Skip to content
Obligara

ISO 27001:2022

The ISMS, instantiated — not a template pack

38 clauses and all 93 Annex A controls instantiated per workspace, with a Statement of Applicability, asset register, supplier governance, security incident management and risk treatments — backed by a ~180-question audit bank.

ISO 27001 · moduleISMS

93

Annex A controls

38

clauses

~180

audit questions

  • Statement of Applicability
  • Asset register (A.5.9)
  • Supplier governance (A.5.19–23)
  • Incidents & risk treatments

What’s in the module

All 93 Annex A controls, instantiated per workspace

Your Statement of Applicability isn’t a spreadsheet that drifts — it’s instantiated from the standard and stays in sync with the work.

  • 01

    Statement of Applicability

    All 93 Annex A controls instantiated per workspace with applicability, justification and implementation status — your SoA stays in sync with the work, not a stale spreadsheet.

  • 02

    Asset register (A.5.9)

    A first-class inventory of information assets with ownership and classification, linked to the controls and risks that protect them.

  • 03

    Supplier governance (A.5.19–23)

    Track supplier relationships, security in agreements and ICT supply-chain risk where the standard expects it.

  • 04

    Incidents & risk treatments

    Security incident management (A.5.24–28) and clause 6.1.3 risk treatments, wired into the same audit log as everything else.

Risk-driven, by design

From risk to treatment to evidence, in one trail

Clause 6.1.3 risk treatments connect to the Annex A controls that address them, which connect to the assets they protect and the evidence that proves them. One trail, one audit log.

  • Statement of Applicability with applicability, justification and status
  • Asset register (A.5.9) with ownership and classification
  • Supplier governance across A.5.19–23, including ICT supply chain
  • Security incident management (A.5.24–28) with post-incident review
  • Clause 6.1.3 risk treatments linked to controls and assets
  • ~180-question audit bank for internal audits

Built on Postgres row-level security

Tenant isolation is enforced by the database, not by hopeful application code, and every change writes an audit-log row in the same transaction. The control that protects your data is the same one protecting ours.

How we secure it

AI gap analysis on the controls

Ask the AI to verdict each control as ready, partial or gap — with the cited evidence references behind the verdict — before an internal or certification audit.

Already on ISO 27001? SOC 2 is mostly done.

Enable SOC 2 and a 71-entry cross-walk carries your existing control evidence onto the Trust Services Criteria — roughly three weeks of duplicate work removed.

See the cross-walk

See your ISMS, instantiated

A walkthrough of the Statement of Applicability, risk treatments and the Annex A controls on your scope.