ISO 27001 control dependencies
Has anyone mapped the dependencies between ISO 27001 controls?
One of the things I've come to appreciate about ISO 27001 is the logical structure behind the controls.
After working with the standard for several years, I've started to see the controls less as individual requirements and more as an interconnected system with dependencies between them.
For example, A.5.9 (Inventory of Information and Other Associated Assets) seems fundamental to many other controls. If you don't have a reliable asset inventory/CMDB, how can you be confident that all relevant systems are included in backup, vulnerability management, monitoring, access reviews, and so on?
There are many similar examples:
A.5.12 Classification → A.5.13 Labelling → A.5.14 Information Transfer
A.5.15 Access Control → A.5.16 Identity Management → A.5.18 Access Rights
A.5.29 Information Security During Disruption → A.5.30 ICT Readiness for Business Continuity
Looking at the standard this way, some controls appear to function as foundation controls, while others depend on them to operate effectively.
Has anyone seen a complete dependency map or hierarchy of ISO 27001:2022 Annex A controls?
I'd be very interested in discussing:
- Which controls you consider the most fundamental.
- Whether some controls should be treated as prerequisites for others.
- How this could be visualized as a dependency graph rather than a flat list of 93 controls.
My hypothesis is that controls such as A.5.2 (Roles and Responsibilities), A.5.9 (Asset Inventory), A.5.16 (Identity Management), and A.8.9 (Configuration Management) would end up among the most central nodes in such a model.
Without a complete overview of systems, and their criticality, it's not possible to do correct access review.
Has anyone explored this before?