Audit and compliance
Annex A
Also called: ISO 27001 Annex A, Annex A controls
Annex A is the list of information security controls in ISO/IEC 27001. The 2022 revision contains 93 controls organized into four themes: organizational, people, physical and technological, replacing the 114 controls in 14 domains of the 2013 version.
Two controls create the security testing expectation: A 8.8 on management of technical vulnerabilities, and A 8.29 on security testing in development and acceptance.
Sources
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.