Critical foundational / security-critical
High required for certification
Medium maturity & hardening
A.8.24 Annex A control reference
Start here. Clauses 4–10 are the management-system requirements auditors assess first — the ISMS itself. The 15 workstreams and SPIEL-specific controls below are largely the Annex A controls you select through your Risk Treatment Plan and record in the Statement of Applicability. You cannot certify on technical security alone: evidence and governance are graded equally.
Part A — Mandatory ISMS (Clauses 4–10)
Part B — The 15 Security Workstreams (Annex A controls)
Part C — SPIEL-Specific Controls (beyond ISO 27001)