Most of ISO 27001 was never a software problem

56 of the 93 Annex A controls enforced and evidenced, and 66 of the standard's 223 clauses.

The standard has two halves. The management system, clauses 4 to 10, is scope, leadership, risk process, internal audit and management review, and it is predominantly process and judgement. The other half is Annex A, 93 controls, and that is where a platform carries the load or does not. Akku enforces and evidences 56 of them.

56/93

Annex A controls enforced and evidenced

10

Management-system clauses contributed to

66/223

Clauses of the standard in total

Where Akku sits in Annex A

Annex A divides into four themes, and Akku's weight is where you would expect it.

  • Technological23 of 34
  • Organisational25 of 37
  • Physical6 of 14
  • People2 of 8

The six in the physical theme are device and media controls: working in secure areas, clear desk and clear screen, security of assets off-premises, storage media, equipment maintenance, and secure disposal or reuse of equipment.

No other single system comes close

Of the 237 actionable requirements in the standard, 113 can be addressed by a system rather than by a person. Akku covers 67 of them. The next system on the list is a document management system at 20, and no security product on the list covers more than 2. Covering the rest means 18 separate platforms.

237

Actionable requirements in the standard

113

Addressable by a system, not only a person

67

Addressed by Akku

  • 46Addressable by another system, not Akku
  • 124Not addressable by a system — process, management decision, human judgement

Of the 46 Akku does not carry, 37 are administrative or operational rather than security-related, and 9 are genuine security requirements that need other tooling.

Compared against the next-best alternative

  • Akku67
  • Document management system20
  • Highest of any other security product2

Requirements addressable by a system, of 113.

Which module carries which clauses

Several clauses are supported by more than one module, which is why these add to 186 mapping points across 66 clauses.

ISO 27001 Annex A and management-clause mapping by Akku module
ModuleCountClauses
DLP46
UEM38
IAM35
IGA23
MDM22
PAM20

The evidence itself

Each control produces a named report rather than a screenshot taken the week before the audit. The SSO Activity Report covers A.5.15, A.5.23, A.8.4 and A.8.15. The Access Recertification Report covers A.5.16, A.5.18 and A.5.22 alongside four management-system clauses. The Audit Log Export covers ten, from A.5.28 through A.8.32. Twenty-six of Akku's reports carry ISO clause mappings, each with fixed columns and a date range you set.

  • SSO Activity ReportA.5.15, A.5.23, A.8.4, A.8.15
  • Access Recertification ReportA.5.16, A.5.18, A.5.22, and four management-system clauses
  • Audit Log Exportten clauses, from A.5.28 through A.8.32

Ask us for the full clause-level mapping against your Statement of Applicability.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.