ISO/IEC 27001:2022 · Information security management
ISO/IEC 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS): the governance an organization puts around protecting its information assets. Helmwart reads it the way it reads every framework — as an interpretive layer, mapping the Annex A controls that carry a design-time threat surface to the agentic threats they bear on, and honestly marking the rest as organizational process.
What ISO/IEC 27001 is
ISO/IEC 27001:2022 is the international standard for an information security management system(ISMS) — the governance scaffolding an organization puts around protecting information, wherever it lives. It is a certifiable management-system standard, structured as management clauses 4–10 plus a set of reference controls in Annex A, organized into four themes: organizational, people, physical, and technological.
In practice the standard asks an organization to define its security policy, assign accountable roles, control access, protect its people and premises, secure its technology (networks, cryptography, logging, secure development), and manage its suppliers — then to keep evidence that it actually does these things, and to improve the system over time. It is a governance and assurance lens, not a threat taxonomy: where OWASP and MITRE ATLAS tell you what can go wrong, ISO 27001 asks whether you are running a system that would catch and manage it.
How Helmwart maps to it
Helmwart is a design-time threat-modeling tool, not an audit. It cannot make you certified to ISO 27001 — certification is an audited outcome of operating a management system, awarded by an accredited body. What Helmwart can do is show, control by control, which Annex A controls your threat model and placed mitigations actually bear on, and which are gaps — a coverage map you can fold into a Statement of Applicability, never a compliance verdict.
Two honest limits shape that map.
Most of Annex A is organizational, not technical. Of the 93 Annex A controls, 59 are policy, HR, physical-facility, and process controls — a security policy exists, staff are screened and trained, premises are secured. A design-time tool cannot satisfy those; they are your organization's process, and Helmwart marks them organizational rather than claiming a green. Only the 34 identity/access, supplier, and — above all — technological controls (A.8) carry a threat surface a model can assess — those are the ones mapped below to the agentic threats they bear on.
The mapping is interpretive. ISO/IEC 27001 is a copyrighted, paywalled standard. Every control description here is Helmwart's own summary of the control's intent, citing ISO 27001 — never the standard's verbatim text. Treat it as an interpretive layer, the same posture Helmwart takes toward every framework it reads.
To turn this reference into a live coverage read against a specific system, model it on thecanvas and open the Compliance view — it scores each Annex A control as covered, at-risk, or not-present from the findings your design actually raises, and lists the mitigations that close each gap.
Annex A reference controls
The 93 Annex A:2022 controls across 4 themes (A.5–A.8). Controls that carry a design-time threat surface are tagged mappable and list the agentic threats they bear on; the rest are tagged organizational — real controls, but your process, not a Helmwart control.
A.5Organizational controls
Policy, roles, supplier & incident-management process
A.5.1Policies for information security.organizational Policy set.
A.5.2Information security roles and responsibilities.organizational Roles & responsibilities.
A.5.3Segregation of duties.organizational Segregation of duties.
A.5.4Management responsibilities.organizational Management responsibilities.
A.5.5Contact with authorities.organizational Authority liaison.
A.5.6Contact with special interest groups.organizational Peer & community liaison.
A.5.7Threat intelligence.organizational Threat-intel consumption process.
A.5.8Information security in project management.organizational Security in projects.
A.5.9Inventory of information and other associated assets.organizational Asset inventory.
A.5.10Acceptable use of information and other associated assets.organizational Acceptable use.
A.5.11Return of assets.organizational Asset return on termination.
A.5.12Classification of information.organizational Information classification.
A.5.13Labelling of information.organizational Information labelling.
A.5.14Information transfer.organizational Transfer procedures & agreements.
A.5.15Access control.mappable Access-control rules over agent identities and privilege boundaries.
A.5.16Identity management.mappable The full identity lifecycle a non-human agent identity moves through.
A.5.17Authentication information.mappable Credential and service-account exposure.
A.5.18Access rights.mappable Rights granted, modified, and revoked across a delegation chain.
A.5.19Information security in supplier relationships.mappable Third-party model/tool/plugin trust.
A.5.20Addressing information security within supplier agreements.organizational Supplier contract terms.
A.5.21Managing information security in the ICT supply chain.mappable Upstream model/prompt/plugin/framework compromise.
A.5.22Monitoring, review, and change management of supplier services.organizational Supplier service oversight.
A.5.23Information security for use of cloud services.mappable Hosting/deployment exposing the system beyond its intended boundary.
Threats:T43A.5.24Information security incident management planning and preparation.organizational Incident-management planning.
A.5.25Assessment and decision on information security events.organizational Event triage process.
A.5.26Response to information security incidents.organizational Incident response process.
A.5.27Learning from information security incidents.organizational Post-incident learning.
A.5.28Collection of evidence.organizational Evidence handling.
A.5.29Information security during disruption.organizational Continuity of security during disruption.
A.5.30ICT readiness for business continuity.organizational ICT continuity readiness.
A.5.31Legal, statutory, regulatory, and contractual requirements.organizational Legal & regulatory requirements.
A.5.32Intellectual property rights.organizational IP rights.
A.5.33Protection of records.organizational Records protection.
A.5.34Privacy and protection of PII.mappable Exposure of retrieved/stored data via the RAG or memory surface.
A.5.35Independent review of information security.organizational Independent review.
A.5.36Compliance with policies, rules, and standards for information security.organizational Internal compliance review.
A.5.37Documented operating procedures.organizational Operating-procedure documentation.
A.6People controls
Screening, training, conduct & termination
A.6.1Screening.organizational Background screening.
A.6.2Terms and conditions of employment.organizational Employment terms.
A.6.3Information security awareness, education, and training.organizational Security awareness training.
A.6.4Disciplinary process.organizational Disciplinary process.
A.6.5Responsibilities after termination or change of employment.organizational Post-termination duties.
A.6.6Confidentiality or non-disclosure agreements.organizational NDAs.
A.6.7Remote working.organizational Remote-work security.
A.6.8Information security event reporting.organizational Human event-reporting channel.
A.7Physical controls
Facilities, media & equipment protection
A.7.1Physical security perimeters.organizational Physical perimeters.
A.7.2Physical entry.organizational Physical entry control.
A.7.3Securing offices, rooms, and facilities.organizational Facility security.
A.7.4Physical security monitoring.organizational Physical monitoring.
A.7.5Protecting against physical and environmental threats.organizational Environmental protection.
A.7.6Working in secure areas.organizational Secure-area procedures.
A.7.7Clear desk and clear screen.organizational Clear desk/screen.
A.7.8Equipment siting and protection.organizational Equipment siting.
A.7.9Security of assets off-premises.organizational Off-premises assets.
A.7.10Storage media.organizational Media handling.
A.7.11Supporting utilities.organizational Utilities resilience.
A.7.12Cabling security.organizational Cabling security.
A.7.13Equipment maintenance.organizational Equipment maintenance.
A.7.14Secure disposal or re-use of equipment.organizational Equipment disposal.
A.8Technological controls
Access, logging, cryptography, network & secure development
A.8.1User endpoint devices.organizational Endpoint device management.
A.8.2Privileged access rights.mappable Privilege compounding across a delegation chain.
A.8.3Information access restriction.mappable Restricting access to retrieved/stored data and service accounts.
A.8.4Access to source code.mappable Tampering with the code paths an agent executes.
A.8.5Secure authentication.mappable Agent/client identity spoofing and impersonation.
A.8.6Capacity management.mappable Resource exhaustion from runaway or fan-out agent behaviour.
A.8.7Protection against malware.mappable Malicious code entering via execution, framework, or plugin paths.
A.8.8Management of technical vulnerabilities.mappable Vulnerability monitoring of the supply chain and dependencies.
A.8.9Configuration management.mappable Config drift bypassing dynamic policy or exposing a server beyond its boundary.
A.8.10Information deletion.organizational Data-deletion process.
A.8.11Data masking.mappable Reducing exposure of retrieved/stored sensitive data.
Threats:T28A.8.12Data leakage prevention.mappable Exfiltration via retrieval or cross-origin browsing.
A.8.13Information backup.organizational Backup process.
A.8.14Redundancy of information processing facilities.organizational Infrastructure redundancy.
A.8.15Logging.mappable Traceability of agent actions, incl. MCP request/tool-invocation logs.
A.8.16Monitoring activities.mappable Monitoring of autonomous-write and resource-consuming behaviour.
A.8.17Clock synchronization.organizational Time sync.
A.8.18Use of privileged utility programs.mappable Privileged tooling that can escalate an agent beyond its scope.
Threats:T3A.8.19Installation of software on operational systems.mappable Unvetted plugins/dependencies entering a running system.
A.8.20Networks security.mappable Network-boundary exposure of tools/servers and cross-origin reach.
A.8.21Security of network services.mappable Insecure inter-agent protocols (A2A/MCP) carrying tampered messages.
A.8.22Segregation of networks.mappable Cross-tenant/cross-client interference from insufficiently isolated agent actions.
A.8.23Web filtering.mappable A browser/computer-use tool reaching untrusted origins.
Threats:T51A.8.24Use of cryptography.mappable Signing-key and credential compromise.
A.8.25Secure development life cycle.mappable Verification & validation across the tool/execution surface.
A.8.26Application security requirements.mappable Hardening the code-execution paths an agent exposes.
Threats:T11A.8.27Secure system architecture and engineering principles.organizational Architecture-level design principles.
A.8.28Secure coding.mappable Code-execution, framework, and plugin vulnerabilities.
A.8.29Security testing in development and acceptance.mappable Pre-release testing of code-execution, framework, and plugin paths.
A.8.30Outsourced development.mappable Third-party-built agents/plugins/MCP servers entering the ecosystem.
A.8.31Separation of development, test, and production environments.mappable Isolation between agent actions and across client sessions.
A.8.32Change management.mappable Verification & validation of tool/execution changes before release.
A.8.33Test information.organizational Test-data handling.
A.8.34Protection of information systems during audit testing.organizational Audit-testing safeguards.
The management-system clauses (4–10)
Annex A is only half the standard. The management-system requirements — the part you are actually certified against — live in clauses 4 through 10, and they are organizational by nature. Helmwart does not assess these; they are audited process, not design-time surface. They are listed here so you can see the whole shape of an ISMS, not just its reference controls.
- Clause 4Context of the organizationUnderstand the organization, interested parties and the scope of the ISMS.
- Clause 5LeadershipTop-management commitment, an information-security policy, and assigned roles and responsibilities.
- Clause 6PlanningActions to address risks and opportunities, security objectives, and the risk-assessment/treatment process.
- Clause 7SupportResources, competence, awareness, communication, and documented information.
- Clause 8OperationOperational planning and control, and running the risk-assessment and risk-treatment process.
- Clause 9Performance evaluationMonitoring, measurement, internal audit, and management review.
- Clause 10ImprovementHandling nonconformity and driving continual improvement of the ISMS.
Sources
- ISO/IEC 27001:2022 — Information security, cybersecurity & privacy protection ↗ · ISO · the authoritative standard (paywalled; purchase from ISO)
- Run the coverage against your model → · Helmwart Compliance · live per-control read from your canvas findings