ISO 27001:2022 Scanning
Scan cloud infrastructure against ISO 27001:2022 Annex A controls, derived by crosswalk from SOC 2 and CIS.
International information security management standard guide.
Overview
ISO/IEC 27001 is the international standard for information security management systems (ISMS).
Who needs it: Organizations worldwide seeking information security certification
Status in AuditKit: Production
Coverage: 53 controls, derived via the NIST 800-53 crosswalk - 53 on AWS, Azure and GCP alike, out of the 93 controls in Annex A
What's covered: Technical controls (A.8), organizational (A.5), people (A.6), physical (A.7)
Important Disclaimer
AuditKit's ISO 27001 support covers technical controls only - NOT sufficient for ISO 27001 certification.
What AuditKit covers:
- Annex A technological controls (A.8) - 32 of 34 automated
- Some organizational controls (A.5) - via configuration checks
- Limited people controls (A.6) - user/account management only
- Limited physical controls (A.7) - cloud provider inheritance
What AuditKit does NOT cover:
- ISMS documentation (policies, procedures, records)
- Risk assessment and treatment
- Internal audits
- Management review
- Continual improvement processes
- Organizational controls requiring human processes
Use for: Technical control assessment as part of ISO 27001 compliance program
Don't use for: Sole evidence of ISO 27001 certification
Hire a consultant for: Complete ISMS implementation and certification audit
ISO 27001:2022 Changes
The 2022 version reduced controls from 114 to 93 and reorganized into 4 themes:
Changes from 2013 version:
- Consolidated from 14 to 4 control categories
- 11 new controls (cloud, threat intelligence, data masking)
- 24 merged controls
- 58 controls with updated titles
- Stronger focus on cloud security
AuditKit supports ISO 27001:2022
Annex A Controls
A.5: Organizational Controls (37 controls)
Focus on policies, roles, responsibilities, asset management:
AuditKit Coverage:
- A.5.1: Information security policies
- A.5.9: Asset inventory
- A.5.10: Acceptable use
- A.5.14: Information transfer
- A.5.23: Information security for cloud services
- A.5.30: ICT readiness for business continuity
Manual/Organizational:
- Risk assessment processes
- Roles and responsibilities
- Contact with authorities
- Project management security
- Supplier relationships
A.6: People Controls (8 controls)
Focus on HR security, awareness, training:
AuditKit Coverage:
- A.6.2: Terms and conditions of employment (via account policies)
- A.6.3: Information security awareness (training logs)
Manual/Organizational:
- Background screening
- Security responsibilities documentation
- Disciplinary process
A.7: Physical Controls (14 controls)
Focus on facility security, equipment protection:
AuditKit Coverage:
- A.7.4: Physical security monitoring (cloud provider docs)
- A.7.13: Equipment maintenance (cloud provider SLAs)
Manual/Organizational (or Cloud Provider Inherited):
- Physical security perimeters
- Physical entry controls
- Securing offices and facilities
- Clear desk and screen policies
- Equipment disposal
A.8: Technological Controls (34 controls) - PRIMARY FOCUS
Fully Automated by AuditKit:
- A.8.2: Privileged access rights
- A.8.3: Information access restriction
- A.8.5: Secure authentication
- A.8.6: Capacity management
- A.8.7: Protection against malware
- A.8.8: Management of technical vulnerabilities
- A.8.9: Configuration management
- A.8.10: Information deletion
- A.8.13: Information backup
- A.8.15: Logging
- A.8.16: Monitoring activities
- A.8.20: Networks security
- A.8.21: Security of network services
- A.8.22: Segregation of networks
- A.8.24: Use of cryptography
- A.8.32: Change management
Partially Automated:
- A.8.1: User endpoint devices (cloud access policies)
- A.8.4: Access to source code (repository settings)
- A.8.17: Clock synchronization (NTP configuration)
- A.8.23: Web filtering (network policies)
Manual/Policy-Based (the only two A.8 controls with no automated check):
- A.8.14: Redundancy of information processing facilities
- A.8.25: Secure development life cycle
Running ISO 27001 Scans
# ISO 27001 scan
auditkit scan -provider aws -framework iso27001
# Azure
auditkit scan -provider azure -framework iso27001
# GCP
auditkit scan -provider gcp -framework iso27001
# Generate report
auditkit scan -provider aws -framework iso27001 -format pdf -output iso27001-report.pdf
# CSV for control tracking
auditkit scan -provider aws -framework iso27001 -format csv -output iso27001-controls.csv
ISO 27001 Certification Process
Stage 1: Planning (Months 1-6)
- Gap Analysis
- Run AuditKit to assess technical controls
- Identify missing organizational controls
-
Document current state
-
ISMS Design
- Define ISMS scope
- Establish security policy
- Conduct risk assessment
-
Create Statement of Applicability (SoA)
-
Implementation Plan
- Prioritize control implementation
- Assign responsibilities
- Set timelines
Stage 2: Implementation (Months 7-12)
- Technical Controls
- Remediate gaps found by AuditKit
- Implement security configurations
-
Deploy monitoring and logging
-
Documentation
- Develop policies and procedures
- Create work instructions
-
Document control implementation
-
Training
- Security awareness for all staff
- Role-specific training
- ISMS process training
Stage 3: Internal Audit (Month 13)
- Conduct internal ISMS audit
- Test control effectiveness
- Document findings
- Remediate gaps
Stage 4: Management Review (Month 14)
- Present ISMS performance to management
- Review audit findings
- Approve changes and improvements
Stage 5: Certification Audit (Months 15-16)
- Stage 1 Audit (Documentation review)
- Certifying body reviews ISMS documentation
- Checks scope definition
- Reviews SoA
-
Identifies major gaps
-
Stage 2 Audit (On-site assessment)
- Certifying body assesses control implementation
- Interviews staff
- Reviews evidence
-
Tests control effectiveness
-
Certification Decision
- Address any non-conformities
- Receive ISO 27001 certificate (valid 3 years)
Stage 6: Surveillance (Ongoing)
- Annual surveillance audits
- Continuous improvement
- Internal audits (at least annually)
- Management reviews (at least annually)
- Recertification every 3 years
ISO 27001 vs Other Frameworks
| Framework | Overlap with ISO 27001 | Notes |
|---|---|---|
| SOC2 | High | Similar technical controls |
| NIST 800-53 | Very High | Most ISO controls map to 800-53 |
| PCI-DSS | Medium | PCI more prescriptive |
| CMMC | High | Both based on similar principles |
| ISO 27017 | Extension | ISO 27001 + cloud-specific controls |
| ISO 27018 | Extension | ISO 27001 + privacy controls |
Key Differentiators:
- ISO 27001 is international (global recognition)
- Requires formal ISMS (not just controls)
- Risk-based approach (tailor controls to risks)
- 3-year certification cycle
- Requires internal audits and management review
Cost Breakdown
| Item | Small Org (<50 people) | Medium Org (50-250) | Large Org (250+) |
|---|---|---|---|
| AuditKit Free | $0 | $0 | $0 |
| Gap analysis | $5K-15K | $15K-30K | $30K-60K |
| ISMS implementation | $20K-50K | $50K-100K | $100K-200K |
| Documentation | $10K-25K | $25K-50K | $50K-100K |
| Training | $5K-10K | $10K-25K | $25K-50K |
| Internal audit | $5K-10K | $10K-20K | $20K-40K |
| Certification audit | $10K-20K | $20K-40K | $40K-80K |
| Initial certification | $55K-130K | $130K-265K | $265K-530K |
| Annual surveillance | $10K-20K | $20K-40K | $40K-80K |
| Recertification (Year 3) | $10K-20K | $20K-40K | $40K-80K |
Timeline: 12-18 months from start to certification
Choosing a Certification Body
Accredited certification bodies (CB) vary by:
Accreditation: Look for UKAS (UK), ANAB (US), DAkkS (Germany), JAB (Japan)
Industry Experience: Choose CB with experience in your industry
Global Recognition: Major CBs:
- BSI (British Standards Institution)
- SGS
- Bureau Veritas
- LRQA
- TUV
- DNV
Cost: $10K-80K depending on organization size and scope
Common ISO 27001 Gaps
Based on certification audit findings:
- Incomplete risk assessment (most common)
- Inadequate ISMS documentation
- Insufficient logging and monitoring (A.8.15, A.8.16)
- Weak access controls (A.8.2, A.8.3, A.8.5)
- Missing internal audits
- Poor change management (A.8.32)
- Inadequate security awareness (A.6.3)
- Incomplete Statement of Applicability
AuditKit helps with #3, #4, #6 - you need consultants for #1, #2, #5, #7, #8
FAQ
Q: Can I get ISO 27001 certified using only AuditKit? A: No. AuditKit covers technical controls, but ISO 27001 requires complete ISMS documentation, risk assessments, internal audits, and formal certification audit. Hire a consultant.
Q: How long does ISO 27001 certification take? A: 12-18 months for initial certification. Smaller organizations may achieve it faster (9-12 months).
Q: What's the difference between ISO 27001 and ISO 27002? A: ISO 27001 is the certifiable standard (requirements). ISO 27002 is the implementation guide (best practices). You get certified to 27001, not 27002.
Q: Do I need to implement all 93 controls? A: No. ISO 27001 allows risk-based exclusions. Document justification in your Statement of Applicability (SoA).
Q: How much does ISO 27001 certification cost? A: Small org: $55K-130K initial, $10K-20K annual. Medium org: $130K-265K initial, $20K-40K annual.
Q: Is ISO 27001 recognized globally? A: Yes. ISO 27001 is the most widely recognized information security certification worldwide.
Q: What happens if I fail the certification audit? A: You receive non-conformity reports. Address them within specified timeframe, then CB re-audits. Most organizations pass on second attempt.
Q: Can I transfer my certificate if I change certification bodies? A: Yes, though the new CB may require a transfer audit to verify your ISMS.
Q: Does ISO 27001 help with GDPR compliance? A: Yes. ISO 27001 addresses many GDPR security requirements, though GDPR has additional privacy-specific requirements.
ISO 27001 and Cloud
Shared Responsibility:
- Cloud providers (AWS, Azure, GCP) have ISO 27001 certification for their infrastructure
- You're responsible for your applications and configurations
- Use cloud provider inherited controls in your SoA
Cloud-Specific Controls:
- A.5.23: Information security for use of cloud services
- A.8.20-22: Network security (cloud networks)
- A.8.24: Cryptography (cloud encryption)
AuditKit helps verify your cloud configurations align with ISO 27001 requirements.
Recommended Path
Phase 1: Assessment (Months 1-3)
- Run AuditKit for technical gap analysis
- Conduct full ISMS gap assessment
- Define ISMS scope
- Select certification body
Phase 2: Design (Months 4-6)
- Establish security policy
- Conduct risk assessment
- Create Statement of Applicability
- Design ISMS processes
Phase 3: Implementation (Months 7-12)
- Implement controls (use AuditKit for technical)
- Develop ISMS documentation
- Deploy monitoring and logging
- Train all personnel
Phase 4: Audit (Months 13-15)
- Conduct internal audit
- Management review
- Remediate findings
- Prepare for certification audit
Phase 5: Certification (Months 16-18)
- Stage 1 audit (documentation review)
- Address Stage 1 findings
- Stage 2 audit (on-site assessment)
- Receive ISO 27001 certificate
Phase 6: Maintain (Ongoing)
- Annual surveillance audits
- Internal audits (minimum annually)
- Management reviews (minimum annually)
- Continuous improvement
- Recertification every 3 years
Next Steps
- Run ISO 27001 technical scan
- Compare to SOC2
- Compare to NIST 800-53
- Find certification body
- ISO 27001 official standard
Remember: AuditKit covers technical controls (Annex A.8). Hire an ISO 27001 consultant for complete ISMS implementation and certification.
Scan your environment
Point AuditKit at AWS, Azure or GCP with read-only credentials and get every finding with the command to fix it. Full results in about thirty minutes.
Start 14-Day Free Trial$297/month after the trial. Cancel any time. The Community Edition is free and open source.