T1 Asset Management 94 T2 Physical and Environmental Security 103 T3 Operations Management 114 T4 Communications 131 T5 Access Control 146 T6 Third-Party Security 167 T7 Information Systems Acquisition, Development and Maintenance 173 T8 Information Security Incident Management 195 T9 Information Systems Continuity Management 207 Annex A: Summary of Always Applicable Controls 215 Annex B: Summary of the Prioritized Controls 216 Annex C: Mapping of Controls against Leading Standards 224 Annex D: Mapping of Threats to Controls 235 Annex E: Sector and National Level Controls 238 Annex F: Terms and Definitions 240 Annex G: Bibliography 246 3

Select target paragraph3