ISO/IEC 27001:2022
International standard for information security management systems. Any organisation that needs to show customers a certified security management system.
15 controls supported. References are Annex A control numbers.
Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.
Mapping under review
- Control
- 5.29Security during disruption
- 5.30ICT readiness for business continuity
- 8.14Redundancy of processing facilities
- How we help
- Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives.
- Evidence you get
- Architecture and RPO/RTO statement, replication health reports, signed records of failover tests.
Mapping under review
- Control
- 8.13Information backup
- 8.24Use of cryptography
- 5.33Protection of records
- How we help
- Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials.
- Evidence you get
- Backup policy settings, Object Lock retention configuration, restore test records.
Mapping under review
- Control
- 5.29Security during disruption
- 5.30ICT readiness for business continuity
- 8.14Redundancy of processing facilities
- How we help
- Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure.
- Evidence you get
- NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history.
Mapping under review
- Control
- 8.15Logging
- 8.16Monitoring activities
- How we help
- Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define.
- Evidence you get
- Logpush job inventory, retention settings, example investigation queries.
Mapping under review
- Control
- 8.20Network security
- 8.26Application security requirements
- How we help
- WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application.
- Evidence you get
- Security configuration export, monthly threat reports, change history.
Mapping under review
- Control
- 5.15Access control rules
- 8.5Secure authentication
- 8.12Data leakage prevention
- 8.22Segregation of networks
- 8.23Web filtering
- How we help
- Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools.
- Evidence you get
- Access policy export, DLP profiles and incidents, Gateway policy export, access logs.
Tell us what you are preparing for
We reply with the controls we can cover, what stays on your side, and a realistic timeline.