Framework
ISO/IEC 27001:2022
Information security management system (ISMS) certification — covers 93 Annex A controls across four themes.
Owner: Compliance TeamLast reviewed: 2026-04-14
Scope in OneComply
/dashboard/iso27001— ISMS overview./dashboard/iso27001/soa— Statement of Applicability generator./dashboard/iso27001/internal-audit— internal audit programme./dashboard/risk-register— ISO 27005-aligned risk methodology.
Typical Workflow
- Define ISMS scope — business units, locations, information systems.
- Adopt the risk methodology (likelihood × impact, appetite thresholds).
- Run risk assessment → risk treatment plan → Statement of Applicability.
- Implement controls; evidence each one via the Evidence module.
- Execute internal audit; record non-conformities and remediation.
- Management review → certification / surveillance audit package export.
Cross-Mapping
The Controls library tags each ISO 27001 Annex A entry against DORA, NIS2, and GDPR where the requirement overlaps, so one evidence artifact can close multiple gaps.
Continue reading