Operate your ISMS, don't just document it
Risk register, SoA, Annex A controls, internal audits, and continuous evidence — wired to live signals from your environment instead of dead documents in a SharePoint folder.
What is ISO compliance automation?
ISO 27001 compliance is the operation of an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022 — risk-driven, continuously improved, and evidenced. Threatstealth runs the ISMS as code: risk register linked to assets, Statement of Applicability mapped to all 93 Annex A controls, internal audit cadence, management reviews, and continuous evidence collection — all inside one console.
Why ISO 27001 programs become document graveyards
- ISMS lives in a Confluence space nobody opens between certifications
- Risk register is a spreadsheet that's stale within a quarter
- Statement of Applicability falls out of sync with what's actually implemented
- Internal audit becomes a fire-drill the month before recert
A four-step operational model
Asset + risk register
Auto-discovered assets fed from the rest of the platform (endpoints, repos, vendors, data stores) form a live asset inventory feeding the risk register.
- Auto-discovered assets
- Risk treatment plans
- Owner + review cadence
Annex A controls + SoA
All 93 Annex A:2022 controls with implementation status, justification for exclusions, and live evidence — generating the Statement of Applicability automatically.
- 93 Annex A:2022 controls
- Auto-generated SoA
- Inclusion/exclusion rationale
Internal audit cycle
Schedule, plan, execute, and close internal audits inside the platform. Findings link to risk treatments and evidence.
- Audit plan + program
- Findings → treatments
- Management review prep
Continuous evidence
Same engine as SOC 2 and PCI — evidence collected hourly, tamper-evident, exportable to certification bodies.
- Hourly evidence runs
- Cert-body export
- Multi-framework reuse
Outcomes for security teams
Live ISMS, not document theatre
Controls reflect what's actually running. Auditors verify, they don't excavate.
Reuse evidence across SOC 2, HIPAA, NIST
One evidence collection effort feeds every framework you're aligned to. Get certified faster, recertify cheaper.
Audit-trail-grade history
Every change to the SoA, risk register, or control implementation is timestamped and attributed — exactly what 27001:2022 expects.
Direct answers
Does it support ISO 27001:2022 or only the older 2013 standard?+
ISO 27001:2022 with all 93 Annex A controls and the new control attributes (preventive/detective/corrective, confidentiality/integrity/availability).
Can it generate the Statement of Applicability?+
Yes. The SoA is generated from your control implementation status with auto-filled justifications for inclusions and exclusions.
Does it support internal audits?+
Yes — full audit lifecycle: plan, scope, execute, findings, corrective actions, follow-up, and management review prep.
Will my certification body accept the evidence?+
Yes. Evidence is exported as a structured bundle aligned to standard cert-body fieldwork. We've worked with BSI, Schellman, and A-LIGN auditors.
