ISO 27001
ISO 27002:2022 Control Alignment
ISO/IEC 27002:2022 provides a reference set of information security controls and the guidance for implementing them; ISO/IEC 27001:2022 remains the requirements standard for the management system. ISO 27002 is not itself a certification standard. What this engagement produces is not a mapping document — it is a set of controls with named owners, a stated operating practice, identified evidence and a way of testing that the evidence means what it claims.
Methodology
- 01
Applicability
Determine which controls apply, using business context, risk and the defined ISMS scope — not a blanket adoption of all 93.
- 02
Ownership
Define ownership and the expected operating practice for each applicable control.
- 03
Evidence Design
Identify the evidence that would prove the control is implemented and operating, before the control goes live rather than after.
- 04
Testing
Test evidence and operating effectiveness through review, sampling, interview or technical assurance where appropriate.
- 05
Exception Tracking
Track exceptions, remediation and residual risk, so a control that is not operating is a known position rather than a surprise at audit.
- 06
Monitoring
Establish how each control is monitored once it is operating, so drift is visible between audits.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- ISO/IEC 27002:2022
- The reference control set and implementation guidance this engagement is run against. Not a certification standard.
- ISO/IEC 27001:2022
- The requirements standard. Annex A is where applicability and the Statement of Applicability are decided.
- CSS ISO 27001 Toolkit
- Control ownership, evidence expectations and monitoring, deployed selectively rather than as a document dump.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS ISO 27001 Toolkit
Statement of Applicability, control ownership register and evidence map.
GRC Assessment Toolkit
Control assessment, evidence assessment and remediation tracking.
PlyoGRC
Where engaged, maintains the relationship between requirement, control, owner, evidence, finding and action as controlled records rather than a spreadsheet.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Organisational controls (37)
- Governance, policies and roles
- Threat intelligence
- Supplier relationships
- Incident management
- Business continuity
- Compliance obligations
- Information classification and handling
People controls (8)
- Responsibilities and terms of employment
- Screening
- Awareness and training
- Disciplinary process
- Remote working
- Reporting of information security events
Physical controls (14)
- Secure areas and physical access management
- Equipment protection and siting
- Environmental safeguards
- Clear desk and clear screen
- Secure disposal and re-use of equipment
- Storage media handling
Technological controls (34)
- Identity and access management
- Endpoint and network security
- Secure development
- Logging and monitoring
- Backup and redundancy
- Vulnerability management
- Cryptography and key management
- Data masking and leakage prevention
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Applicability is decided, not assumed
Controls are selected against business context, risk and the ISMS scope. Adopting all 93 because they exist produces a Statement of Applicability nobody can defend and controls nobody operates.
Every control has a named owner
A control owned by “the security team” for a process the security team does not run will not operate, and an auditor will find that.
Evidence designed with the control
What would prove this control operates is decided before it goes live. Retrofitting evidence ahead of an audit is the most common cause of a late, expensive certification push.
27002 is guidance, 27001 is the requirement
ISO/IEC 27002 is not a certification standard. Control alignment supports certification against ISO/IEC 27001; it does not substitute for it.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.