ISO/IEC 27001:2022 — SnowOps Control Mapping¶
Framework: ISO/IEC 27001:2022 (Annex A controls) Predecessor: ISO 27001:2013 (clause numbering changed in 2022 edition) Certification body: Client-selected accredited CAB (certification audit body) SnowOps package: Advanced "Certification-Ready" [A] (Baseline [B] covers A.8, A.12, A.13 foundation)
Coverage Legend¶
| Symbol | Meaning |
|---|---|
| ✅ | Automated — SnowOps asset provides automated implementation + evidence |
| 🔧 | Partial — Asset exists; supplemental manual steps or documentation required |
| 📋 | Manual — ISMS documentation, procedure, or management activity |
| ⏳ | Roadmap — Planned in M4 |
| ❌ | Out of scope — Azure platform, physical controls, or external responsibility |
Clause 4–10 (ISMS Management Clauses)¶
These clauses govern the management system itself — they cannot be automated but SnowOps produces evidence that satisfies their intent.
| Clause | Requirement | Coverage | Notes |
|---|---|---|---|
| 4.1 | Understanding the organization and its context | 📋 Manual | Discovery Audit Suite (G0–G7) discovery maps the technical context |
| 4.2 | Understanding needs of interested parties | 📋 Manual | Stakeholder register; management activity |
| 4.3 | ISMS scope definition | 📋 Manual | Formally document which systems are in scope |
| 5.1 | Leadership commitment | 📋 Manual | Management sign-off; policy approval |
| 5.2 | Information security policy | 🔧 Partial | compliance/policies/ placeholder; V-series (M4, Policy Repo Template (V1)) |
| 5.3 | Roles and responsibilities | ✅ | Entra ID Baseline Module (H1)/Conditional Access Module (H2)/Entra PIM Templates Module (H3): documented RBAC in code |
| 6.1 | Risk assessment | ✅ | Discovery Audit Suite (G0–G7) produces scored posture with severity + framework tags |
| 6.1.3 | Statement of Applicability (SoA) | 📋 Manual | Use this control-mapping doc as the technical input; formal SoA is a management document |
| 6.2 | Information security objectives | 📋 Manual | Reference Discovery Audit Suite (G0–G7) findings; targets set by management |
| 7.5 | Documented information | 🔧 Partial | Runbook Generator (V3) (runbook generator); Module Registry & Versioning (F11) (module versioning) |
| 8.2 | Information security risk assessment | ✅ | Discovery Audit Suite (G0–G7); Drift Detector (S1) drift detection for ongoing assessment |
| 8.3 | Information security risk treatment | 🔧 Partial | F-modules implement treatment; risk treatment plan is manual |
| 9.1 | Monitoring, measurement, analysis, evaluation | ✅ | Compliance Dashboard (S2) compliance dashboard; Compliance Snapshot Collector (E0) snapshots; Automated Restore Drill (L4) drill reports |
| 9.2 | Internal audit | 📋 Manual | Annual audit program; auditor reviews SnowOps evidence |
| 9.3 | Management review | 📋 Manual | Periodic review meetings using Compliance Dashboard (S2) dashboard as input |
| 10.1 | Nonconformity and corrective action | ✅ | Drift Detector (S1) tickets per drift finding; Policy Waiver Engine (D5) waivers with expiry |
Annex A Controls (ISO 27001:2022)¶
A.5 — Organizational Controls¶
| Control | Description | Coverage | Asset | Evidence |
|---|---|---|---|---|
| A.5.1 | Policies for information security | 🔧 Partial | — | Draft policies in compliance/policies/; V-series (M4, Policy Repo Template (V1)) |
| A.5.2 | Information security roles and responsibilities | ✅ | Entra ID Baseline Module (H1)/Conditional Access Module (H2)/Entra PIM Templates Module (H3) |
RBAC assignments in Terraform state |
| A.5.3 | Segregation of duties | ✅ | Azure Resource PIM Module (B5), Conditional Access Module (H2) |
PIM eligible roles; custom role definitions |
| A.5.5 | Contact with authorities | 📋 Manual | — | IR runbook includes authority contacts (Incident Response Runbooks K1) |
| A.5.7 | Threat intelligence | ✅ | Subscription Baseline Module (B3) (Defender) |
Defender for Cloud threat signals |
| A.5.8 | Information security in project management | 🔧 Partial | PR Quality-Gate Workflow (D2), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) |
Security gates in CI/CD pipeline; checklist item for project plans |
| A.5.9 | Inventory of information and assets | ✅ | Discovery Audit Suite (G0–G7), Module Registry & Versioning (F11) |
Discovery audit asset list; module registry |
| A.5.10 | Acceptable use of information | 📋 Manual | — | AUP policy document |
| A.5.11 | Return of assets | 📋 Manual | — | Offboarding checklist; Entra ID Baseline Module (H1) user lifecycle |
| A.5.12 | Classification of information | 📋 Manual | — | Data classification policy; not an IaC control |
| A.5.13 | Labelling of information | 🔧 Partial | Tag Policy Module (U2) |
Required-tags deny policy enforces tag presence |
| A.5.14 | Information transfer | 🔧 Partial | TLS Policy Module (M3), Private Endpoint Policy Module (N5) |
TLS deny policy; public-access deny; DLP not in scope |
| A.5.15 | Access control | ✅ | Azure Baseline Module (F1), Entra ID Baseline Module (H1)–Entra PIM Templates Module (H3), Azure Resource PIM Module (B5), Break-Glass Account Module (H7) |
Identity module outputs; RBAC; PIM; break-glass |
| A.5.16 | Identity management | ✅ | Azure Baseline Module (F1), Entra ID Baseline Module (H1) |
Entra ID module; group-based access provisioning |
| A.5.17 | Authentication information | ✅ | Break-Glass Account Module (H7), Pre-Commit Quality Hooks (D1) |
Break-glass + FIDO2; branch protection (no password push) |
| A.5.18 | Access rights | ✅ | Conditional Access Module (H2), Azure Resource PIM Module (B5) |
Role assignments; PIM eligibility records |
| A.5.19 | Information security in supplier relationships | ⏳ Roadmap | P-series (M4) | Vendor risk questionnaires |
| A.5.20 | Addressing security within supplier agreements | 📋 Manual | — | Contract clauses; legal instrument |
| A.5.21 | Managing security in ICT supply chain | ✅ | Container Build & Sign Pipeline (C2) (Grype, Syft), Kyverno AKS Policy Bundle (D4) |
SBOM + CVE scan artifacts; signed images |
| A.5.22 | Monitoring, review of supplier services | ⏳ Roadmap | P-series (M4) | Periodic vendor review tracking |
| A.5.23 | Information security for cloud services | ✅ | Subscription Baseline Module (B3), Compliance Snapshot Collector (E0), Compliance Dashboard (S2) |
MCSB; Defender score; compliance snapshot |
| A.5.24 | Information security incident management planning | ✅ | Incident Response Runbooks (K1), On-Call Integration Module (K2) |
IR runbook library; on-call integration |
| A.5.25 | Assessment and decision on information security events | ✅ | Incident Response Runbooks (K1) |
IR runbook triage steps |
| A.5.26 | Response to information security incidents | ✅ | Incident Response Runbooks (K1), On-Call Integration Module (K2) |
Response runbooks; on-call escalation |
| A.5.27 | Learning from incidents | 🔧 Partial | Incident Response Runbooks (K1) |
Post-incident review section in IR runbook |
| A.5.28 | Collection of evidence | ✅ | Audit Log Archive Module (J6), Compliance Snapshot Collector (E0) |
WORM immutable logs; compliance snapshots |
| A.5.29 | Information security during disruption | ✅ | Azure Backup Policy Module (L1), Cross-Region Replication Module (L2), Automated Restore Drill (L4) |
Backup policies; cross-region replication; restore drill |
| A.5.30 | ICT readiness for business continuity | ✅ | Automated Restore Drill (L4) |
Restore drill report with measured RTO |
| A.5.33 | Protection of records | ✅ | Audit Log Archive Module (J6), Azure Backup Policy Module (L1) |
WORM blob; backup retention policy |
| A.5.34 | Privacy and protection of PII | 🔧 Partial | Data Residency Policy Module (M6), Entra ID Baseline Module (H1)/Conditional Access Module (H2) |
Region deny policy; access control |
| A.5.36 | Compliance with policies | ✅ | Terraform OPA Policy Bundle (D3)/Conftest Test Suite (X3), PR Quality-Gate Workflow (D2) |
OPA policy gate; quality gates CI |
| A.5.37 | Documented operating procedures | ✅ | Runbook Generator (V3), Incident Response Runbooks (K1) |
Runbook generator; IR runbook library |
A.6 — People Controls¶
| Control | Description | Coverage | Asset | Evidence |
|---|---|---|---|---|
| A.6.1 | Screening (background checks) | ⏳ Roadmap | Q-series (M4) | Tracking only; checks are manual |
| A.6.2 | Terms and conditions of employment | 📋 Manual | — | Employment contract; HR process |
| A.6.3 | Information security awareness, education, training | ⏳ Roadmap | Q-series (M4) | Training completion tracking |
| A.6.4 | Disciplinary process | 📋 Manual | — | HR process |
| A.6.5 | Responsibilities after termination | 🔧 Partial | Entra ID Baseline Module (H1) (user lifecycle) |
Entra group removal on offboarding |
| A.6.6 | Confidentiality or NDA | 📋 Manual | — | Legal document |
| A.6.7 | Remote working | ✅ | Private Endpoint Policy Module (N5), TLS Policy Module (M3) |
Network + TLS policies apply equally to remote |
| A.6.8 | Information security event reporting | ✅ | Incident Response Runbooks (K1), On-Call Integration Module (K2) |
Incident reporting runbook; on-call escalation |
A.7 — Physical Controls¶
All A.7 physical controls apply to offices and on-premises equipment — not applicable to Azure cloud IaC. Azure's physical security is inherited from Microsoft's ISO 27001 certification.
| Control | Coverage | Notes |
|---|---|---|
| A.7.1–A.7.14 | ❌ Azure platform / office | Client responsible for office physical controls; Azure data centre controls inherited |
A.8 — Technological Controls¶
| Control | Description | Coverage | Asset | Evidence |
|---|---|---|---|---|
| A.8.1 | User endpoint devices | 🔧 Partial | PR Quality-Gate Workflow (D2) (gitleaks) |
Secret scan on developer machines via pre-commit (D2) |
| A.8.2 | Privileged access rights | ✅ | Azure Resource PIM Module (B5), Entra PIM Templates Module (H3), Break-Glass Account Module (H7) |
PIM eligible assignments; activation policy; break-glass |
| A.8.3 | Information access restriction | ✅ | Conditional Access Module (H2), Private Endpoint Policy Module (N5) |
RBAC custom roles; public-access deny |
| A.8.4 | Access to source code | ✅ | Pre-Commit Quality Hooks (D1), GitOps Branching Standard (C4) |
Branch protection; CODEOWNER review gates |
| A.8.5 | Secure authentication | ✅ | Break-Glass Account Module (H7), Azure Baseline Module (F1) |
Break-glass FIDO2; OIDC federation (no passwords) |
| A.8.6 | Capacity management | ✅ | Budget Alert Module (U1), Log Analytics Module (J1) |
Budget alerts; LAW metrics queries |
| A.8.7 | Protection against malware | ✅ | Subscription Baseline Module (B3), Kyverno AKS Policy Bundle (D4), Container Build & Sign Pipeline (C2) |
Defender for Cloud; Kyverno signed-image admission |
| A.8.8 | Management of technical vulnerabilities | ✅ | PR Quality-Gate Workflow (D2) (trivy/tfsec/checkov), Container Build & Sign Pipeline (C2) (Grype) |
CVE scan artifacts in CI |
| A.8.9 | Configuration management | ✅ | All F/B modules | Terraform-managed configuration; no manual changes |
| A.8.10 | Information deletion | 🔧 Partial | Azure Backup Policy Module (L1) (retention) |
Backup retention policy; manual deletion policy needed |
| A.8.11 | Data masking | 📋 Manual | — | Application-layer control; not IaC |
| A.8.12 | Data leakage prevention | 🔧 Partial | PR Quality-Gate Workflow (D2) (gitleaks) |
Secret scanning; full DLP not in scope |
| A.8.13 | Information backup | ✅ | Azure Backup Policy Module (L1) |
Azure Backup policy module; multi-tier retention |
| A.8.14 | Redundancy of information processing | ✅ | Cross-Region Replication Module (L2), Automated Restore Drill (L4) |
Cross-region replication; restore drill proof |
| A.8.15 | Logging | ✅ | Log Analytics Module (J1), Policy Diagnostics Module (J2), Audit Log Archive Module (J6) |
Log Analytics workspace; diagnostic settings; WORM |
| A.8.16 | Monitoring activities | ✅ | Drift Detector (S1), Compliance Dashboard (S2), Subscription Baseline Module (B3) |
Drift detection; compliance dashboard; Defender |
| A.8.17 | Clock synchronization | ❌ | Azure platform | Azure enforces NTP; not configurable via IaC |
| A.8.18 | Use of privileged utility programs | ✅ | Azure Resource PIM Module (B5) (PIM), Break-Glass Account Module (H7) |
Time-boxed privileged access; break-glass audit log |
| A.8.19 | Installation of software on operational systems | ✅ | Kyverno AKS Policy Bundle (D4) (Kyverno), Container Build & Sign Pipeline (C2) |
Signed-image admission; SBOM tracking |
| A.8.20 | Networks security | ✅ | Network Hub Module (F2), Private Endpoint Policy Module (N5), NSG Baseline Module (N6) |
VNet isolation; NSG; public-access deny |
| A.8.21 | Security of network services | ✅ | Network Hub Module (F2), TLS Policy Module (M3) |
Private endpoints; TLS deny policy |
| A.8.22 | Segregation of networks | ✅ | Network Hub Module (F2), Secure AKS Module (F3) |
Spoke VNet per workload; AKS with Azure CNI Overlay |
| A.8.23 | Web filtering | ❌ Application layer | — | Not an IaC control |
| A.8.24 | Use of cryptography | ✅ | Encryption Policy Module (M1), Customer-Managed Key Module (M2), Key Vault Module (F5) |
Encryption deny policy; CMK; Key Vault |
| A.8.25 | Secure development lifecycle | ✅ | Pre-Commit Quality Hooks (D1), PR Quality-Gate Workflow (D2), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) |
Branch protection; quality gates; signed delivery |
| A.8.26 | Application security requirements | 🔧 Partial | Terraform OPA Policy Bundle (D3)/Conftest Test Suite (X3), PR Quality-Gate Workflow (D2) |
OPA policy; checkov; application-layer controls are client's |
| A.8.27 | Secure system architecture and engineering | ✅ | Cloud-Agnostic Module Contracts (F0) (contracts), B-modules |
Cloud-agnostic contracts; opinionated composition modules |
| A.8.28 | Secure coding | 🔧 Partial | PR Quality-Gate Workflow (D2) (CodeQL via GHA) |
SAST; language-specific secure-coding practices are client's |
| A.8.29 | Security testing in development and acceptance | ✅ | Terratest Harness (X2) (Terratest), PR Quality-Gate Workflow (D2) |
IaC tests; quality gates gate every PR |
| A.8.30 | Outsourced development | 📋 Manual | — | Supplier management (P-series, M4) |
| A.8.31 | Separation of development, test, production | ✅ | Azure Sandbox Subscription (X1), Terraform Plan/Apply Pipeline (C1) (environments) |
Dedicated sandbox sub; GitHub/ADO environment gates |
| A.8.32 | Change management | ✅ | Pre-Commit Quality Hooks (D1), GitOps Branching Standard (C4), Terraform Plan/Apply Pipeline (C1)–AKS Deploy Pipeline (C3) |
PR + CI + CODEOWNER → merge gate |
| A.8.33 | Test information | ✅ | Azure Sandbox Subscription (X1), Terratest Harness (X2) |
Sandbox subscription; Terratest fixtures (no prod data) |
| A.8.34 | Protection of information systems during audit | ✅ | Pre-Commit Quality Hooks (D1), Azure Resource PIM Module (B5) |
Read-only audit accounts via PIM; branch protection |
What SnowOps Does NOT Automate (Manual Requirements for Certification)¶
These items are required for ISO 27001:2022 certification but are outside SnowOps automation scope. What to do about each:
| Requirement | Who | What the manual step is | Notes |
|---|---|---|---|
| ISMS scope document | Client | Write a formal document naming the boundaries of the Information Security Management System — which business units, locations, systems, and services are in/out of scope, and why | This is the foundational management artefact every other ISO 27001 document references; SnowOps' technical scope (the F/B/H platform) can inform it but the org-wide boundary decision is the client's |
| Statement of Applicability (SoA) | Client | For each of the 93 Annex A controls, state whether it's applicable, justify the inclusion/exclusion, and reference the implementing control/asset (use this mapping doc as the technical input column) | The SoA itself — the signed-off management artefact mapping controls to justifications — must be authored and owned by the client's ISMS lead |
| Risk treatment plan | Client | Stand up a risk register seeded from Discovery Audit Suite (G0–G7) findings; assign owners, likelihood/impact scores, and treatment decisions (accept/mitigate/transfer/avoid), and review on a fixed cadence |
The G-series report supplies severity-scored, framework-tagged findings as raw input; converting that into a formal, management-reviewed treatment plan with documented decisions is a governance responsibility |
| Internal audit programme | Client | Define an annual internal-audit schedule, ensure auditor independence (someone who didn't implement the control performs the audit), and track findings to closure | Compliance Dashboard (S2) and Compliance Snapshot Collector (E0) evidence streams give the auditor source data, but the audit programme, scheduling, and independence requirement are organizational |
| Management review meetings (9.3) | Client | Hold periodic (quarterly recommended) management-review meetings covering ISMS performance, audit results, risk status, and improvement opportunities, and minute the decisions | Use the Compliance Dashboard (S2) dashboard as the review input; the meeting itself, attendance, and documented decisions must be run by the client's leadership |
| Corrective action tracking (10.1) | Client (🔧 partially tooled) | Maintain a formal CAPA (corrective and preventive action) register: log each nonconformity, root-cause it, assign a fix and an owner, and verify closure | Drift Detector (S1) opens an issue per drift finding automatically; turning that issue stream into an auditable CAPA register with root-cause analysis is manual today — Policy Repo Template (V1, M4) will formalize the workflow |
| Information security policies (A.5.1) | Client | Draft each required policy (InfoSec, access control, cryptography, supplier, incident response, etc.) as a markdown doc with purpose/scope/statements/roles/review-cadence/approval log, and commit it to compliance/policies/ per the Policy Library Guide |
Policy Repo Template (V1, M4) will add a markdown library + amendment workflow + acknowledgment sync; until then the git history of compliance/policies/ is the audit trail — Q-series and P-series (M4) cover the adjacent HR/vendor policy tracking |
| Background checks / screening (A.6.1) | Client | Run pre-employment background checks through a vetted screening vendor before each hire's start date, and retain the results on file | HR Security & Training (Q1–Q5, M4) will automate tracking of completion/expiry via tickets; the checks themselves and the hire/no-hire decision are inherently human, HR-owned steps |
| Security awareness training (A.6.3) | Client | Stand up (or use an existing) training platform, assign annual security-awareness plus role-specific training, and retain completion certificates as evidence | HR Security & Training (Q1–Q5, M4) will automate enrollment/completion tracking and reminders; delivering and recording the training stays client-owned even after M4 ships |
| Physical security controls (A.7) | Client | For client-controlled premises: implement badge access, visitor logs, CCTV, clean-desk policy, and equipment-disposal procedures, and document them in a physical-security policy | Azure datacentre physical security is inherited from Microsoft's own ISO 27001 certification (see the Compliance Engagement Guide for the shared-responsibility framing); office/equipment controls are the client's to implement and document |
| Vendor contracts with security clauses (A.5.20) | Client | Build a vendor register (name, service, data accessed, risk tier), collect SOC 2/ISO reports or completed security questionnaires from critical vendors, and have legal counsel execute contracts/DPAs containing security clauses | Vendor & Third-Party Risk (P1–P4, M4) will automate the register and review-tracker; the due-diligence judgment calls and contract execution through legal counsel remain manual — see the Policy Library Guide vendor-management-policy.md row |
| Certification body engagement | Client | Select and contract an accredited Certification Body (CAB) and schedule the two-stage external audit (Stage 1 documentation review, Stage 2 implementation audit) | See the Compliance Engagement Guide §3 ISO 27001 — "Auditor" note for sequencing and lead-time guidance |
| Surveillance audits (annual) | Client | Budget for and schedule annual surveillance audits with the CAB to maintain certification between the 3-year recertification cycles | Ongoing commitment after initial certification; Compliance Snapshot Collector (E0) evidence accumulation continues to reduce the audit-prep burden each cycle |