ISO 27001 Annex A
Compliance Scanning
ISO 27001 is the international standard for information security management systems (ISMS). ComplianceLayer maps external scan findings to the specific Annex A controls covering cryptography, network security, communications security, and application security.
ISO 27001 Annex A Controls Mapped to Scan Modules
The following Annex A controls from ISO/IEC 27001:2022 are assessed through external scanning. Control references follow the standard Annex A numbering.
| Control ID | Control Name | Scan Module | What We Check |
|---|---|---|---|
| A.5.15 | Access Control | Open Ports | Rules to control access to information and associated assets shall be established. Detects exposed RDP, database, and administrative ports. |
| A.8.3 | Information Access Restriction | Open Ports | Access to information and other associated assets shall be restricted. Identifies exposed database ports (MySQL, PostgreSQL) and administrative interfaces. |
| A.8.24 | Use of Cryptography | SSL/TLS | Rules for the effective use of cryptography, including key management, shall be defined and implemented. Validates TLS versions, cipher strength, HTTPS enforcement, certificate validity, expiration, and self-signed certificate usage. |
| A.8.7 | Protection Against Malware | Security Headers | Protection against malware shall be implemented. Validates Content-Security-Policy for script injection prevention. |
| A.8.8 | Management of Technical Vulnerabilities | All Modules | Information about technical vulnerabilities shall be obtained and appropriate measures taken. ComplianceLayer scans across 15 modules continuously. |
| A.8.20 | Networks Security | Open Ports | Networks and network devices shall be secured, managed, and controlled. Detects exposed SMB, Telnet, FTP, and other unnecessary network services. |
| A.5.14 | Information Transfer | Information transfer rules shall be in place for all types of transfer, including electronic messaging. Validates SPF, DKIM, DMARC, and Referrer-Policy configuration. | |
| A.8.26 | Application Security Requirements | SSL/TLS / Headers | Information security requirements shall be applied to application services on public networks. Validates TLS configuration, HSTS enforcement, and security header presence. |
| A.8.27 | Secure System Architecture and Engineering Principles | Security Headers | Principles for engineering secure systems shall be established and applied. Checks CSP, X-Frame-Options, X-Content-Type-Options, and Permissions-Policy. |
ISO 27001 certification requires formal audit and organizational controls. These are ISO 27001-relevant technical controls observable externally. Full certification requires an accredited certification body assessment. Control names are summaries for readability, not quotations from the published standard.
ISO 27001 Evidence Collection in 3 Steps
Enter your domain
Submit any domain your organization operates. ComplianceLayer scans the external surface across 15 scan modules.
Review Annex A mapping
Each finding maps to specific ISO 27001 Annex A controls with pass, fail, or partial status.
Support your ISMS
Download the compliance report to support your Statement of Applicability, surveillance audits, or certification preparation.
Common questions
Does ComplianceLayer provide ISO 27001 certification?
No. ISO 27001 certification requires a formal audit by an accredited certification body. ComplianceLayer maps your external security posture to Annex A controls, providing documented evidence that supports the technical control requirements of your ISMS.
Which ISO 27001 Annex A controls does ComplianceLayer cover?
ComplianceLayer maps to ISO/IEC 27001:2022 Annex A controls with externally observable technical aspects, including A.5.14 (Information Transfer), A.5.15 (Access Control), A.8.8 (Management of Technical Vulnerabilities), A.8.20 (Networks Security), A.8.24 (Use of Cryptography), and A.8.26-A.8.27 (application security and secure engineering).
How does ComplianceLayer help with ISO 27001 Statement of Applicability?
The compliance scan report shows which Annex A controls appear supported, partially supported, or failing based on what is externally observable. This can support your Statement of Applicability (SoA) with documentation for the technical controls you declare as applicable. Your auditor determines whether each control is actually met.
Can ComplianceLayer be used for ISO 27001 surveillance audits?
It can help. After initial certification, ISO 27001 requires annual surveillance audits. Continuous ComplianceLayer scanning provides an ongoing record of your externally observable technical controls between formal audits.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. The free tier is here to stay.
All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.