Loading Vaultize
Skip to main content

Compliance/Security frameworks/ISO/IEC 27001:2022

Ninety-three controls: twenty leave evidence in the file.

ISO/IEC 27001 asks you to choose controls and show they operate. Vaultize adds records that stay with the data.

  • Certifiable standard
  • Capability mapping, not certification
  • ISO/IEC 27001:2022 · Amd 1:2024

ORG

Organizational

10 of 37

  • 5.1
  • 5.2
  • 5.3
  • 5.4
  • 5.5
  • 5.6
  • 5.7
  • 5.8
  • 5.9
  • 5.10
  • 5.11
  • 5.12
  • 5.13
  • 5.14
  • 5.15
  • 5.16
  • 5.17
  • 5.18
  • 5.19
  • 5.20
  • 5.21
  • 5.22
  • 5.23
  • 5.24
  • 5.25
  • 5.26
  • 5.27
  • 5.28
  • 5.29
  • 5.30
  • 5.31
  • 5.32
  • 5.33
  • 5.34
  • 5.35
  • 5.36
  • 5.37

PEO

People

2 of 8

  • 6.1
  • 6.2
  • 6.3
  • 6.4
  • 6.5
  • 6.6
  • 6.7
  • 6.8

PHY

Physical

0 of 14

  • 7.1
  • 7.2
  • 7.3
  • 7.4
  • 7.5
  • 7.6
  • 7.7
  • 7.8
  • 7.9
  • 7.10
  • 7.11
  • 7.12
  • 7.13
  • 7.14

TEC

Technological

8 of 34

  • 8.1
  • 8.2
  • 8.3
  • 8.4
  • 8.5
  • 8.6
  • 8.7
  • 8.8
  • 8.9
  • 8.10
  • 8.11
  • 8.12
  • 8.13
  • 8.14
  • 8.15
  • 8.16
  • 8.17
  • 8.18
  • 8.19
  • 8.20
  • 8.21
  • 8.22
  • 8.23
  • 8.24
  • 8.25
  • 8.26
  • 8.27
  • 8.28
  • 8.29
  • 8.30
  • 8.31
  • 8.32
  • 8.33
  • 8.34

5.9

Inventory of information and other associated assets

Discover & Classify

20of 93 Annex A controls

The answer in 30 seconds

Vaultize adds file-level records to 20 Annex A controls across the organizational, people and technological themes. Physical controls and the other 73 belong to other control owners.

The standard in one view

Four themes. Ninety-three controls. Where file evidence lands.

Annex A groups its controls into four themes. Select a theme to see which of its controls a governed file can evidence.

ORGORGANIZATIONALPEOPEOPLEPHYPHYSICALTECTECHNOLOGICAL

ORG

Organizational

Organizational controls, 5.1 to 5.37

Outcomes the file can evidence

How Vaultize contributes
Discover & Classify builds the inventory and applies classification bands and labels. Vaultize Seal binds access rights to the file. Vaultize Share governs transfer and supplier access. Vaultize Secure preserves records and evidence.
Evidence to retain
Inventory and classification records. Sealed rights per recipient. Transfer and recipient audit trails. Preserved versions.

Control by control

What each control asks. What the file can answer.

Control numbers and titles are from Annex A of ISO/IEC 27001:2022. Read the control wording in the standard. Each row is a capability mapping, not a certification.

Using this page

Where these rows fit in the ISMS.

ISO/IEC 27001 runs as a management system. This page is evidence for the Statement of Applicability and the operation of the controls it lists.

  1. 1

    Define the scope

    Clause 4. Set the boundaries of the ISMS.

  2. 2

    Assess the risks

    Clause 6. Identify and analyse information security risks.

  3. 3

    Treat and declare

    Clause 6. Choose controls and record them in the Statement of Applicability. These rows belong here.

    Bring the twenty rows above as evidence for the controls you declare applicable.

  4. 4

    Operate the controls

    Clause 8. Run the controls and keep the records.

  5. 5

    Audit and review

    Clauses 9 and 10. Internal audit, management review, improvement.

Responsibility boundary

Controls support certification. A product does not confer it.

Vaultize contributes technical controls and evidence to an ISMS. It does not certify, attest, or decide which controls apply. Certification is granted by an external certification body after its own audit, not by ISO and not by a product. Read the standard and obtain qualified advice before relying on this page.

A practical next step

Bring your Statement of Applicability.

We will mark which declared controls the governed file can evidence today. We will name the control owner responsible for the rest.

Request a compliance mapping session