ISO 27001: Information Security
Azure 54 automated checks
Information security management controls aligned with ISO/IEC 27001:2022 Annex A
Access Control (A.9)
- Storage account must disable anonymous blob public access
- Key Vault should use RBAC authorization
- SQL Server should use Azure AD-only authentication
- Cosmos DB should disable local authentication
- Container Registry must disable admin user
- AKS cluster must enable RBAC
- Organization should perform periodic access reviews
Asset Management (A.8)
Business Continuity (A.17)
Communications Security (A.13)
Cryptography (A.10)
Human Resource Security (A.7)
Information Security Incident Management (A.16)
ISMS Audit
Operations Security (A.12)
Organizational Controls (A.5)
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- IAM password policy must require minimum length of 14
- Organization should maintain an information security policy approved by management
- Organization should define information security roles and responsibilities
- Organization should maintain contact with relevant authorities
- Organization should collect and analyze threat intelligence
- Organization should integrate security into project management
- Organization should maintain an inventory of information assets
- Organization should classify information according to confidentiality requirements
- Organization should manage information security in supplier relationships
- Organization should establish incident management procedures
- Organization should have procedures for evidence collection and preservation
- Organization should integrate security into business continuity management
- Organization should identify applicable legal and regulatory requirements
People Controls (A.6)
- IAM password policy must require minimum length of 14
- Organization should perform personnel screening
- Organization should provide information security awareness and training
- Organization should have a disciplinary process for security violations
- Organization should define security responsibilities upon termination
Physical Controls (A.7)
Physical Security (A.11)
Supplier Relationships (A.15)
Measure your ISO 27001: Information Security posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.