Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Adhering to the ISO 27002 Security Framework with Privileged and Vulnerability Management current page
Link copied

Adhering to the ISO 27002 Security Framework with Privileged and Vulnerability Management

Aug 8, 2017
Author:
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust
Blog banner default
Adhering to the ISO 27002 Security Framework with Privileged and Vulnerability Management
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust

Adhering to the ISO 27002 Security Framework

The International Organization for Standardization (ISO) has established guidelines and general principles for initiating, implementing, maintaining and improving information security management in an organization. The objectives outlined in ISO 27002 provide general guidance on the commonly accepted goals of information security management. ISO 2700 security management can serve as a practical guideline for developing organizational security standards and effective security management practices.

For organizations that have adopted ISO 27002:2013(E), it is important that all existing and new security solutions map into this framework. This standard contains 14 security control clauses containing a total of 35 main security categories and 114 security controls.

Whether an organization’s objective is to achieve legislative compliance or to adopt security best practices, these controls apply to most organizations and in most environments.

How can privileged access management and vulnerability management help achieve compliance with ISO 27002 requirements?

Privileged access management and vulnerability management play key roles in adhering to the ISO 27002 standard. BeyondTrust solutions address parts of 12 security control clauses, 29 security control categories, and 74 security controls in the standard.

For a summary of how BeyondTrust solutions map into the specific control clauses, please see below.

  • 6 - Organization of Information Security:

    Identity all assets, security policies defined by asset and user, authorization levels for role based access, and policies, and coordinate oversight of security roles and responsibilities with solutions in the BeyondTrust platform.
  • 8 - Asset Management:

    Provide a centralized location for asset inventory and provide details on user behavior, vulnerabilities, attacks, malware, services, processes, tasks, users, software, and events.
  • 9 - Access Control:

    Address several controls under this clause, include those regarding access control policy, user access management, and user responsibilities – as well as network, operating system and application access controls.
  • 10 - Cryptography:

    Scan and report on security weaknesses in deployed cryptographic controls, and provide a framework for managing, reporting, and assessing keys within an organization.
  • 11 - Physical Environment Security:

    Aggregate vulnerability and configuration assessments to determine if clear screen policies are being implemented correctly; and assess a resource to determine if settings like automatic session activity logoff, multi-factor authentication, and inappropriate peripherals are connected contrary to clear screen policies.
  • 12 - Operations Security:

    Provide complete logging as a part of change management procedures for any access that may affect privileged access management, users, or settings. Document malware against assets by comparing file and application hashes with Virus Total and NSRL using BeyondTrust’s Clarity Malware Analysis capabilities. Provide vulnerability assessment, reporting, and advanced threat analytics to support vulnerability management processes using network scanners, agents, or the cloud for assessments.
  • 13 - Communications Security:

    Aggregate vulnerability and privileged access control into a central framework to verify the security and operation integrity of network services, and manage privileged access to network resources.
  • 14 - System Acquisition, Development and Maintenance:

    Support best practices for security, data analysis, and implementation of technical specifications included in business processes.
  • 15 - Supplier Relationships:

    Store vulnerability assessment information gathered per contractual requirements from suppliers.
  • 16 - Information Security Incident Management:

    Assign critical events and incidents to the proper teams for enforcement of cyber security responsibilities and roles. Escalate and consolidate cyber security events related to vulnerabilities and user behavior. This information can be forwarded to SIEM solutions for additional correlation.
  • 17 - Information Security Aspects of Business Continuity Management:

    Support high availability installations and disaster recovery plans for cyber security continuity.
  • 18 - Compliance:

    Allow for secure access to privileged access and vulnerability data that could be used for compliance, legal, and contractual requirements. Collect and securely store all log data – including session logs, event logs and recordings.

How do BeyondTrust’s solutions help address these ISO 27002 requirements?

For a complete explanation of how each BeyondTrust solution addresses ISO 27002 requirements, please download the white paper, "Mapping BeyondTrust Solutions to ISO 27002". The paper not only includes detailed product mappings down to the lowest level of the framework, but it also includes reporting available in Retina Enterprise Vulnerability Management to prove it.

For more information on how BeyondTrust can help you achieve greater control and accountability over your information security environment, contact us today for a strategy session.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Are these Privileged Access Security Myths Haunting You?
    Oct 31, 2019 Are these Privileged Access Security Myths Haunting You?
    Blog
    1m
  • How to  Mitigate macOS CVE-2021-30657 with BeyondTrust Privilege Management for Mac
    May 18, 2021 How to Mitigate macOS CVE-2021-30657 with BeyondTrust Privilege Management for Mac
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.