01 · Organisational controls
Policies, roles, asset management, access rules, supplier relationships, incident response and business continuity alignment.
A practical framework for ISO/IEC 27001 readiness — map the clauses, track evidence gaps, and prioritise Annex A themes that matter. Educational only; not a certification audit.
Open the frameworkISO/IEC 27001 asks organisations to establish, implement, maintain and continually improve an information security management system. This portal turns that into a usable map — with human factors, supplier risk and operational evidence kept in view alongside the Statement of Applicability.
Mark each item as you build evidence. Use this as a readiness conversation tool with leadership — not as a certificate.
This framework is educational. It is not legal advice, an audit, or a determination of ISO/IEC 27001 conformity or certification readiness.
Policies, roles, asset management, access rules, supplier relationships, incident response and business continuity alignment.
Screening, terms of employment, awareness, disciplinary process, and remote working expectations under pressure.
Secure areas, entry controls, equipment protection, clear desk/screen and secure disposal of media.
Authentication, malware protection, logging, network security, secure development, encryption and data leakage prevention.
Which Annex A controls apply, which do not, and why — with residual risk accepted by name.
Where controls collide with workload, culture and convenience — the gap between procedure and behaviour.
FIDO
Phishing-resistant authentication belongs inside a working ISMS — map FIDO into access control and assurance evidence.
Open FIDO frameworkISO/IEC 42001
Where AI systems create new information risks, map them into your AIMS — and keep the ISMS and AIMS coherent.
Open ISO 42001 frameworkWP-01
SanRa thought leadership on human factors and security in the age of AI-augmented systems.
Download whitepaperRead our privacy notice.