UnixTime

Domain guide

What this domain covers

Risk treatment, ISO 27005 links, GRC mappings, control relationships, and cross-framework translation notes.

5 resources

Guide + resources

Grouped resources

Crosswalks

Mappings across controls, risks, standards, and assurance views.

5 items
Framework note 04 mins read

A.5 Controls Implementation Audit Risk Mapping

This table maps each covered A.5 organizational control to implementation output, audit evidence, and ISO/IEC 27005-style risk logic.

ISO27001 ISO27002 iso27001 iso27005
Framework note 03 mins read

A.6 People Controls Implementation Audit Risk Mapping

- A.6 controls are people-risk treatments. They reduce the chance that the wrong person is trusted or that the right person lacks clear obligations. - A.6 evidence often sits ou...

ISO27001 ISO27002 iso27001 iso27005
Framework note 05 mins read

A.7 Physical Controls Implementation Audit Risk Mapping

- Physical controls often fail through behavior, not technology. Observation and walkthrough evidence matter. - Physical controls should align to asset inventory, classification...

ISO27001 ISO27002 iso27001 iso27005
Framework note 11 mins read

A.8 Technological Controls Implementation Audit Risk Mapping

- A.8 controls require technical evidence. Policies are not enough. - Endpoint controls connect to remote working, off-premises assets, and incident reporting. - Privileged acce...

ISO27001 iso27001 iso27005 iso27002
Framework note 03 mins read

ISO 27001 Implementer Auditor ISO 27005 Mapping

1. implementer view: what to build; 2. auditor view: what to verify; 3. ISO/IEC 27005 view: what risk logic supports the decision.

ISO27001 ISO27005 iso27001 iso27005

Deep links

Link to this domain with /research/iso27001/risk-crosswalks/ . Link directly to exact notes from any resource card above.