Global · 9 controls evidenced

    Continuous evidence for ISO 27001:2022

    Annex A controls auto-evidenced from the public attack surface.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    See your ISO 27001:2022 readiness in 60 seconds. Free, no signup.

    Sample evidence
    acme-corp.com · ISO 27001:2022
    Live
    A.8.24 Use of cryptography
    Encrypted transport (TLS 1.2+)
    A.5.14 Information transfer
    Email authentication (SPF / DKIM / DMARC)
    A.8.23 Web filtering
    Secure HTTP response headers
    A.8.20 Networks security
    DNS hygiene & DNSSEC
    Updated continuously+ 5 more controls
    Why it matters

    ISO 27001:2022 in 30 seconds

    ISO 27001 is the global benchmark for an Information Security Management System. Auditors and enterprise buyers expect documented, dated evidence for every Annex A control you say you implement — not a screenshot taken once a year.

    Scope

    Any organisation pursuing or maintaining an ISO 27001:2022 certificate, or one of its sector-specific derivatives (27017, 27018, 27701).

    Exposure

    Loss of certification + contract loss with enterprise customers.

    Clause-by-clause mapping

    How Security Monitor evidences ISO 27001:2022

    Each row links a ISO 27001:2022 clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.

    ISO 27001:2022 clauseWhat it requiresHow we evidence it
    TLS-1
    A.8.24 Use of cryptography
    Cryptography is applied effectively to protect information confidentiality and integrity in transit.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    EMAIL-1
    A.5.14 Information transfer
    Information transfer rules and controls are in place for electronic communications, including email authenticity.
    Email authentication (SPF / DKIM / DMARC)
    We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses.
    WEB-1
    A.8.23 Web filtering
    Access to external websites is managed; web-facing services enforce hardened response headers.
    Secure HTTP response headers
    We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site.
    DNS-1
    A.8.20 Networks security
    Networks and supporting services are secured, monitored, and configured to prevent unauthorised access.
    DNS hygiene & DNSSEC
    We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls.
    REP-1
    A.5.7 Threat intelligence
    Information about threats relevant to the organisation is collected and analysed to produce intelligence.
    Reputation & threat intelligence
    We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing.
    BREACH-1
    A.5.34 Privacy & PII protection
    Privacy and protection of PII is preserved as required by applicable laws — including detection of leaked credentials.
    Credential exposure monitoring
    We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts.
    EXP-1
    A.5.10 Acceptable use of information
    Information and assets are protected from inappropriate exposure; sensitive resources must not be publicly accessible.
    Exposed files & admin panels
    We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable.
    SUB-1
    A.5.9 Inventory of information & assets
    An inventory of information assets — including externally facing services and the third parties loaded on them — is maintained and accurate.
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    SUB-1
    A.5.19 / A.5.21 Information security in supplier relationships & ICT supply chain
    Identify and document third-party services that process or are exposed to organisational data via your public surface (analytics, payments, chat, CDNs, tag managers). The data flow map evidences this from the outside.
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    Honest scope

    What we don’t cover for ISO 27001:2022

    External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:

    • Internal HR, supplier and physical security controls (Annex A.6, A.7 majority)
    • Internal logging & monitoring of private systems (we observe externally only)
    • Documented policies, risk assessment and ISMS governance — your auditor still needs these
    FAQ

    ISO 27001:2022 questions

    See your ISO 27001:2022 readiness now

    One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption