Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
This skill provides guidance for implementing and verifying ISO 27001:2022 Annex A controls within the CIA platform, ensuring systematic information security management aligned with Hack23 ISMS framework.
Apply this skill when:
A.5.10 - Acceptable Use of Information
A.5.15 - Access Control
A.5.17 - Authentication Information
A.5.23 - Information Security for Cloud Services
A.8.1 - User Endpoint Devices
A.8.2 - Privileged Access Rights
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class MethodSecurityConfig {
@Bean
public RoleHierarchy roleHierarchy() {
RoleHierarchyImpl hierarchy = new RoleHierarchyImpl();
hierarchy.setHierarchy("ROLE_ADMIN > ROLE_USER\n" +
"ROLE_USER > ROLE_GUEST");
return hierarchy;
}
}
@Service
public class PrivilegedOperationService {
@PreAuthorize("hasRole('ADMIN')")
@Audited
public void modifySystemConfiguration(ConfigurationChange change) {
// Log privileged action
auditLogger.log("PRIVILEGED_ACTION", "System config modified", change);
// Perform operation
configurationRepository.save(change);
}
}
A.8.3 - Information Access Restriction
@Entity
@Table(name = "document")
public class Document {
@Id
private String id;
@Enumerated(EnumType.STRING)
private DataClassification classification; // PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED
private String ownerId;
@ElementCollection
private Set<String> authorizedUserIds;
}
@Service
public class DocumentAccessService {
public Document getDocument(String documentId, String userId) {
Document doc = documentRepository.findById(documentId)
.orElseThrow(() -> new ResourceNotFoundException("Document not found"));
// Enforce access control based on classification
if (!canAccess(doc, userId)) {
auditLogger.logAccessDenied(userId, documentId);
throw new AccessDeniedException("Insufficient permissions");
}
return doc;
}
private boolean canAccess(Document doc, String userId) {
switch (doc.getClassification()) {
case PUBLIC:
return true;
case INTERNAL:
return userService.isInternalUser(userId);
case CONFIDENTIAL:
return doc.getAuthorizedUserIds().contains(userId);
case RESTRICTED:
return doc.getOwnerId().equals(userId) ||
userService.isAdmin(userId);
default:
return false;
}
}
}
A.8.8 - Management of Technical Vulnerabilities
A.8.9 - Configuration Management
# Document all configuration in Infrastructure as Code
# Store in version control (git)
# Example: AWS CloudFormation for infrastructure
AWSTemplateFormatVersion: '2010-09-09'
Description: 'CIA Platform Infrastructure - ISO 27001 Compliant'
Resources:
# Database with encryption enabled (A.8.24)
CIADatabase:
Type: AWS::RDS::DBInstance
Properties:
Engine: postgres
StorageEncrypted: true
KmsKeyId: !Ref DatabaseEncryptionKey
BackupRetentionPeriod: 30
EnableCloudwatchLogsExports:
- postgresql
DeletionProtection: true
# Application servers with security group restrictions
AppSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: CIA Application Security Group
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 443
ToPort: 443
CidrIp: 0.0.0.0/0 # HTTPS only
SecurityGroupEgress:
- IpProtocol: tcp
FromPort: 443
ToPort: 443
DestinationSecurityGroupId: !Ref DatabaseSecurityGroup
A.8.11 - Data Masking
@Component
public class DataMaskingService {
public String maskPersonalId(String personalId) {
if (personalId == null || personalId.length() < 12) return "***";
return personalId.substring(0, 4) + "****" + personalId.substring(8);
}
public String maskEmail(String email) {
if (email == null || !email.contains("@")) return "***@***";
int atIndex = email.indexOf('@');
String prefix = email.substring(0, Math.min(2, atIndex));
String suffix = email.substring(atIndex);
return prefix + "***" + suffix;
}
public String maskPhoneNumber(String phone) {
if (phone == null || phone.length() < 8) return "***";
return phone.substring(0, 3) + "****" + phone.substring(phone.length() - 2);
}
}
// Use in logging
log.info("User accessed document: userId={}, documentId={}",
dataMaskingService.maskPersonalId(userId), documentId);
A.8.23 - Web Filtering
@Configuration
public class SecurityHeadersConfig {
@Bean
public SecurityFilterChain securityHeaders(HttpSecurity http) throws Exception {
http.headers(headers -> headers
.contentSecurityPolicy("default-src 'self'; " +
"script-src 'self'; " +
"style-src 'self'; " +
"img-src 'self' data: https:; " +
"font-src 'self'; " +
"connect-src 'self'; " +
"frame-ancestors 'none';")
.xssProtection()
.frameOptions().deny()
.httpStrictTransportSecurity()
.maxAgeInSeconds(31536000)
.includeSubDomains(true)
.preload(true)
);
return http.build();
}
}
A.8.24 - Use of Cryptography
A.8.28 - Secure Coding
A.14.2.1 - Secure Development Policy
Required elements:
A.14.2.5 - Secure System Engineering Principles
A.14.2.8 - System Security Testing
# Automated security testing pipeline
# .github/workflows/security-testing.yml
name: Security Testing
on:
pull_request:
push:
branches: [main]
jobs:
sast:
name: Static Application Security Testing
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# CodeQL SAST
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: java
queries: security-and-quality
- name: Build
run: mvn clean compile -DskipTests
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
# SonarCloud
- name: SonarCloud Scan
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
run: mvn sonar:sonar -Dsonar.qualitygate.wait=true
# OWASP Dependency Check
- name: OWASP Dependency Check
run: mvn org.owasp:dependency-check-maven:check
- name: Upload Dependency Check Report
uses: actions/upload-artifact@v4
with:
name: dependency-check-report
path: target/dependency-check-report.html
dast:
name: Dynamic Application Security Testing
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# Start application
- name: Start Application
run: |
docker-compose up -d
sleep 30
# OWASP ZAP scan
- name: ZAP Scan
uses: zaproxy/action-baseline@v0.7.0
with:
target: 'http://localhost:8080'
rules_file_name: '.zap/rules.tsv'
cmd_options: '-a'
A.14.2.9 - System Acceptance Testing
Security acceptance criteria:
A.16.1.4 - Assessment and Decision of Information Security Events
@Service
public class SecurityIncidentService {
public void reportIncident(SecurityIncident incident) {
// Assess severity
IncidentSeverity severity = assessSeverity(incident);
// Log to SIEM
siemLogger.log(severity, incident);
// Notify security team for high/critical incidents
if (severity.isHighOrCritical()) {
notificationService.notifySecurityTeam(incident);
}
// Create incident record
incidentRepository.save(incident);
// Initiate incident response if needed
if (severity == IncidentSeverity.CRITICAL) {
incidentResponseService.initiate(incident);
}
}
private IncidentSeverity assessSeverity(SecurityIncident incident) {
// Classify based on impact and likelihood
if (incident.involvesDataBreach()) {
return IncidentSeverity.CRITICAL;
}
if (incident.affectsAvailability()) {
return IncidentSeverity.HIGH;
}
if (incident.involvesUnauthorizedAccess()) {
return IncidentSeverity.MEDIUM;
}
return IncidentSeverity.LOW;
}
}
Use this checklist for each ISO 27001 control:
Control Identification
Implementation
Evidence Collection
Testing & Verification
Documentation
#!/bin/bash
# iso27001-compliance-check.sh
echo "=== ISO 27001 Compliance Verification ==="
# A.8.8 - Check for known vulnerabilities
echo "Checking for vulnerabilities (A.8.8)..."
mvn org.owasp:dependency-check-maven:check
if [ $? -ne 0 ]; then
echo "❌ FAIL: Vulnerabilities detected"
else
echo "✅ PASS: No vulnerabilities"
fi
# A.8.24 - Verify TLS configuration
echo "Checking TLS configuration (A.8.24)..."
if grep -q "TLSv1.3,TLSv1.2" server.xml; then
echo "✅ PASS: TLS 1.2+ configured"
else
echo "❌ FAIL: Weak TLS configuration"
fi
# A.8.28 - Run security scans
echo "Running SAST scans (A.8.28)..."
mvn sonar:sonar -Dsonar.qualitygate.wait=true
if [ $? -eq 0 ]; then
echo "✅ PASS: Code quality gate passed"
else
echo "❌ FAIL: Code quality issues"
fi
# A.14.2.8 - Security test coverage
echo "Checking security test coverage..."
mvn test
coverage=$(grep -oP 'Coverage: \K[0-9]+' target/site/jacoco/index.html)
if [ "$coverage" -ge 80 ]; then
echo "✅ PASS: Test coverage ${coverage}%"
else
echo "❌ FAIL: Test coverage below 80%"
fi
echo "=== Compliance Check Complete ==="
Maintain these documents for ISO 27001 compliance:
ISMS Policy (✅ Required)
Risk Assessment (✅ Required)
Statement of Applicability (SOA) (✅ Required)
Procedures (✅ Required)
Records (✅ Required)
Comprehensive ISO 27001 Implementation Documentation:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC