| ISO ID | Title | Layer | Owner | Linked artefacts | Unresolved | Status |
|---|
| 4.1 | Understanding the organization and its context | linked | ISMS Manager | OS (cites), GS (cites), ERR (cites), ISOCL (cites) | | implemented |
| 4.2 | Understanding the needs and expectations of interested parties | linked | Compliance Manager | ERR (cites), SRP (cites), ISOCL (cites) | SOC2-SD | implemented |
| 4.3 | Determining the scope of the ISMS | linked | ISMS Manager | ISS (cites), SAS (cites), SINV (cites), ISOCL (cites), AST-001 (field-ref), AST-005 (field-ref), AST-011 (field-ref), AST-014 (field-ref), AST-012 (field-ref), AST-013 (field-ref), AST-003 (field-ref) | | implemented |
| 4.4 | Information security management system | linked | ISMS Manager | GS (cites), IMPL-WB (cites), ISOCL (cites) | WIR-S1 | implemented |
| 5.1 | Leadership and commitment | linked | Top Management | ISP (cites), MRART (cites), MRMT (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) | | implemented |
| 5.2 | Information security policy | linked | ISMS Manager | ISP (cites), TRC (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) | | implemented |
| 5.3 | Organizational roles, responsibilities and authorities | linked | ISMS Manager | RACI (cites), GS (cites), OS (cites), ISOCL (cites) | | implemented |
| 6.1.1 | Actions to address risks and opportunities | linked | Risk Manager | RR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) | CIL | implemented |
| 6.1.2 | Information security risk assessment | linked | Risk Manager | RAM (cites), RAMT (cites), RASM (cites), RR (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) | | implemented |
| 6.1.3 | Information security risk treatment | linked | Risk Manager | RTP (cites), SOA (cites), ISOCTRL (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) | | implemented |
| 6.2 | Information security objectives and planning to achieve them | linked | Top Management | ISP (cites), IMPL-WB (cites), MME (cites), ISOCL (cites) | | implemented |
| 6.3 | Planning of changes | linked | Change Manager | CR (cites), ISOCL (cites) | CMP; ISMS-CL | implemented |
| 7.1 | Resources | linked | Top Management | MRART (cites), MRMT (cites), GS (cites), ISOCL (cites) | | implemented |
| 7.2 | Competence | linked | HR Manager | TR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | CMTP | implemented |
| 7.3 | Awareness | linked | Security Lead | TRC (cites), HRSP (cites), ISOCL (cites) | | implemented |
| 7.4 | Communication | documented | Communications Owner | ISOCL (cites) | COMM-P; SICT; IRP | implemented |
| 7.5 | Documented information | linked | Document Owner | DR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites) | DCP; WIR-S1 | implemented |
| 8.1 | Operational planning and control | documented | ISMS Manager | ISOCTRL (cites), ISOCL (cites) | WIR-S1; CMP | implemented |
| 8.2 | Information security risk assessment | linked | Risk Manager | RR (cites), RAM (cites), ISOCL (cites) | ISMS-CL | implemented |
| 8.3 | Information security risk treatment | linked | Risk Manager | RTP (cites), SOA (cites), CAR (cites), ISOCL (cites) | | implemented |
| 9.1 | Monitoring, measurement, analysis and evaluation | linked | Security Lead | MME (cites), IMPL-WB (cites), MRART (cites), ISOCL (cites) | | implemented |
| 9.2 | Internal audit | linked | Internal Auditor | IAP (cites), CAR (cites), MRMT (cites), ISOCL (cites) | | implemented |
| 9.3 | Management review | linked | Top Management | MRART (cites), MRMT (cites), ISOCL (cites) | | implemented |
| 10.1 | Continual improvement | linked | ISMS Manager | CAR (cites), ISOCL (cites) | CIL; WIR-S1 | implemented |
| 10.2 | Nonconformity and corrective action | linked | ISMS Manager | CAR (cites), IAP (cites), MRMT (cites), ISOCL (cites) | | implemented |
| A.5.1 | Policies for information security | linked | ISMS Manager | ISP (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.5.2 | Information security roles and responsibilities | linked | ISMS Manager | RACI (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.5.3 | Segregation of duties | documented | IT Operations | SOA (cites), ISOCTRL (cites) | SOD-CHK-2026-Q3 | partial |
| A.5.4 | Management responsibilities | documented | Top Management | SOA (cites), ISOCTRL (cites) | MR-2026-Q3 | implemented |
| A.5.5 | Contact with authorities | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | COMM-P | implemented |
| A.5.6 | Contact with special interest groups | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-SUB-2026 | implemented |
| A.5.7 | Threat intelligence | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-LOG-2026-Q3 | partial |
| A.5.8 | Information security in project management | documented | Project Manager | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.5.9 | Inventory of information and other associated assets | linked | Asset Manager | AI (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), SINV (cites) | | implemented |
| A.5.10 | Acceptable use of information and other associated assets | linked | HR Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites) | AUP-ACK-2026-Q3 | implemented |
| A.5.11 | Return of assets | linked | HR Manager | OFC (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), LAP-047 (field-ref), BADGE-047 (field-ref) | | implemented |
| A.5.12 | Classification of information | linked | ISMS Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites) | CLASS-STD-2026 | implemented |
| A.5.13 | Labelling of information | linked | Document Owner | DR (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), AI (cites), SINV (cites), ICP (cites) | | implemented |
| A.5.14 | Information transfer | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ITR-2026-Q3 | implemented |
| A.5.15 | Access control | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| A.5.16 | Identity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.5.17 | Authentication information | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.5.18 | Access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ARR | implemented |
| A.5.19 | Information security in supplier relationships | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) | | partial |
| A.5.20 | Addressing information security within supplier agreements | linked | Supplier Manager | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CSS | partial |
| A.5.21 | Managing information security in the ICT supply chain | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) | | planned |
| A.5.22 | Monitoring, review and change management of supplier services | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) | | partial |
| A.5.23 | Information security for use of cloud services | linked | Cloud Service Owner | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CLOUD-CTRL-2026-Q3 | partial |
| A.5.24 | Information security incident management planning and preparation | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| A.5.25 | Assessment and decision on information security events | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | SIR | implemented |
| A.5.26 | Response to information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IR-RB | implemented |
| A.5.27 | Learning from information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | CIL | planned |
| A.5.28 | Collection of evidence | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | ELAI | implemented |
| A.5.29 | Information security during disruption | documented | Business Continuity Manager | SOA (cites), ISOCTRL (cites) | BCP | implemented |
| A.5.30 | ICT readiness for business continuity | documented | IT Operations | SOA (cites), ISOCTRL (cites) | DRP | partial |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | LRR | implemented |
| A.5.32 | Intellectual property rights | linked | Legal Counsel | IPR (field-ref), SOA (cites), ISOCTRL (cites) | | planned |
| A.5.33 | Protection of records | documented | Document Owner | SOA (cites), ISOCTRL (cites) | RRS | implemented |
| A.5.34 | Privacy and protection of PII | documented | Privacy Lead | SOA (cites), ISOCTRL (cites) | DPAR | implemented |
| A.5.35 | Independent review of information security | linked | Internal Auditor | IAP (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.5.36 | Compliance with policies, rules and standards for information security | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | REQT | implemented |
| A.5.37 | Documented operating procedures | documented | Process Owner | SOA (cites), ISOCTRL (cites) | DOP | partial |
| A.6.1 | Screening | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| A.6.2 | Terms and conditions of employment | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| A.6.3 | Information security awareness, education and training | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | TRAIN-REC-2026-188 | implemented |
| A.6.4 | Disciplinary process | linked | HR Manager | HRP (field-ref), SOA (cites), ISOCTRL (cites), DR (cites), AI (cites), SINV (cites) | | planned |
| A.6.5 | Responsibilities after termination or change of employment | linked | HR Manager | OFC (field-ref), SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites), LAP-047 (field-ref), BADGE-047 (field-ref) | | implemented |
| A.6.6 | Confidentiality or non-disclosure agreements | documented | Legal Counsel | SOA (cites), ISOCTRL (cites) | NDA-REG-2026 | implemented |
| A.6.7 | Remote working | documented | IT Operations | SOA (cites), ISOCTRL (cites) | REMOTE-2026 | implemented |
| A.6.8 | Information security event reporting | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| A.7.1 | Physical security perimeters | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-SEC-2026 | implemented |
| A.7.2 | Physical entry | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-ACCESS-2026 | implemented |
| A.7.3 | Securing offices, rooms and facilities | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-OFFICE-2026 | implemented |
| A.7.4 | Physical security monitoring | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-MON-2026-Q3 | partial |
| A.7.5 | Protecting against physical and environmental threats | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | BCP | planned |
| A.7.6 | Working in secure areas | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) | | not-applicable |
| A.7.7 | Clear desk and clear screen | documented | HR Manager | SOA (cites), ISOCTRL (cites) | AUP-ACK-2026-Q3 | implemented |
| A.7.8 | Equipment siting and protection | linked | IT Operations | AI (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.7.9 | Security of assets off-premises | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.7.10 | Storage media | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.7.11 | Supporting utilities | not-applicable | Facilities Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites) | | not-applicable |
| A.7.12 | Cabling security | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) | | not-applicable |
| A.7.13 | Equipment maintenance | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.7.14 | Secure disposal or re-use of equipment | linked | IT Operations | OFC (field-ref), SOA (cites), ISOCTRL (cites), LAP-047 (field-ref), BADGE-047 (field-ref) | | implemented |
| A.8.1 | User endpoint devices | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.8.2 | Privileged access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| A.8.3 | Information access restriction | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| A.8.4 | Access to source code | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SI | implemented |
| A.8.5 | Secure authentication | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.8.6 | Capacity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | planned |
| A.8.7 | Protection against malware | documented | IT Operations | SOA (cites), ISOCTRL (cites) | EDR-2026-Q3 | implemented |
| A.8.8 | Management of technical vulnerabilities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | VULN-2026-Q3 | partial |
| A.8.9 | Configuration management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | partial |
| A.8.10 | Information deletion | documented | Data Owner | SOA (cites), ISOCTRL (cites) | RRS | partial |
| A.8.11 | Data masking | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-DMASK-2026 | planned |
| A.8.12 | Data leakage prevention | documented | Security Lead | SOA (cites), ISOCTRL (cites) | DLP-PLAN-2026 | planned |
| A.8.13 | Information backup | documented | IT Operations | SOA (cites), ISOCTRL (cites) | BKP-CRM-001 | implemented |
| A.8.14 | Redundancy of information processing facilities | linked | IT Operations | SINV (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.8.15 | Logging | documented | Security Lead | SOA (cites), ISOCTRL (cites) | LOG-2026-Q3 | implemented |
| A.8.16 | Monitoring activities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | partial |
| A.8.17 | Clock synchronization | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | implemented |
| A.8.18 | Use of privileged utility programs | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| A.8.19 | Installation of software on operational systems | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| A.8.20 | Networks security | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NSP | implemented |
| A.8.21 | Security of network services | linked | IT Operations | SINV (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| A.8.22 | Segregation of networks | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NET-SEG-2026 | partial |
| A.8.23 | Web filtering | documented | IT Operations | SOA (cites), ISOCTRL (cites) | TBD-WEBFILTER-2026 | planned |
| A.8.24 | Use of cryptography | documented | Security Lead | SOA (cites), ISOCTRL (cites) | CKMP | implemented |
| A.8.25 | Secure development life cycle | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.8.26 | Application security requirements | documented | Product Owner | SOA (cites), ISOCTRL (cites) | APPSEC-REQ-2026 | partial |
| A.8.27 | Secure system architecture and engineering principles | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ARCH-SEC-2026 | planned |
| A.8.28 | Secure coding | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.8.29 | Security testing in development and acceptance | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TEST-SEC-2026 | partial |
| A.8.30 | Outsourced development | not-applicable | Engineering Lead | SOA (field-ref), ISOCTRL (cites) | | not-applicable |
| A.8.31 | Separation of development, test and production environments | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ENV-SEP-2026 | implemented |
| A.8.32 | Change management | documented | Change Manager | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| A.8.33 | Test information | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-TESTDATA-2026 | planned |
| A.8.34 | Protection of information systems during audit testing | linked | Internal Auditor | IAP (field-ref), SOA (cites), ISOCTRL (cites) | | implemented |
| ISO ID | Title | Layer | Owner | Linked artefacts | Unresolved | Status |
|---|
| 4.2 | Understanding the needs and expectations of interested parties | linked | Compliance Manager | ERR (cites), SRP (cites), ISOCL (cites) | SOC2-SD | implemented |
| 4.4 | Information security management system | linked | ISMS Manager | GS (cites), IMPL-WB (cites), ISOCL (cites) | WIR-S1 | implemented |
| 6.1.1 | Actions to address risks and opportunities | linked | Risk Manager | RR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) | CIL | implemented |
| 6.3 | Planning of changes | linked | Change Manager | CR (cites), ISOCL (cites) | CMP; ISMS-CL | implemented |
| 7.2 | Competence | linked | HR Manager | TR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | CMTP | implemented |
| 7.4 | Communication | documented | Communications Owner | ISOCL (cites) | COMM-P; SICT; IRP | implemented |
| 7.5 | Documented information | linked | Document Owner | DR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites) | DCP; WIR-S1 | implemented |
| 8.1 | Operational planning and control | documented | ISMS Manager | ISOCTRL (cites), ISOCL (cites) | WIR-S1; CMP | implemented |
| 8.2 | Information security risk assessment | linked | Risk Manager | RR (cites), RAM (cites), ISOCL (cites) | ISMS-CL | implemented |
| 10.1 | Continual improvement | linked | ISMS Manager | CAR (cites), ISOCL (cites) | CIL; WIR-S1 | implemented |
| A.5.3 | Segregation of duties | documented | IT Operations | SOA (cites), ISOCTRL (cites) | SOD-CHK-2026-Q3 | partial |
| A.5.4 | Management responsibilities | documented | Top Management | SOA (cites), ISOCTRL (cites) | MR-2026-Q3 | implemented |
| A.5.5 | Contact with authorities | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | COMM-P | implemented |
| A.5.6 | Contact with special interest groups | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-SUB-2026 | implemented |
| A.5.7 | Threat intelligence | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-LOG-2026-Q3 | partial |
| A.5.8 | Information security in project management | documented | Project Manager | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.5.10 | Acceptable use of information and other associated assets | linked | HR Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites) | AUP-ACK-2026-Q3 | implemented |
| A.5.12 | Classification of information | linked | ISMS Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites) | CLASS-STD-2026 | implemented |
| A.5.14 | Information transfer | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ITR-2026-Q3 | implemented |
| A.5.15 | Access control | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| A.5.16 | Identity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.5.17 | Authentication information | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.5.18 | Access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ARR | implemented |
| A.5.20 | Addressing information security within supplier agreements | linked | Supplier Manager | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CSS | partial |
| A.5.23 | Information security for use of cloud services | linked | Cloud Service Owner | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CLOUD-CTRL-2026-Q3 | partial |
| A.5.24 | Information security incident management planning and preparation | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| A.5.25 | Assessment and decision on information security events | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | SIR | implemented |
| A.5.26 | Response to information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IR-RB | implemented |
| A.5.27 | Learning from information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | CIL | planned |
| A.5.28 | Collection of evidence | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | ELAI | implemented |
| A.5.29 | Information security during disruption | documented | Business Continuity Manager | SOA (cites), ISOCTRL (cites) | BCP | implemented |
| A.5.30 | ICT readiness for business continuity | documented | IT Operations | SOA (cites), ISOCTRL (cites) | DRP | partial |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | LRR | implemented |
| A.5.33 | Protection of records | documented | Document Owner | SOA (cites), ISOCTRL (cites) | RRS | implemented |
| A.5.34 | Privacy and protection of PII | documented | Privacy Lead | SOA (cites), ISOCTRL (cites) | DPAR | implemented |
| A.5.36 | Compliance with policies, rules and standards for information security | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | REQT | implemented |
| A.5.37 | Documented operating procedures | documented | Process Owner | SOA (cites), ISOCTRL (cites) | DOP | partial |
| A.6.1 | Screening | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| A.6.2 | Terms and conditions of employment | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| A.6.3 | Information security awareness, education and training | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | TRAIN-REC-2026-188 | implemented |
| A.6.6 | Confidentiality or non-disclosure agreements | documented | Legal Counsel | SOA (cites), ISOCTRL (cites) | NDA-REG-2026 | implemented |
| A.6.7 | Remote working | documented | IT Operations | SOA (cites), ISOCTRL (cites) | REMOTE-2026 | implemented |
| A.6.8 | Information security event reporting | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| A.7.1 | Physical security perimeters | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-SEC-2026 | implemented |
| A.7.2 | Physical entry | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-ACCESS-2026 | implemented |
| A.7.3 | Securing offices, rooms and facilities | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-OFFICE-2026 | implemented |
| A.7.4 | Physical security monitoring | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-MON-2026-Q3 | partial |
| A.7.5 | Protecting against physical and environmental threats | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | BCP | planned |
| A.7.7 | Clear desk and clear screen | documented | HR Manager | SOA (cites), ISOCTRL (cites) | AUP-ACK-2026-Q3 | implemented |
| A.7.9 | Security of assets off-premises | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.7.10 | Storage media | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.7.13 | Equipment maintenance | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.8.1 | User endpoint devices | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| A.8.2 | Privileged access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| A.8.3 | Information access restriction | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| A.8.4 | Access to source code | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SI | implemented |
| A.8.5 | Secure authentication | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| A.8.6 | Capacity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | planned |
| A.8.7 | Protection against malware | documented | IT Operations | SOA (cites), ISOCTRL (cites) | EDR-2026-Q3 | implemented |
| A.8.8 | Management of technical vulnerabilities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | VULN-2026-Q3 | partial |
| A.8.9 | Configuration management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | partial |
| A.8.10 | Information deletion | documented | Data Owner | SOA (cites), ISOCTRL (cites) | RRS | partial |
| A.8.11 | Data masking | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-DMASK-2026 | planned |
| A.8.12 | Data leakage prevention | documented | Security Lead | SOA (cites), ISOCTRL (cites) | DLP-PLAN-2026 | planned |
| A.8.13 | Information backup | documented | IT Operations | SOA (cites), ISOCTRL (cites) | BKP-CRM-001 | implemented |
| A.8.15 | Logging | documented | Security Lead | SOA (cites), ISOCTRL (cites) | LOG-2026-Q3 | implemented |
| A.8.16 | Monitoring activities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | partial |
| A.8.17 | Clock synchronization | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | implemented |
| A.8.18 | Use of privileged utility programs | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| A.8.19 | Installation of software on operational systems | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| A.8.20 | Networks security | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NSP | implemented |
| A.8.22 | Segregation of networks | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NET-SEG-2026 | partial |
| A.8.23 | Web filtering | documented | IT Operations | SOA (cites), ISOCTRL (cites) | TBD-WEBFILTER-2026 | planned |
| A.8.24 | Use of cryptography | documented | Security Lead | SOA (cites), ISOCTRL (cites) | CKMP | implemented |
| A.8.25 | Secure development life cycle | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.8.26 | Application security requirements | documented | Product Owner | SOA (cites), ISOCTRL (cites) | APPSEC-REQ-2026 | partial |
| A.8.27 | Secure system architecture and engineering principles | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ARCH-SEC-2026 | planned |
| A.8.28 | Secure coding | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| A.8.29 | Security testing in development and acceptance | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TEST-SEC-2026 | partial |
| A.8.31 | Separation of development, test and production environments | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ENV-SEP-2026 | implemented |
| A.8.32 | Change management | documented | Change Manager | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| A.8.33 | Test information | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-TESTDATA-2026 | planned |