Ransomware and ISO 27001: Which Annex A Controls Would Have Stopped It
Ransomware and other destructive malware usually succeed through a familiar chain: an attacker gets in, gains more access, spreads, and damages or encrypts data. ISO/IEC 27001:2022 Annex A includes controls that break each link. Here are the ones that matter most.
Keeping the Attacker Out
- 6.3 Information security awareness, education and training: phishing remains a common entry point.
- 8.7 Protection against malware: detection, prevention, and user awareness.
- 8.8 Management of technical vulnerabilities: timely patching of exposed systems.
- 8.5 Secure authentication: including multi-factor authentication for remote access.
- 5.7 Threat intelligence: knowing which threats target your industry.
Limiting Spread
- 5.15 Access control and 8.2 Privileged access rights: attackers look for administrator accounts; limit and monitor them.
- 8.20 Networks security and 8.22 Segregation of networks: separate business and operational networks so one infection does not reach everything.
- 8.9 Configuration management: hardened, consistent system configurations.
Detecting It Early
- 8.15 Logging and 8.16 Monitoring activities: logs that are collected, protected, and actually reviewed.
Recovering
- 8.13 Information backup: backups that are tested, protected from the same attack, and restorable.
- 5.29 Information security during disruption and 5.30 ICT readiness for business continuity: the plan to keep operating.
Responding and Learning
- 5.24 to 5.28 Incident management: planning, assessment, response, learning from incidents, and collection of evidence.
What Auditors Check
For each control in your Statement of Applicability, an auditor asks for evidence it operates: patch records, backup restore tests, access reviews, log review records, and incident reports. A control that exists only in a policy is not a control.
Compliance Fortress includes a qualified ISO 27001 lead auditor who can assess these controls at your organization. Related reading: ISO 27001 Audit Preparation.
How Compliance Fortress Solves This: The Exceleor Path
- Discovery: understand the problem, measure where things stand today, and agree on what success looks like.
- Define the engagement path: most organizations don't know the path. We do. A proven method, tailored to your situation.
- Training: bring your people to a clear understanding of the requirements.
- Implement and engage: carry out the work jointly, with your people involved from day one.
- Verify: confirm the work was done and meets the requirement.
- Validate: confirm the original problem is actually solved, measured against the success measures from Discovery.
- Transfer ownership: we collaborate throughout, so your team can run it without us.
- Sustain and grow: we stay close, check in, and catch the next need early. We're here to make sure you succeed.
Is this your situation? See how we approach it on the Malware Sabotaged Our Data page, or request a Situation Review. You can also email [email protected].
Need an EHS Audit?
Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.
Request Your AssessmentFree EHS Compliance Checklist
Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.
Download Free ChecklistMore Free Resources
Fortify Your Compliance Today
Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.