Compliance
ISO 27001: evidencing Annex A controls continuously
Auditors want to see that controls work. blacklens.io generates the evidence for vulnerabilities, inventory, threats and suppliers, continuously and with history.
What ISO 27001 requires in the audit
ISO/IEC 27001:2022 requires an ISMS whose controls demonstrably work, and not only on the day of the audit.
93 controls in four themes
Organisational, people, physical, technological. Your statement of applicability selects.
Monitor and measure
The effectiveness of the ISMS is monitored, measured and evaluated on an ongoing basis.
Management review
Top management reviews the ISMS at planned intervals, including trends.
Data instead of descriptions
Auditors ask, for example, which vulnerabilities you detected, assessed and fixed in three months.
Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.
Controls for which blacklens.io provides evidence
The mapping follows Annex A of the 2022 edition. Which controls apply to you is defined in your statement of applicability.
A.8.8
A.5.9
A.5.7
- CVE published08:12
- 2 assets in your inventory affected09:00
- Confirmed by PoC scan09:26
- Alert sent to Microsoft Teams09:27
A.5.19 to A.5.22
A.5.23 and A.8.9
Visuals show sample data.
Audit evidence that blacklens.io generates
Executive, vulnerability, pentest, query and insights reports go out by email daily, weekly or monthly, so the evidence is complete at audit time.
Activity log
Who opened, commented on, risk-accepted or closed which finding, and when.
Finding history
Closed findings are archived after 30 days rather than deleted.
Trends for clause 9
Nightly snapshots and exposure score for measurement and management review.
Exports and API
CSV and PDF from any list, REST API for your ISMS or GRC tool.
Audit preparation in four steps
- 1
Map controls
Map applicable controls from your statement of applicability to the matching evidence.
- 2
Connect the scope
Add domains and cloud accounts, roll out Sentry for the internal network.
- 3
Schedule reports
Send vulnerability and executive reports monthly to the ISMS owners.
- 4
Link the evidence
Attach reports and exports to the respective control in your ISMS tool.
Example from practice
Logistics provider evidences A.8.8 across subsidiaries
A Europe-wide logistics provider had to collect vulnerabilities from networks, cloud accounts and subsidiaries centrally. blacklens.io built a complete inventory and detected newly exposed systems between scheduled scans.
Result
Reduced attack surface, clear responsibilities and auditable implementation in line with ISO 27001.
Visuals show sample data.
Frequently asked questions
- ISO/IEC 27001 is the international standard for information security management systems (ISMS). The 2022 edition groups the measures in Annex A into 93 controls across four themes: organisational, people, physical and technological. For certification, an organisation shows that the applicable controls are implemented and effective, not only on the day of the audit. blacklens.io is not an ISMS tool and does not replace a risk assessment; the platform is the technical source of evidence.
Evidence for Annex A, generated continuously
See in a demo which reports and logs your auditor receives. Or start with your domains.
- 14 days free, all features
- No credit card required
- We walk you through your first findings