Skip to content

Compliance

ISO 27001: evidencing Annex A controls continuously

Auditors want to see that controls work. blacklens.io generates the evidence for vulnerabilities, inventory, threats and suppliers, continuously and with history.

Evidence for Annex Aas PDF
Asset inventoryISO/IEC 27001 A.5.9continuous
Threat Center matchingISO/IEC 27001 A.5.7real time
Supplier watchlistISO/IEC 27001 A.5.22about every 30 min
Vulnerability reportISO/IEC 27001 A.8.8monthly

What ISO 27001 requires in the audit

ISO/IEC 27001:2022 requires an ISMS whose controls demonstrably work, and not only on the day of the audit.

Annex A

93 controls in four themes

Organisational, people, physical, technological. Your statement of applicability selects.

Clause 9.1

Monitor and measure

The effectiveness of the ISMS is monitored, measured and evaluated on an ongoing basis.

Clause 9.3

Management review

Top management reviews the ISMS at planned intervals, including trends.

Certification

Data instead of descriptions

Auditors ask, for example, which vulnerabilities you detected, assessed and fixed in three months.

Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.

Controls for which blacklens.io provides evidence

The mapping follows Annex A of the 2022 edition. Which controls apply to you is defined in your statement of applicability.

A.8.8

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Visuals show sample data.

Audit evidence that blacklens.io generates

Executive, vulnerability, pentest, query and insights reports go out by email daily, weekly or monthly, so the evidence is complete at audit time.

Reportsscheduled by email
PDFExecutive reportWeekly, Monday 07:00
PDFVulnerability reportMonthly
PDFPentest reportAfter every test
Management, head of IT
  • Activity log

    Who opened, commented on, risk-accepted or closed which finding, and when.

  • Finding history

    Closed findings are archived after 30 days rather than deleted.

  • Trends for clause 9

    Nightly snapshots and exposure score for measurement and management review.

  • Exports and API

    CSV and PDF from any list, REST API for your ISMS or GRC tool.

Audit preparation in four steps

  1. 1

    Map controls

    Map applicable controls from your statement of applicability to the matching evidence.

  2. 2

    Connect the scope

    Add domains and cloud accounts, roll out Sentry for the internal network.

  3. 3

    Schedule reports

    Send vulnerability and executive reports monthly to the ISMS owners.

  4. 4

    Link the evidence

    Attach reports and exports to the respective control in your ISMS tool.

Example from practice

Logistics provider evidences A.8.8 across subsidiaries

A Europe-wide logistics provider had to collect vulnerabilities from networks, cloud accounts and subsidiaries centrally. blacklens.io built a complete inventory and detected newly exposed systems between scheduled scans.

  • Result

    Reduced attack surface, clear responsibilities and auditable implementation in line with ISO 27001.

Progresslast 90 days
Critical findings143
Exposed services3821

Visuals show sample data.

Frequently asked questions

ISO/IEC 27001 is the international standard for information security management systems (ISMS). The 2022 edition groups the measures in Annex A into 93 controls across four themes: organisational, people, physical and technological. For certification, an organisation shows that the applicable controls are implemented and effective, not only on the day of the audit. blacklens.io is not an ISMS tool and does not replace a risk assessment; the platform is the technical source of evidence.

Evidence for Annex A, generated continuously

See in a demo which reports and logs your auditor receives. Or start with your domains.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings