Annex A category 8

ISO 27001 Technological controls

Technical safeguards across identity, systems, networks, applications, data and operations. Use this category page to understand the control family and move into detailed implementation guides.

How this category supports the ISMS

Technological controls provide a structured reference for risk treatment. Applicability follows the organization’s risks, obligations, scope and chosen treatment. Record decisions in the Statement of Applicability and test selected controls in operation.

Use these guides to move from category-level planning into control-specific implementation, evidence and audit testing. The interactive lookup remains available for quick cross-control reference.

Published technological control guides

Control 8.1

User endpoint devices

Apply managed security baselines and lifecycle controls to endpoints that access organizational information and services.

Read the full guide →

Control 8.2

Privileged access rights

Restrict, approve, monitor and review powerful access separately from routine user access.

Read the full guide →

Control 8.3

Information access restriction

Enforce access boundaries according to business need, classification and approved authorization rules.

Read the full guide →

Control 8.4

Access to source code

Limit and monitor source-code access to protect integrity, confidentiality and controlled change.

Read the full guide →

Control 8.5

Secure authentication

Use authentication mechanisms and operating practices proportionate to account, system and transaction risk.

Read the full guide →

Control 8.6

Capacity management

Monitor and plan capacity so services remain reliable and security controls continue to operate under expected demand.

Read the full guide →

Control 8.7

Protection against malware

Combine preventive, detective and recovery measures to reduce malware execution and impact.

Read the full guide →

Control 8.8

Management of technical vulnerabilities

Identify relevant technical vulnerabilities, determine exposure and drive risk-based remediation and exception decisions.

Read the full guide →

Control 8.9

Configuration management

Define, deploy and monitor secure configuration baselines across relevant technology.

Read the full guide →

Control 8.10

Information deletion

Delete information when authorized and no longer needed, including relevant copies and service-provider locations.

Read the full guide →

Control 8.11

Data masking

Reduce exposure of sensitive data by obscuring values where full detail is unnecessary.

Read the full guide →

Control 8.12

Data leakage prevention

Detect and reduce unauthorized movement or disclosure of sensitive information across people, endpoints and services.

Read the full guide →

Control 8.13

Information backup

Create protected, recoverable copies aligned with business recovery and information-retention needs.

Read the full guide →

Control 8.14

Redundancy of information processing facilities

Use proportionate redundancy to meet service availability and recovery needs.

Read the full guide →

Control 8.15

Logging

Generate, protect and retain useful event records that support detection, investigation and accountability.

Read the full guide →

Control 8.16

Monitoring activities

Review systems, networks and user activity for anomalies and indicators requiring investigation or response.

Read the full guide →

Control 8.17

Clock synchronization

Maintain consistent time sources so records, alerts and investigations can be correlated reliably.

Read the full guide →

Control 8.18

Use of privileged utility programs

Restrict and monitor powerful utilities that can bypass normal system or application controls.

Read the full guide →

Control 8.19

Installation of software on operational systems

Authorize and control software installation to protect stability, licensing and security baselines.

Read the full guide →

Control 8.20

Networks security

Design, configure and operate networks to protect information flows and connected services.

Read the full guide →

Control 8.21

Security of network services

Define and monitor security expectations for network services, whether internal, outsourced or cloud-delivered.

Read the full guide →

Control 8.22

Segregation of networks

Separate networks, users and services where segmentation reduces exposure or limits movement.

Read the full guide →

Control 8.23

Web filtering

Reduce exposure to malicious or prohibited web content through risk-based filtering and exception handling.

Read the full guide →

Control 8.24

Use of cryptography

Govern cryptographic use, algorithms, certificates and keys according to information and service risk.

Read the full guide →

Control 8.25

Secure development life cycle

Embed security activities, ownership and assurance throughout development and acquisition.

Read the full guide →

Control 8.26

Application security requirements

Define testable security and privacy requirements before applications are designed, acquired or changed.

Read the full guide →

Control 8.27

Secure system architecture and engineering principles

Apply documented security principles and risk decisions to system architecture and engineering.

Read the full guide →

Control 8.28

Secure coding

Use coding standards, developer practices and review techniques that prevent common weaknesses.

Read the full guide →

Control 8.29

Security testing in development and acceptance

Test security requirements and risk scenarios before release and after material change.

Read the full guide →

Control 8.30

Outsourced development

Apply security requirements, oversight and acceptance criteria when development is performed externally.

Read the full guide →

Control 8.31

Separation of development, test and production environments

Separate environments and control movement between them to reduce unauthorized change and data exposure.

Read the full guide →

Control 8.32

Change management

Assess, authorize, test, implement and review technology changes through controlled workflows.

Read the full guide →

Control 8.33

Test information

Select, protect and remove test information so testing does not create unnecessary exposure.

Read the full guide →

Control 8.34

Protection of information systems during audit testing

Plan and control audit testing so assurance activity does not disrupt systems or expose sensitive information.

Read the full guide →

All technological controls

Browse the complete category. Each control opens a dedicated implementation guide and remains available in the free interactive lookup.