SanRa
ISO/IEC 27001 · Information security management

An ISMS people
can actually run.

A practical framework for ISO/IEC 27001 readiness — map the clauses, track evidence gaps, and prioritise Annex A themes that matter. Educational only; not a certification audit.

Open the framework
Your readiness signal 0% complete

Work through the clause checklist. Progress stays in this browser only.

Why this exists

Security fails when the system is paper-only.

ISO/IEC 27001 asks organisations to establish, implement, maintain and continually improve an information security management system. This portal turns that into a usable map — with human factors, supplier risk and operational evidence kept in view alongside the Statement of Applicability.

Clause framework

Seven domains. Work them in order.

Mark each item as you build evidence. Use this as a readiness conversation tool with leadership — not as a certificate.

Discuss gaps with SanRa

This framework is educational. It is not legal advice, an audit, or a determination of ISO/IEC 27001 conformity or certification readiness.

Annex A lens · 2022

Control themes that usually matter first

01 · Organisational controls

Policies, roles, asset management, access rules, supplier relationships, incident response and business continuity alignment.

02 · People controls

Screening, terms of employment, awareness, disciplinary process, and remote working expectations under pressure.

03 · Physical controls

Secure areas, entry controls, equipment protection, clear desk/screen and secure disposal of media.

04 · Technological controls

Authentication, malware protection, logging, network security, secure development, encryption and data leakage prevention.

05 · Statement of Applicability

Which Annex A controls apply, which do not, and why — with residual risk accepted by name.

06 · Human factors

Where controls collide with workload, culture and convenience — the gap between procedure and behaviour.

Related frameworks

FIDO

Passkeys that
survive phishing.

Phishing-resistant authentication belongs inside a working ISMS — map FIDO into access control and assurance evidence.

Open FIDO framework

ISO/IEC 42001

AI management
alongside the ISMS.

Where AI systems create new information risks, map them into your AIMS — and keep the ISMS and AIMS coherent.

Open ISO 42001 framework

WP-01

The Neuron Doctrine
of Security.

SanRa thought leadership on human factors and security in the age of AI-augmented systems.

Download whitepaper
Start a readiness conversation

Build an ISMS that survives
contact with reality.

ibrahim.mukherjee@icloud.com

Read our privacy notice.