---
title: "ISO 27001: controls supported by Noraina"
description: "Which ISO 27001 controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/iso-27001/
language: en
---
# ISO 27001: controls supported by Noraina

Any organisation that needs to show customers a certified security management system.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## ISO/IEC 27001:2022

International standard for information security management systems. References are Annex A control numbers.

15 controls supported.

### Efficient Cloud Instances with replication

- Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities)
- How we help: Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives.
- Evidence you get: Architecture and RPO/RTO statement, replication health reports, signed records of failover tests.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 8.13 (Information backup); 8.24 (Use of cryptography); 5.33 (Protection of records)
- How we help: Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials.
- Evidence you get: Backup policy settings, Object Lock retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities)
- How we help: Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure.
- Evidence you get: NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: 8.15 (Logging); 8.16 (Monitoring activities)
- How we help: Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define.
- Evidence you get: Logpush job inventory, retention settings, example investigation queries.
- Status: Mapping under review

### Application and DDoS protection

- Control: 8.20 (Network security); 8.26 (Application security requirements)
- How we help: WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application.
- Evidence you get: Security configuration export, monthly threat reports, change history.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 5.15 (Access control rules); 8.5 (Secure authentication); 8.12 (Data leakage prevention); 8.22 (Segregation of networks); 8.23 (Web filtering)
- How we help: Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools.
- Evidence you get: Access policy export, DLP profiles and incidents, Gateway policy export, access logs.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/iso-27001/#assessment
