28
Use coding standards, developer practices and review techniques that prevent common weaknesses.
Read the full guide →Control 8.29
Test security requirements and risk scenarios before release and after material change.
Read the full guide →Control 8.30
Apply security requirements, oversight and acceptance criteria when development is performed externally.
Read the full guide →Control 8.31
Separate environments and control movement between them to reduce unauthorized change and data exposure.
Read the full guide →Control 8.32
Assess, authorize, test, implement and review technology changes through controlled workflows.
Read the full guide →Control 8.33
Select, protect and remove test information so testing does not create unnecessary exposure.
Read the full guide →Control 8.34
Plan and control audit testing so assurance activity does not disrupt systems or expose sensitive information.
Read the full guide →Browse the complete category. Each control opens a dedicated implementation guide and remains available in the free interactive lookup.
Control 8.1
Control 8.2
Control 8.3
Control 8.4
Control 8.5
Control 8.6
Control 8.7
Control 8.8
Control 8.9
Control 8.10
Control 8.11
Control 8.12
Control 8.13
Control 8.14
Control 8.15
Control 8.16
Control 8.17
Control 8.18
Control 8.19
Control 8.20
Control 8.21
Control 8.22
Control 8.23
Control 8.24
Control 8.25
Control 8.26
Control 8.27
Control 8.28
Control 8.29
Control 8.30
Control 8.31
Control 8.32
Control 8.33
Control 8.34