Compliance/Security frameworks/ISO/IEC 27001:2022
Ninety-three controls: twenty leave evidence in the file.
ISO/IEC 27001 asks you to choose controls and show they operate. Vaultize adds records that stay with the data.
- Certifiable standard
- Capability mapping, not certification
- ISO/IEC 27001:2022 · Amd 1:2024
ORG
Organizational
10 of 37
- 5.1
- 5.2
- 5.3
- 5.4
- 5.5
- 5.6
- 5.7
- 5.8
- 5.9
- 5.10
- 5.11
- 5.12
- 5.13
- 5.14
- 5.15
- 5.16
- 5.17
- 5.18
- 5.19
- 5.20
- 5.21
- 5.22
- 5.23
- 5.24
- 5.25
- 5.26
- 5.27
- 5.28
- 5.29
- 5.30
- 5.31
- 5.32
- 5.33
- 5.34
- 5.35
- 5.36
- 5.37
PEO
People
2 of 8
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
PHY
Physical
0 of 14
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 7.8
- 7.9
- 7.10
- 7.11
- 7.12
- 7.13
- 7.14
TEC
Technological
8 of 34
- 8.1
- 8.2
- 8.3
- 8.4
- 8.5
- 8.6
- 8.7
- 8.8
- 8.9
- 8.10
- 8.11
- 8.12
- 8.13
- 8.14
- 8.15
- 8.16
- 8.17
- 8.18
- 8.19
- 8.20
- 8.21
- 8.22
- 8.23
- 8.24
- 8.25
- 8.26
- 8.27
- 8.28
- 8.29
- 8.30
- 8.31
- 8.32
- 8.33
- 8.34
5.9
Inventory of information and other associated assets
Discover & Classify
The answer in 30 seconds
Vaultize adds file-level records to 20 Annex A controls across the organizational, people and technological themes. Physical controls and the other 73 belong to other control owners.
The standard in one view
Four themes. Ninety-three controls. Where file evidence lands.
Annex A groups its controls into four themes. Select a theme to see which of its controls a governed file can evidence.
ORG
Organizational
Organizational controls, 5.1 to 5.37
Outcomes the file can evidence
- How Vaultize contributes
- Discover & Classify builds the inventory and applies classification bands and labels. Vaultize Seal binds access rights to the file. Vaultize Share governs transfer and supplier access. Vaultize Secure preserves records and evidence.
- Evidence to retain
- Inventory and classification records. Sealed rights per recipient. Transfer and recipient audit trails. Preserved versions.
Control by control
What each control asks. What the file can answer.
Control numbers and titles are from Annex A of ISO/IEC 27001:2022. Read the control wording in the standard. Each row is a capability mapping, not a certification.
Using this page
Where these rows fit in the ISMS.
ISO/IEC 27001 runs as a management system. This page is evidence for the Statement of Applicability and the operation of the controls it lists.
- 1
Define the scope
Clause 4. Set the boundaries of the ISMS.
- 2
Assess the risks
Clause 6. Identify and analyse information security risks.
- 3
Treat and declare
Clause 6. Choose controls and record them in the Statement of Applicability. These rows belong here.
Bring the twenty rows above as evidence for the controls you declare applicable.
- 4
Operate the controls
Clause 8. Run the controls and keep the records.
- 5
Audit and review
Clauses 9 and 10. Internal audit, management review, improvement.
Responsibility boundary
Controls support certification. A product does not confer it.
Vaultize contributes technical controls and evidence to an ISMS. It does not certify, attest, or decide which controls apply. Certification is granted by an external certification body after its own audit, not by ISO and not by a product. Read the standard and obtain qualified advice before relying on this page.
Official references
Read the source before relying on the mapping.
Control numbers, titles and clause names come from the first item. The others are ISO’s own guidance.
A practical next step
Bring your Statement of Applicability.
We will mark which declared controls the governed file can evidence today. We will name the control owner responsible for the rest.
