Security Questionnaire Mapper
Framework

ISO/IEC 27001:2022: what it anchors in a questionnaire

The certificate most suppliers hold. Annex A is quoted; the management clauses (risk assessment, internal audit) are named where a question tests them, not quoted.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it.

Families anchored here

31 families, 31 clauses cited, 2 named
FamilyClause
Information security policy5.1
Security roles and a named security lead5.2
Risk assessmentclause 6.1.2 (named)
Independent audit and certification5.35 · clause 9.2 (named)
Background checks6.1
Security awareness training6.3
Confidentiality terms and leavers6.6
Multi-factor authentication8.5
Password policy5.17
Access provisioning and review5.18
Privileged access8.2
Encryption at rest8.24
Encryption in transit8.24
Data retention and secure deletion8.10
Data location and transfers5.31
Logging and monitoring8.15 · 8.16
Vulnerability and patch management8.8
Penetration testing8.8
Malware protection and endpoints8.7
Secure development and change8.25
Network security and segmentation8.20
Physical security7.1
Incident response plan5.24 · 5.26
Notifying the customer of an incident5.24 · 5.25 · 5.26
Business continuity plan5.29 · 5.30
Backup and disaster recovery8.13
Subcontractors and subprocessors5.19 · 5.20 · 5.21
Assessing your own suppliers5.22
Data subject requests5.34
Lawful basis, consent and privacy notice5.34
Data processing agreement5.34

Every ISO 27001 clause the register cites, with its text and evidence