Skip to main content
Threatstealth
Login
// ISO.27001.2022

Operate your ISMS, don't just document it

Risk register, SoA, Annex A controls, internal audits, and continuous evidence — wired to live signals from your environment instead of dead documents in a SharePoint folder.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is ISO compliance automation?

ISO 27001 compliance is the operation of an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022 — risk-driven, continuously improved, and evidenced. Threatstealth runs the ISMS as code: risk register linked to assets, Statement of Applicability mapped to all 93 Annex A controls, internal audit cadence, management reviews, and continuous evidence collection — all inside one console.

// THE.PROBLEM

Why ISO 27001 programs become document graveyards

  • ISMS lives in a Confluence space nobody opens between certifications
  • Risk register is a spreadsheet that's stale within a quarter
  • Statement of Applicability falls out of sync with what's actually implemented
  • Internal audit becomes a fire-drill the month before recert
// HOW.IT.WORKS

A four-step operational model

1

Asset + risk register

Auto-discovered assets fed from the rest of the platform (endpoints, repos, vendors, data stores) form a live asset inventory feeding the risk register.

  • Auto-discovered assets
  • Risk treatment plans
  • Owner + review cadence
2

Annex A controls + SoA

All 93 Annex A:2022 controls with implementation status, justification for exclusions, and live evidence — generating the Statement of Applicability automatically.

  • 93 Annex A:2022 controls
  • Auto-generated SoA
  • Inclusion/exclusion rationale
3

Internal audit cycle

Schedule, plan, execute, and close internal audits inside the platform. Findings link to risk treatments and evidence.

  • Audit plan + program
  • Findings → treatments
  • Management review prep
4

Continuous evidence

Same engine as SOC 2 and PCI — evidence collected hourly, tamper-evident, exportable to certification bodies.

  • Hourly evidence runs
  • Cert-body export
  • Multi-framework reuse
93
Annex A:2022 controls
Auto
Statement of Applicability
Live
Risk register
Multi-framework
Evidence reuse
// WHY.IT.MATTERS

Outcomes for security teams

Live ISMS, not document theatre

Controls reflect what's actually running. Auditors verify, they don't excavate.

Reuse evidence across SOC 2, HIPAA, NIST

One evidence collection effort feeds every framework you're aligned to. Get certified faster, recertify cheaper.

Audit-trail-grade history

Every change to the SoA, risk register, or control implementation is timestamped and attributed — exactly what 27001:2022 expects.

// FAQ

Direct answers

Does it support ISO 27001:2022 or only the older 2013 standard?+

ISO 27001:2022 with all 93 Annex A controls and the new control attributes (preventive/detective/corrective, confidentiality/integrity/availability).

Can it generate the Statement of Applicability?+

Yes. The SoA is generated from your control implementation status with auto-filled justifications for inclusions and exclusions.

Does it support internal audits?+

Yes — full audit lifecycle: plan, scope, execute, findings, corrective actions, follow-up, and management review prep.

Will my certification body accept the evidence?+

Yes. Evidence is exported as a structured bundle aligned to standard cert-body fieldwork. We've worked with BSI, Schellman, and A-LIGN auditors.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.