Skip to content

ISO/IEC 27001:2022 — SnowOps Control Mapping

Framework: ISO/IEC 27001:2022 (Annex A controls) Predecessor: ISO 27001:2013 (clause numbering changed in 2022 edition) Certification body: Client-selected accredited CAB (certification audit body) SnowOps package: Advanced "Certification-Ready" [A] (Baseline [B] covers A.8, A.12, A.13 foundation)

Coverage Legend

Symbol Meaning
Automated — SnowOps asset provides automated implementation + evidence
🔧 Partial — Asset exists; supplemental manual steps or documentation required
📋 Manual — ISMS documentation, procedure, or management activity
Roadmap — Planned in M4
Out of scope — Azure platform, physical controls, or external responsibility

Clause 4–10 (ISMS Management Clauses)

These clauses govern the management system itself — they cannot be automated but SnowOps produces evidence that satisfies their intent.

Clause Requirement Coverage Notes
4.1 Understanding the organization and its context 📋 Manual Discovery Audit Suite (G0G7) discovery maps the technical context
4.2 Understanding needs of interested parties 📋 Manual Stakeholder register; management activity
4.3 ISMS scope definition 📋 Manual Formally document which systems are in scope
5.1 Leadership commitment 📋 Manual Management sign-off; policy approval
5.2 Information security policy 🔧 Partial compliance/policies/ placeholder; V-series (M4, Policy Repo Template (V1))
5.3 Roles and responsibilities Entra ID Baseline Module (H1)/Conditional Access Module (H2)/Entra PIM Templates Module (H3): documented RBAC in code
6.1 Risk assessment Discovery Audit Suite (G0G7) produces scored posture with severity + framework tags
6.1.3 Statement of Applicability (SoA) 📋 Manual Use this control-mapping doc as the technical input; formal SoA is a management document
6.2 Information security objectives 📋 Manual Reference Discovery Audit Suite (G0G7) findings; targets set by management
7.5 Documented information 🔧 Partial Runbook Generator (V3) (runbook generator); Module Registry & Versioning (F11) (module versioning)
8.2 Information security risk assessment Discovery Audit Suite (G0G7); Drift Detector (S1) drift detection for ongoing assessment
8.3 Information security risk treatment 🔧 Partial F-modules implement treatment; risk treatment plan is manual
9.1 Monitoring, measurement, analysis, evaluation Compliance Dashboard (S2) compliance dashboard; Compliance Snapshot Collector (E0) snapshots; Automated Restore Drill (L4) drill reports
9.2 Internal audit 📋 Manual Annual audit program; auditor reviews SnowOps evidence
9.3 Management review 📋 Manual Periodic review meetings using Compliance Dashboard (S2) dashboard as input
10.1 Nonconformity and corrective action Drift Detector (S1) tickets per drift finding; Policy Waiver Engine (D5) waivers with expiry

Annex A Controls (ISO 27001:2022)

A.5 — Organizational Controls

Control Description Coverage Asset Evidence
A.5.1 Policies for information security 🔧 Partial Draft policies in compliance/policies/; V-series (M4, Policy Repo Template (V1))
A.5.2 Information security roles and responsibilities Entra ID Baseline Module (H1)/Conditional Access Module (H2)/Entra PIM Templates Module (H3) RBAC assignments in Terraform state
A.5.3 Segregation of duties Azure Resource PIM Module (B5), Conditional Access Module (H2) PIM eligible roles; custom role definitions
A.5.5 Contact with authorities 📋 Manual IR runbook includes authority contacts (Incident Response Runbooks K1)
A.5.7 Threat intelligence Subscription Baseline Module (B3) (Defender) Defender for Cloud threat signals
A.5.8 Information security in project management 🔧 Partial PR Quality-Gate Workflow (D2), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) Security gates in CI/CD pipeline; checklist item for project plans
A.5.9 Inventory of information and assets Discovery Audit Suite (G0G7), Module Registry & Versioning (F11) Discovery audit asset list; module registry
A.5.10 Acceptable use of information 📋 Manual AUP policy document
A.5.11 Return of assets 📋 Manual Offboarding checklist; Entra ID Baseline Module (H1) user lifecycle
A.5.12 Classification of information 📋 Manual Data classification policy; not an IaC control
A.5.13 Labelling of information 🔧 Partial Tag Policy Module (U2) Required-tags deny policy enforces tag presence
A.5.14 Information transfer 🔧 Partial TLS Policy Module (M3), Private Endpoint Policy Module (N5) TLS deny policy; public-access deny; DLP not in scope
A.5.15 Access control Azure Baseline Module (F1), Entra ID Baseline Module (H1)–Entra PIM Templates Module (H3), Azure Resource PIM Module (B5), Break-Glass Account Module (H7) Identity module outputs; RBAC; PIM; break-glass
A.5.16 Identity management Azure Baseline Module (F1), Entra ID Baseline Module (H1) Entra ID module; group-based access provisioning
A.5.17 Authentication information Break-Glass Account Module (H7), Pre-Commit Quality Hooks (D1) Break-glass + FIDO2; branch protection (no password push)
A.5.18 Access rights Conditional Access Module (H2), Azure Resource PIM Module (B5) Role assignments; PIM eligibility records
A.5.19 Information security in supplier relationships ⏳ Roadmap P-series (M4) Vendor risk questionnaires
A.5.20 Addressing security within supplier agreements 📋 Manual Contract clauses; legal instrument
A.5.21 Managing security in ICT supply chain Container Build & Sign Pipeline (C2) (Grype, Syft), Kyverno AKS Policy Bundle (D4) SBOM + CVE scan artifacts; signed images
A.5.22 Monitoring, review of supplier services ⏳ Roadmap P-series (M4) Periodic vendor review tracking
A.5.23 Information security for cloud services Subscription Baseline Module (B3), Compliance Snapshot Collector (E0), Compliance Dashboard (S2) MCSB; Defender score; compliance snapshot
A.5.24 Information security incident management planning Incident Response Runbooks (K1), On-Call Integration Module (K2) IR runbook library; on-call integration
A.5.25 Assessment and decision on information security events Incident Response Runbooks (K1) IR runbook triage steps
A.5.26 Response to information security incidents Incident Response Runbooks (K1), On-Call Integration Module (K2) Response runbooks; on-call escalation
A.5.27 Learning from incidents 🔧 Partial Incident Response Runbooks (K1) Post-incident review section in IR runbook
A.5.28 Collection of evidence Audit Log Archive Module (J6), Compliance Snapshot Collector (E0) WORM immutable logs; compliance snapshots
A.5.29 Information security during disruption Azure Backup Policy Module (L1), Cross-Region Replication Module (L2), Automated Restore Drill (L4) Backup policies; cross-region replication; restore drill
A.5.30 ICT readiness for business continuity Automated Restore Drill (L4) Restore drill report with measured RTO
A.5.33 Protection of records Audit Log Archive Module (J6), Azure Backup Policy Module (L1) WORM blob; backup retention policy
A.5.34 Privacy and protection of PII 🔧 Partial Data Residency Policy Module (M6), Entra ID Baseline Module (H1)/Conditional Access Module (H2) Region deny policy; access control
A.5.36 Compliance with policies Terraform OPA Policy Bundle (D3)/Conftest Test Suite (X3), PR Quality-Gate Workflow (D2) OPA policy gate; quality gates CI
A.5.37 Documented operating procedures Runbook Generator (V3), Incident Response Runbooks (K1) Runbook generator; IR runbook library

A.6 — People Controls

Control Description Coverage Asset Evidence
A.6.1 Screening (background checks) ⏳ Roadmap Q-series (M4) Tracking only; checks are manual
A.6.2 Terms and conditions of employment 📋 Manual Employment contract; HR process
A.6.3 Information security awareness, education, training ⏳ Roadmap Q-series (M4) Training completion tracking
A.6.4 Disciplinary process 📋 Manual HR process
A.6.5 Responsibilities after termination 🔧 Partial Entra ID Baseline Module (H1) (user lifecycle) Entra group removal on offboarding
A.6.6 Confidentiality or NDA 📋 Manual Legal document
A.6.7 Remote working Private Endpoint Policy Module (N5), TLS Policy Module (M3) Network + TLS policies apply equally to remote
A.6.8 Information security event reporting Incident Response Runbooks (K1), On-Call Integration Module (K2) Incident reporting runbook; on-call escalation

A.7 — Physical Controls

All A.7 physical controls apply to offices and on-premises equipment — not applicable to Azure cloud IaC. Azure's physical security is inherited from Microsoft's ISO 27001 certification.

Control Coverage Notes
A.7.1–A.7.14 ❌ Azure platform / office Client responsible for office physical controls; Azure data centre controls inherited

A.8 — Technological Controls

Control Description Coverage Asset Evidence
A.8.1 User endpoint devices 🔧 Partial PR Quality-Gate Workflow (D2) (gitleaks) Secret scan on developer machines via pre-commit (D2)
A.8.2 Privileged access rights Azure Resource PIM Module (B5), Entra PIM Templates Module (H3), Break-Glass Account Module (H7) PIM eligible assignments; activation policy; break-glass
A.8.3 Information access restriction Conditional Access Module (H2), Private Endpoint Policy Module (N5) RBAC custom roles; public-access deny
A.8.4 Access to source code Pre-Commit Quality Hooks (D1), GitOps Branching Standard (C4) Branch protection; CODEOWNER review gates
A.8.5 Secure authentication Break-Glass Account Module (H7), Azure Baseline Module (F1) Break-glass FIDO2; OIDC federation (no passwords)
A.8.6 Capacity management Budget Alert Module (U1), Log Analytics Module (J1) Budget alerts; LAW metrics queries
A.8.7 Protection against malware Subscription Baseline Module (B3), Kyverno AKS Policy Bundle (D4), Container Build & Sign Pipeline (C2) Defender for Cloud; Kyverno signed-image admission
A.8.8 Management of technical vulnerabilities PR Quality-Gate Workflow (D2) (trivy/tfsec/checkov), Container Build & Sign Pipeline (C2) (Grype) CVE scan artifacts in CI
A.8.9 Configuration management All F/B modules Terraform-managed configuration; no manual changes
A.8.10 Information deletion 🔧 Partial Azure Backup Policy Module (L1) (retention) Backup retention policy; manual deletion policy needed
A.8.11 Data masking 📋 Manual Application-layer control; not IaC
A.8.12 Data leakage prevention 🔧 Partial PR Quality-Gate Workflow (D2) (gitleaks) Secret scanning; full DLP not in scope
A.8.13 Information backup Azure Backup Policy Module (L1) Azure Backup policy module; multi-tier retention
A.8.14 Redundancy of information processing Cross-Region Replication Module (L2), Automated Restore Drill (L4) Cross-region replication; restore drill proof
A.8.15 Logging Log Analytics Module (J1), Policy Diagnostics Module (J2), Audit Log Archive Module (J6) Log Analytics workspace; diagnostic settings; WORM
A.8.16 Monitoring activities Drift Detector (S1), Compliance Dashboard (S2), Subscription Baseline Module (B3) Drift detection; compliance dashboard; Defender
A.8.17 Clock synchronization Azure platform Azure enforces NTP; not configurable via IaC
A.8.18 Use of privileged utility programs Azure Resource PIM Module (B5) (PIM), Break-Glass Account Module (H7) Time-boxed privileged access; break-glass audit log
A.8.19 Installation of software on operational systems Kyverno AKS Policy Bundle (D4) (Kyverno), Container Build & Sign Pipeline (C2) Signed-image admission; SBOM tracking
A.8.20 Networks security Network Hub Module (F2), Private Endpoint Policy Module (N5), NSG Baseline Module (N6) VNet isolation; NSG; public-access deny
A.8.21 Security of network services Network Hub Module (F2), TLS Policy Module (M3) Private endpoints; TLS deny policy
A.8.22 Segregation of networks Network Hub Module (F2), Secure AKS Module (F3) Spoke VNet per workload; AKS with Azure CNI Overlay
A.8.23 Web filtering ❌ Application layer Not an IaC control
A.8.24 Use of cryptography Encryption Policy Module (M1), Customer-Managed Key Module (M2), Key Vault Module (F5) Encryption deny policy; CMK; Key Vault
A.8.25 Secure development lifecycle Pre-Commit Quality Hooks (D1), PR Quality-Gate Workflow (D2), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) Branch protection; quality gates; signed delivery
A.8.26 Application security requirements 🔧 Partial Terraform OPA Policy Bundle (D3)/Conftest Test Suite (X3), PR Quality-Gate Workflow (D2) OPA policy; checkov; application-layer controls are client's
A.8.27 Secure system architecture and engineering Cloud-Agnostic Module Contracts (F0) (contracts), B-modules Cloud-agnostic contracts; opinionated composition modules
A.8.28 Secure coding 🔧 Partial PR Quality-Gate Workflow (D2) (CodeQL via GHA) SAST; language-specific secure-coding practices are client's
A.8.29 Security testing in development and acceptance Terratest Harness (X2) (Terratest), PR Quality-Gate Workflow (D2) IaC tests; quality gates gate every PR
A.8.30 Outsourced development 📋 Manual Supplier management (P-series, M4)
A.8.31 Separation of development, test, production Azure Sandbox Subscription (X1), Terraform Plan/Apply Pipeline (C1) (environments) Dedicated sandbox sub; GitHub/ADO environment gates
A.8.32 Change management Pre-Commit Quality Hooks (D1), GitOps Branching Standard (C4), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) PR + CI + CODEOWNER → merge gate
A.8.33 Test information Azure Sandbox Subscription (X1), Terratest Harness (X2) Sandbox subscription; Terratest fixtures (no prod data)
A.8.34 Protection of information systems during audit Pre-Commit Quality Hooks (D1), Azure Resource PIM Module (B5) Read-only audit accounts via PIM; branch protection

What SnowOps Does NOT Automate (Manual Requirements for Certification)

These items are required for ISO 27001:2022 certification but are outside SnowOps automation scope. What to do about each:

Requirement Who What the manual step is Notes
ISMS scope document Client Write a formal document naming the boundaries of the Information Security Management System — which business units, locations, systems, and services are in/out of scope, and why This is the foundational management artefact every other ISO 27001 document references; SnowOps' technical scope (the F/B/H platform) can inform it but the org-wide boundary decision is the client's
Statement of Applicability (SoA) Client For each of the 93 Annex A controls, state whether it's applicable, justify the inclusion/exclusion, and reference the implementing control/asset (use this mapping doc as the technical input column) The SoA itself — the signed-off management artefact mapping controls to justifications — must be authored and owned by the client's ISMS lead
Risk treatment plan Client Stand up a risk register seeded from Discovery Audit Suite (G0G7) findings; assign owners, likelihood/impact scores, and treatment decisions (accept/mitigate/transfer/avoid), and review on a fixed cadence The G-series report supplies severity-scored, framework-tagged findings as raw input; converting that into a formal, management-reviewed treatment plan with documented decisions is a governance responsibility
Internal audit programme Client Define an annual internal-audit schedule, ensure auditor independence (someone who didn't implement the control performs the audit), and track findings to closure Compliance Dashboard (S2) and Compliance Snapshot Collector (E0) evidence streams give the auditor source data, but the audit programme, scheduling, and independence requirement are organizational
Management review meetings (9.3) Client Hold periodic (quarterly recommended) management-review meetings covering ISMS performance, audit results, risk status, and improvement opportunities, and minute the decisions Use the Compliance Dashboard (S2) dashboard as the review input; the meeting itself, attendance, and documented decisions must be run by the client's leadership
Corrective action tracking (10.1) Client (🔧 partially tooled) Maintain a formal CAPA (corrective and preventive action) register: log each nonconformity, root-cause it, assign a fix and an owner, and verify closure Drift Detector (S1) opens an issue per drift finding automatically; turning that issue stream into an auditable CAPA register with root-cause analysis is manual today — Policy Repo Template (V1, M4) will formalize the workflow
Information security policies (A.5.1) Client Draft each required policy (InfoSec, access control, cryptography, supplier, incident response, etc.) as a markdown doc with purpose/scope/statements/roles/review-cadence/approval log, and commit it to compliance/policies/ per the Policy Library Guide Policy Repo Template (V1, M4) will add a markdown library + amendment workflow + acknowledgment sync; until then the git history of compliance/policies/ is the audit trail — Q-series and P-series (M4) cover the adjacent HR/vendor policy tracking
Background checks / screening (A.6.1) Client Run pre-employment background checks through a vetted screening vendor before each hire's start date, and retain the results on file HR Security & Training (Q1Q5, M4) will automate tracking of completion/expiry via tickets; the checks themselves and the hire/no-hire decision are inherently human, HR-owned steps
Security awareness training (A.6.3) Client Stand up (or use an existing) training platform, assign annual security-awareness plus role-specific training, and retain completion certificates as evidence HR Security & Training (Q1Q5, M4) will automate enrollment/completion tracking and reminders; delivering and recording the training stays client-owned even after M4 ships
Physical security controls (A.7) Client For client-controlled premises: implement badge access, visitor logs, CCTV, clean-desk policy, and equipment-disposal procedures, and document them in a physical-security policy Azure datacentre physical security is inherited from Microsoft's own ISO 27001 certification (see the Compliance Engagement Guide for the shared-responsibility framing); office/equipment controls are the client's to implement and document
Vendor contracts with security clauses (A.5.20) Client Build a vendor register (name, service, data accessed, risk tier), collect SOC 2/ISO reports or completed security questionnaires from critical vendors, and have legal counsel execute contracts/DPAs containing security clauses Vendor & Third-Party Risk (P1P4, M4) will automate the register and review-tracker; the due-diligence judgment calls and contract execution through legal counsel remain manual — see the Policy Library Guide vendor-management-policy.md row
Certification body engagement Client Select and contract an accredited Certification Body (CAB) and schedule the two-stage external audit (Stage 1 documentation review, Stage 2 implementation audit) See the Compliance Engagement Guide §3 ISO 27001 — "Auditor" note for sequencing and lead-time guidance
Surveillance audits (annual) Client Budget for and schedule annual surveillance audits with the CAB to maintain certification between the 3-year recertification cycles Ongoing commitment after initial certification; Compliance Snapshot Collector (E0) evidence accumulation continues to reduce the audit-prep burden each cycle