ISO 27001 Annex A
Compliance Scanning
ISO 27001 is the international standard for information security management systems (ISMS). ComplianceLayer maps external scan findings to the specific Annex A controls covering cryptography, network security, communications security, and application security.
ISO 27001 Annex A Controls Mapped to Scan Modules
The following Annex A controls from ISO/IEC 27001:2013 are verified through external scanning. Control references follow the standard Annex A numbering.
| Control ID | Control Name | Scan Module | What We Check |
|---|---|---|---|
| A.9.1.2 | Access to Networks and Services | Open Ports | Users shall only be provided access to network services they are specifically authorized to use. Detects exposed RDP, database, and administrative ports. |
| A.9.4.1 | Information Access Restriction | Open Ports | Access to information and application system functions shall be restricted. Identifies exposed database ports (MySQL, PostgreSQL) and administrative interfaces. |
| A.10.1.1 | Policy on Cryptographic Controls | SSL/TLS | A policy on the use of cryptographic controls shall be implemented. Validates TLS versions, cipher suite strength, and HTTPS enforcement. |
| A.10.1.2 | Key Management | SSL/TLS | A policy on the use, protection, and lifetime of cryptographic keys shall be implemented. Checks certificate validity, expiration, and self-signed certificate usage. |
| A.12.2.1 | Controls Against Malware | Security Headers | Detection, prevention, and recovery controls against malware shall be implemented. Validates Content-Security-Policy for script injection prevention. |
| A.12.6.1 | Management of Technical Vulnerabilities | All Modules | Information about technical vulnerabilities shall be obtained and appropriate measures taken. ComplianceLayer scans 16 modules continuously. |
| A.13.1.1 | Network Controls | Open Ports | Networks shall be managed and controlled to protect information. Detects exposed SMB, Telnet, FTP, and other unnecessary network services. |
| A.13.2.1 | Information Transfer Policies | Formal transfer policies shall be in place. Validates SPF, DKIM, DMARC, and Referrer-Policy for secure information transfer. | |
| A.13.2.3 | Electronic Messaging | Information involved in electronic messaging shall be appropriately protected. Checks email authentication (SPF, DKIM, DMARC) configuration. | |
| A.14.1.2 | Securing Application Services | SSL/TLS / Headers | Application services on public networks shall be protected. Validates TLS configuration, HSTS enforcement, and security header presence. |
| A.14.2.5 | Secure System Engineering Principles | Security Headers | Principles for engineering secure systems shall be established. Checks CSP, X-Frame-Options, X-Content-Type-Options, and Permissions-Policy. |
ISO 27001 certification requires formal audit and organizational controls. These are ISO 27001-relevant technical controls verifiable externally. Full certification requires an accredited certification body assessment.
ISO 27001 Evidence Collection in 3 Steps
Enter your domain
Submit any domain your organization operates. ComplianceLayer scans the external surface across 16 security modules.
Review Annex A mapping
Each finding maps to specific ISO 27001 Annex A controls with pass, fail, or partial status.
Support your ISMS
Download the compliance report as evidence for your Statement of Applicability, surveillance audits, or certification preparation.
Common questions
Does ComplianceLayer provide ISO 27001 certification?
No. ISO 27001 certification requires a formal audit by an accredited certification body. ComplianceLayer maps your external security posture to Annex A controls, providing documented evidence that supports the technical control requirements of your ISMS.
Which ISO 27001 Annex A controls does ComplianceLayer cover?
ComplianceLayer maps to Annex A controls in domains A.9 (Access Control), A.10 (Cryptography), A.12 (Operations Security), A.13 (Communications Security), and A.14 (System Acquisition, Development, and Maintenance). These are the controls with externally verifiable technical aspects.
How does ComplianceLayer help with ISO 27001 Statement of Applicability?
The compliance scan report shows which Annex A controls are met, partially met, or failing based on external scanning. This directly supports your Statement of Applicability (SoA) by providing evidence for the technical controls you declare as applicable.
Can ComplianceLayer be used for ISO 27001 surveillance audits?
Yes. After initial certification, ISO 27001 requires annual surveillance audits. Continuous ComplianceLayer scanning provides an ongoing audit trail demonstrating that your technical controls remain effective between formal audits.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.