ISO 27001:2022
The ISMS, instantiated — not a template pack
38 clauses and all 93 Annex A controls instantiated per workspace, with a Statement of Applicability, asset register, supplier governance, security incident management and risk treatments — backed by a ~180-question audit bank.
93
Annex A controls
38
clauses
~180
audit questions
- Statement of Applicability
- Asset register (A.5.9)
- Supplier governance (A.5.19–23)
- Incidents & risk treatments
What’s in the module
All 93 Annex A controls, instantiated per workspace
Your Statement of Applicability isn’t a spreadsheet that drifts — it’s instantiated from the standard and stays in sync with the work.
- 01
Statement of Applicability
All 93 Annex A controls instantiated per workspace with applicability, justification and implementation status — your SoA stays in sync with the work, not a stale spreadsheet.
- 02
Asset register (A.5.9)
A first-class inventory of information assets with ownership and classification, linked to the controls and risks that protect them.
- 03
Supplier governance (A.5.19–23)
Track supplier relationships, security in agreements and ICT supply-chain risk where the standard expects it.
- 04
Incidents & risk treatments
Security incident management (A.5.24–28) and clause 6.1.3 risk treatments, wired into the same audit log as everything else.
Risk-driven, by design
From risk to treatment to evidence, in one trail
Clause 6.1.3 risk treatments connect to the Annex A controls that address them, which connect to the assets they protect and the evidence that proves them. One trail, one audit log.
- Statement of Applicability with applicability, justification and status
- Asset register (A.5.9) with ownership and classification
- Supplier governance across A.5.19–23, including ICT supply chain
- Security incident management (A.5.24–28) with post-incident review
- Clause 6.1.3 risk treatments linked to controls and assets
- ~180-question audit bank for internal audits
Built on Postgres row-level security
Tenant isolation is enforced by the database, not by hopeful application code, and every change writes an audit-log row in the same transaction. The control that protects your data is the same one protecting ours.
How we secure itAI gap analysis on the controls
Ask the AI to verdict each control as ready, partial or gap — with the cited evidence references behind the verdict — before an internal or certification audit.
Already on ISO 27001? SOC 2 is mostly done.
Enable SOC 2 and a 71-entry cross-walk carries your existing control evidence onto the Trust Services Criteria — roughly three weeks of duplicate work removed.
See your ISMS, instantiated
A walkthrough of the Statement of Applicability, risk treatments and the Annex A controls on your scope.