ClearPenTest

Audit and compliance

Annex A

Also called: ISO 27001 Annex A, Annex A controls

Annex A is the list of information security controls in ISO/IEC 27001. The 2022 revision contains 93 controls organized into four themes: organizational, people, physical and technological, replacing the 114 controls in 14 domains of the 2013 version.

Two controls create the security testing expectation: A 8.8 on management of technical vulnerabilities, and A 8.29 on security testing in development and acceptance.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.