Skip to content

ISO/IEC 27001:2022 Annex A

Framework version: ISO/IEC 27001:2022.

Control identifiers and titles from Annex A (2022). passmcp supplies technical evidence for the controls it supports; certification is granted by an accredited body, not by a tool.

Every finding in a JSON report carries the controls it evidences under controls.iso27001. passmcp verify --framework iso27001 reads an attestation offline and reports each one below as evidenced, failing or not assessed, and passmcp evidence --framework iso27001 builds a dated evidence bundle from attestations over an audit period.

Controls

Control Title Evidenced by
A.5.1 Policies for information security Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.2 Information security roles and responsibilities Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.3 Segregation of duties Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.4 Management responsibilities Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.5 Contact with authorities Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.6 Contact with special interest groups Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.7 Threat intelligence Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.8 Information security in project management Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.9 Inventory of information and other associated assets Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.10 Acceptable use of information and other associated assets Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.11 Return of assets Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.12 Classification of information catalog.personal_data
A.5.13 Labelling of information Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.14 Information transfer Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.15 Access control a2a.unauthenticated, auth.unauthenticated_tools, auth.wrong_audience, discovery.as, discovery.challenge, discovery.first_contact, discovery.prm, discovery.prm.resource
A.5.16 Identity management auth.registration, discovery.enterprise_managed, discovery.registration
A.5.17 Authentication information auth.token.expiry, fs.credential_probe, resilience.token_refresh, stdio.environment
A.5.18 Access rights auth.token.scope, discovery.challenge.scope
A.5.19 Information security in supplier relationships Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.20 Addressing information security within supplier agreements Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.21 Managing information security in the ICT supply chain a2a.card_signature, supply.buildinfo, supply.provenance
A.5.22 Monitoring, review and change management of supplier services Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.23 Information security for use of cloud services Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.24 Information security incident management planning and preparation Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.25 Assessment and decision on information security events Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.26 Response to information security incidents Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.27 Learning from information security incidents Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.28 Collection of evidence Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.29 Information security during disruption Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.30 ICT readiness for business continuity resilience.upstream_down
A.5.31 Legal, statutory, regulatory and contractual requirements Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.32 Intellectual property rights Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.33 Protection of records Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.34 Privacy and protection of PII catalog.personal_data
A.5.35 Independent review of information security Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.36 Compliance with policies, rules and standards for information security Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.5.37 Documented operating procedures Not covered by passmcp: An organisational control, evidenced by the ISMS's policies, records and processes rather than by testing a server.
A.6.1 Screening Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.2 Terms and conditions of employment Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.3 Information security awareness, education and training Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.4 Disciplinary process Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.5 Responsibilities after termination or change of employment Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.6 Confidentiality or non-disclosure agreements Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.7 Remote working Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.6.8 Information security event reporting Not covered by passmcp: A people control (screening, terms, awareness, reporting); no technical test can evidence it.
A.7.1 Physical security perimeters Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.2 Physical entry Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.3 Securing offices, rooms and facilities Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.4 Physical security monitoring Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.5 Protecting against physical and environmental threats Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.6 Working in secure areas Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.7 Clear desk and clear screen Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.8 Equipment siting and protection Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.9 Security of assets off-premises Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.10 Storage media Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.11 Supporting utilities Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.12 Cabling security Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.13 Equipment maintenance Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.7.14 Secure disposal or re-use of equipment Not covered by passmcp: A physical control; outside what a network or process test can observe.
A.8.1 User end point devices Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.2 Privileged access rights auth.token.scope
A.8.3 Information access restriction a2a.unauthenticated, auth.unauthenticated_tools
A.8.4 Access to source code Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.5 Secure authentication auth.rejects_garbage, auth.token, auth.token.expiry, auth.token.type, auth.wrong_audience, discovery.as, discovery.as.grants, discovery.as.https, discovery.as.pkce, discovery.challenge, discovery.dpop, discovery.first_contact, discovery.prm, discovery.prm.resource
A.8.6 Capacity management execution.payload_size, performance.concurrency, performance.ping, performance.rate_limit, performance.throttle, performance.tools, performance.warmup, resilience.soak_memory
A.8.7 Protection against malware catalog.names.confusable, catalog.text.comments, catalog.text.cross_server_shadowing, catalog.text.encoded, catalog.text.hidden, catalog.text.instructions, catalog.text.secret_paths, catalog.text.shadowing, execution.output_injection, handshake.instructions, stdio.post_init_processes, stdio.post_init_writes
A.8.8 Management of technical vulnerabilities catalog.names.confusable, catalog.text.comments, catalog.text.cross_server_shadowing, catalog.text.encoded, catalog.text.hidden, catalog.text.instructions, catalog.text.shadowing, execution.output_injection, handshake.instructions
A.8.9 Configuration management catalog.baseline, stdio.launch_config
A.8.10 Information deletion Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.11 Data masking Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.12 Data leakage prevention catalog.text.secret_paths, catalog.toxic_combination, egress.hosts, egress.undeclared_host, fs.canary_exfiltrated, fs.credential_probe, stdio.post_init_connections
A.8.13 Information backup Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.14 Redundancy of information processing facilities resilience.session_reinit, resilience.stateless
A.8.15 Logging Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.16 Monitoring activities Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.17 Clock synchronization Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.18 Use of privileged utility programs Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.19 Installation of software on operational systems stdio.launch_config, supply.buildinfo, supply.provenance
A.8.20 Networks security a2a.transport, egress.hosts, egress.undeclared_host, net.scheme, net.tls, net.tls.version, stdio.bind_all, stdio.post_init_connections
A.8.21 Security of network services a2a.transport, net.scheme, net.tls, net.tls.version, protocol.origin
A.8.22 Segregation of networks Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.23 Web filtering Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.24 Use of cryptography a2a.card_signature, a2a.transport, discovery.as.https, net.scheme, net.tls, net.tls.cert, net.tls.version
A.8.25 Secure development life cycle Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.26 Application security requirements catalog.tools.annotation_honesty, catalog.tools.annotations, catalog.tools.idempotency, handshake.session, protocol.bogus_session, protocol.invalid_params, protocol.malformed_json, protocol.origin, protocol.unknown_method, protocol.unknown_tool
A.8.27 Secure system architecture and engineering principles Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.28 Secure coding Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.29 Security testing in development and acceptance protocol.invalid_params, protocol.malformed_json, protocol.unknown_method, protocol.unknown_tool
A.8.30 Outsourced development Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.31 Separation of development, test and production environments Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.32 Change management catalog.baseline
A.8.33 Test information Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.
A.8.34 Protection of information systems during audit testing Not covered by passmcp: A technological control that passmcp does not test: it concerns the organisation's own endpoints, operations or development, not an MCP server's observable behaviour.

Checks

Check Controls
a2a.card_schema None: protocol conformance and interoperability: it shows the agent card is valid A2A, which no control in this framework requires
a2a.card_signature A.5.21, A.8.24
a2a.transport A.8.20, A.8.21, A.8.24
a2a.unauthenticated A.5.15, A.8.3
auth.mode None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
auth.registration A.5.16
auth.rejects_garbage A.8.5
auth.source.* None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
auth.token A.8.5
auth.token.expiry A.5.17, A.8.5
auth.token.scope A.5.18, A.8.2
auth.token.type A.8.5
auth.unauthenticated_tools A.5.15, A.8.3
auth.wrong_audience A.5.15, A.8.5
catalog.baseline A.8.9, A.8.32
catalog.budget.tokens None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.cache_hints None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.empty None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.names.confusable A.8.7, A.8.8
catalog.personal_data A.5.12, A.5.34
catalog.prompts.descriptions None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.prompts.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.mime None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.templates None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.uris None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.semantic.ambiguity None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.text.comments A.8.7, A.8.8
catalog.text.cross_server_shadowing A.8.7, A.8.8
catalog.text.encoded A.8.7, A.8.8
catalog.text.hidden A.8.7, A.8.8
catalog.text.instructions A.8.7, A.8.8
catalog.text.secret_paths A.8.7, A.8.12
catalog.text.shadowing A.8.7, A.8.8
catalog.tools.annotation_honesty A.8.26
catalog.tools.annotations A.8.26
catalog.tools.descriptions None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.idempotency A.8.26
catalog.tools.input_schema None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.output_schema None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.title None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.unique None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.toxic_combination A.8.12
discovery.as A.5.15, A.8.5
discovery.as.grants A.8.5
discovery.as.https A.8.5, A.8.24
discovery.as.pkce A.8.5
discovery.assemble None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.challenge A.5.15, A.8.5
discovery.challenge.scope A.5.18
discovery.creds_unused None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.dpop A.8.5
discovery.enterprise_managed A.5.16
discovery.first_contact A.5.15, A.8.5
discovery.override None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.override.build None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.prm A.5.15, A.8.5
discovery.prm.resource A.5.15, A.8.5
discovery.registration A.5.16
egress.hosts A.8.12, A.8.20
egress.undeclared_host A.8.12, A.8.20
execution.content None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.error_guidance None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.output_injection A.8.7, A.8.8
execution.payload_size A.8.6
execution.policy None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
execution.prompts None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.resources None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.tools None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.validation None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
fs.canary_exfiltrated A.8.12
fs.credential_probe A.5.17, A.8.12
handshake.capabilities None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.initialize None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.instructions A.8.7, A.8.8
handshake.protocol_era None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.protocol_version None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.server_info None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.session A.8.26
handshake.stateless None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
net.dns None: a connectivity precondition for every other check, not evidence of a control
net.scheme A.8.20, A.8.21, A.8.24
net.tcp None: a connectivity precondition for every other check, not evidence of a control
net.tls A.8.20, A.8.21, A.8.24
net.tls.cert A.8.24
net.tls.version A.8.20, A.8.21, A.8.24
performance.concurrency A.8.6
performance.ping A.8.6
performance.rate_limit A.8.6
performance.throttle A.8.6
performance.tools A.8.6
performance.warmup A.8.6
protocol.accept_header None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.bogus_session A.8.26
protocol.deprecated_features None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.extensions None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.get_stream None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.id_echo None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.invalid_params A.8.26, A.8.29
protocol.malformed_json A.8.26, A.8.29
protocol.mrtr None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.origin A.8.21, A.8.26
protocol.ping None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.routing_headers None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.capability None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.lifecycle None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.undeclared None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.unknown_id None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.unknown_method A.8.26, A.8.29
protocol.unknown_tool A.8.26, A.8.29
protocol.version_header None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
resilience.session_reinit A.8.14
resilience.soak_memory A.8.6
resilience.stateless A.8.14
resilience.token_refresh A.5.17
resilience.upstream_down A.5.30
stdio.alive None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.bind_all A.8.20
stdio.clean_exit None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.environment A.5.17
stdio.launch_config A.8.9, A.8.19
stdio.no_zombie None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.post_init_connections A.8.12, A.8.20
stdio.post_init_processes A.8.7
stdio.post_init_writes A.8.7
stdio.process None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.stderr None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.stdout_clean None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
supply.buildinfo A.5.21, A.8.19
supply.provenance A.5.21, A.8.19