Compliance Scanning

ISO 27001 Annex A
Compliance Scanning

ISO 27001 is the international standard for information security management systems (ISMS). ComplianceLayer maps external scan findings to the specific Annex A controls covering cryptography, network security, communications security, and application security.

Control Mapping

ISO 27001 Annex A Controls Mapped to Scan Modules

The following Annex A controls from ISO/IEC 27001:2013 are verified through external scanning. Control references follow the standard Annex A numbering.

Control IDControl NameScan ModuleWhat We Check
A.9.1.2Access to Networks and ServicesOpen PortsUsers shall only be provided access to network services they are specifically authorized to use. Detects exposed RDP, database, and administrative ports.
A.9.4.1Information Access RestrictionOpen PortsAccess to information and application system functions shall be restricted. Identifies exposed database ports (MySQL, PostgreSQL) and administrative interfaces.
A.10.1.1Policy on Cryptographic ControlsSSL/TLSA policy on the use of cryptographic controls shall be implemented. Validates TLS versions, cipher suite strength, and HTTPS enforcement.
A.10.1.2Key ManagementSSL/TLSA policy on the use, protection, and lifetime of cryptographic keys shall be implemented. Checks certificate validity, expiration, and self-signed certificate usage.
A.12.2.1Controls Against MalwareSecurity HeadersDetection, prevention, and recovery controls against malware shall be implemented. Validates Content-Security-Policy for script injection prevention.
A.12.6.1Management of Technical VulnerabilitiesAll ModulesInformation about technical vulnerabilities shall be obtained and appropriate measures taken. ComplianceLayer scans 16 modules continuously.
A.13.1.1Network ControlsOpen PortsNetworks shall be managed and controlled to protect information. Detects exposed SMB, Telnet, FTP, and other unnecessary network services.
A.13.2.1Information Transfer PoliciesEmailFormal transfer policies shall be in place. Validates SPF, DKIM, DMARC, and Referrer-Policy for secure information transfer.
A.13.2.3Electronic MessagingEmailInformation involved in electronic messaging shall be appropriately protected. Checks email authentication (SPF, DKIM, DMARC) configuration.
A.14.1.2Securing Application ServicesSSL/TLS / HeadersApplication services on public networks shall be protected. Validates TLS configuration, HSTS enforcement, and security header presence.
A.14.2.5Secure System Engineering PrinciplesSecurity HeadersPrinciples for engineering secure systems shall be established. Checks CSP, X-Frame-Options, X-Content-Type-Options, and Permissions-Policy.

ISO 27001 certification requires formal audit and organizational controls. These are ISO 27001-relevant technical controls verifiable externally. Full certification requires an accredited certification body assessment.

How It Works

ISO 27001 Evidence Collection in 3 Steps

01

Enter your domain

Submit any domain your organization operates. ComplianceLayer scans the external surface across 16 security modules.

02

Review Annex A mapping

Each finding maps to specific ISO 27001 Annex A controls with pass, fail, or partial status.

03

Support your ISMS

Download the compliance report as evidence for your Statement of Applicability, surveillance audits, or certification preparation.

FAQ

Common questions

Does ComplianceLayer provide ISO 27001 certification?

No. ISO 27001 certification requires a formal audit by an accredited certification body. ComplianceLayer maps your external security posture to Annex A controls, providing documented evidence that supports the technical control requirements of your ISMS.

Which ISO 27001 Annex A controls does ComplianceLayer cover?

ComplianceLayer maps to Annex A controls in domains A.9 (Access Control), A.10 (Cryptography), A.12 (Operations Security), A.13 (Communications Security), and A.14 (System Acquisition, Development, and Maintenance). These are the controls with externally verifiable technical aspects.

How does ComplianceLayer help with ISO 27001 Statement of Applicability?

The compliance scan report shows which Annex A controls are met, partially met, or failing based on external scanning. This directly supports your Statement of Applicability (SoA) by providing evidence for the technical controls you declare as applicable.

Can ComplianceLayer be used for ISO 27001 surveillance audits?

Yes. After initial certification, ISO 27001 requires annual surveillance audits. Continuous ComplianceLayer scanning provides an ongoing audit trail demonstrating that your technical controls remain effective between formal audits.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.