ISO 27001SecurityGlobalAll Industries

ISO/IEC 27001 Information Security Management

International standard for information security management systems (ISMS). Certification demonstrates commitment to security and is often required for international business.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

ISO 27001A.12.4.1A record of access

Event Logging

Event logs recording user activities, exceptions, faults and information security events MUST be produced, kept and regularly reviewed.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

ISO 27001A.12.4.3Least privilege and privileged useAttribution to an individual

Administrator Logs

System administrator and operator activities MUST be logged and the logs protected and regularly reviewed.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

ISO 27001A.9.2.1Least privilege and privileged use

User Registration

Formal user registration and de-registration process MUST be implemented to enable assignment of access rights.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

ISO 27001A.16.1.2Routing and evidencing the response

Reporting Security Events

Information security events MUST be reported through appropriate management channels as quickly as possible.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

What ISO 27001 covers

This instrument defines no data category of its own. Scope is whatever the organisation puts inside its ISMS boundary and its own asset inventory under A.5.9. The standard governs the management system, not a category of data.

How ISO 27001 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Your accredited certification body, at surveillance and recertification audits.

A voluntary standard. No regulator enforces it.

Certification is a contract with a certification body, not a legal obligation. A major nonconformity that is not closed within the agreed window suspends the certificate and can lead to withdrawal, which is visible to every customer who asked for it in the first place.

Several instruments elsewhere in this list treat an ISO 27001 certificate as evidence of appropriate technical measures, so losing it can weaken a defence under those.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for ISO 27001,
not configured for it afterwards

Policy Template

A.12.4 Logging Policy

Complete implementation of ISO 27001 logging controls

Report

ISMS Audit Report

Evidence package for ISO 27001 certification audits

Dashboard

Security Event Review

Regular review interface for A.12.4.1 compliance

Alert

Privileged User Monitoring

A.12.4.3 compliant administrator activity tracking

Walk into the ISO 27001 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment