Annex A controls auto-evidenced from the public attack surface.
See your ISO 27001:2022 readiness in 60 seconds. Free, no signup.
ISO 27001 is the global benchmark for an Information Security Management System. Auditors and enterprise buyers expect documented, dated evidence for every Annex A control you say you implement — not a screenshot taken once a year.
Any organisation pursuing or maintaining an ISO 27001:2022 certificate, or one of its sector-specific derivatives (27017, 27018, 27701).
Loss of certification + contract loss with enterprise customers.
Each row links a ISO 27001:2022 clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.
| ISO 27001:2022 clause | What it requires | How we evidence it |
|---|---|---|
TLS-1 A.8.24 Use of cryptography | Cryptography is applied effectively to protect information confidentiality and integrity in transit. | Encrypted transport (TLS 1.2+) We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname. |
EMAIL-1 A.5.14 Information transfer | Information transfer rules and controls are in place for electronic communications, including email authenticity. | Email authentication (SPF / DKIM / DMARC) We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses. |
WEB-1 A.8.23 Web filtering | Access to external websites is managed; web-facing services enforce hardened response headers. | Secure HTTP response headers We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site. |
DNS-1 A.8.20 Networks security | Networks and supporting services are secured, monitored, and configured to prevent unauthorised access. | DNS hygiene & DNSSEC We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls. |
REP-1 A.5.7 Threat intelligence | Information about threats relevant to the organisation is collected and analysed to produce intelligence. | Reputation & threat intelligence We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing. |
BREACH-1 A.5.34 Privacy & PII protection | Privacy and protection of PII is preserved as required by applicable laws — including detection of leaked credentials. | Credential exposure monitoring We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts. |
EXP-1 A.5.10 Acceptable use of information | Information and assets are protected from inappropriate exposure; sensitive resources must not be publicly accessible. | Exposed files & admin panels We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable. |
SUB-1 A.5.9 Inventory of information & assets | An inventory of information assets — including externally facing services and the third parties loaded on them — is maintained and accurate. | Third-party data flow map (subdomains & external services) We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses. |
SUB-1 A.5.19 / A.5.21 Information security in supplier relationships & ICT supply chain | Identify and document third-party services that process or are exposed to organisational data via your public surface (analytics, payments, chat, CDNs, tag managers). The data flow map evidences this from the outside. | Third-party data flow map (subdomains & external services) We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses. |
External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:
One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.
Article 21 cybersecurity measures + Article 23 incident reporting.
Information security in Dutch healthcare — technische maatregelen.
Continuous evidence for CC6 (logical access) and CC7 (system operations).
Article 32 security of processing + Article 33 breach notification.
Digital Operational Resilience Act for financial entities.
External requirements for any business handling cardholder data.
We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies (Google Analytics, Google Tag Manager) to improve the product. You can change your choice anytime via "Cookie preferences" in the footer. Privacy Policy · Sub-processors