← Atlas · Frameworks & standardsInterpretive coverage map

ISO/IEC 27001:2022 · Information security management

ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system (ISMS): the governance an organization puts around protecting its information assets. Helmwart reads it the way it reads every framework — as an interpretive layer, mapping the Annex A controls that carry a design-time threat surface to the agentic threats they bear on, and honestly marking the rest as organizational process.

Governance & assurance standardAnnex A:2022 · 93 controlsInterpretive mapping
4 themes93 Annex A controls34 design-time mappable59 organizational

What ISO/IEC 27001 is

ISO/IEC 27001:2022 is the international standard for an information security management system(ISMS) — the governance scaffolding an organization puts around protecting information, wherever it lives. It is a certifiable management-system standard, structured as management clauses 4–10 plus a set of reference controls in Annex A, organized into four themes: organizational, people, physical, and technological.

In practice the standard asks an organization to define its security policy, assign accountable roles, control access, protect its people and premises, secure its technology (networks, cryptography, logging, secure development), and manage its suppliers — then to keep evidence that it actually does these things, and to improve the system over time. It is a governance and assurance lens, not a threat taxonomy: where OWASP and MITRE ATLAS tell you what can go wrong, ISO 27001 asks whether you are running a system that would catch and manage it.

How Helmwart maps to it

Helmwart is a design-time threat-modeling tool, not an audit. It cannot make you certified to ISO 27001 — certification is an audited outcome of operating a management system, awarded by an accredited body. What Helmwart can do is show, control by control, which Annex A controls your threat model and placed mitigations actually bear on, and which are gaps — a coverage map you can fold into a Statement of Applicability, never a compliance verdict.

Two honest limits shape that map.

Most of Annex A is organizational, not technical. Of the 93 Annex A controls, 59 are policy, HR, physical-facility, and process controls — a security policy exists, staff are screened and trained, premises are secured. A design-time tool cannot satisfy those; they are your organization's process, and Helmwart marks them organizational rather than claiming a green. Only the 34 identity/access, supplier, and — above all — technological controls (A.8) carry a threat surface a model can assess — those are the ones mapped below to the agentic threats they bear on.

The mapping is interpretive. ISO/IEC 27001 is a copyrighted, paywalled standard. Every control description here is Helmwart's own summary of the control's intent, citing ISO 27001 — never the standard's verbatim text. Treat it as an interpretive layer, the same posture Helmwart takes toward every framework it reads.

To turn this reference into a live coverage read against a specific system, model it on thecanvas and open the Compliance view — it scores each Annex A control as covered, at-risk, or not-present from the findings your design actually raises, and lists the mitigations that close each gap.

Annex A reference controls

The 93 Annex A:2022 controls across 4 themes (A.5–A.8). Controls that carry a design-time threat surface are tagged mappable and list the agentic threats they bear on; the rest are tagged organizational — real controls, but your process, not a Helmwart control.

A.5Organizational controls

Policy, roles, supplier & incident-management process

  • A.5.1Policies for information security.organizational

    Policy set.

  • A.5.2Information security roles and responsibilities.organizational

    Roles & responsibilities.

  • A.5.3Segregation of duties.organizational

    Segregation of duties.

  • A.5.4Management responsibilities.organizational

    Management responsibilities.

  • A.5.5Contact with authorities.organizational

    Authority liaison.

  • A.5.6Contact with special interest groups.organizational

    Peer & community liaison.

  • A.5.7Threat intelligence.organizational

    Threat-intel consumption process.

  • A.5.8Information security in project management.organizational

    Security in projects.

  • A.5.9Inventory of information and other associated assets.organizational

    Asset inventory.

  • A.5.10Acceptable use of information and other associated assets.organizational

    Acceptable use.

  • A.5.11Return of assets.organizational

    Asset return on termination.

  • A.5.12Classification of information.organizational

    Information classification.

  • A.5.13Labelling of information.organizational

    Information labelling.

  • A.5.14Information transfer.organizational

    Transfer procedures & agreements.

  • A.5.15Access control.mappable

    Access-control rules over agent identities and privilege boundaries.

    Threats:T3T45
  • A.5.16Identity management.mappable

    The full identity lifecycle a non-human agent identity moves through.

  • A.5.17Authentication information.mappable

    Credential and service-account exposure.

    Threats:T9T22
  • A.5.18Access rights.mappable

    Rights granted, modified, and revoked across a delegation chain.

    Threats:T3T50
  • A.5.19Information security in supplier relationships.mappable

    Third-party model/tool/plugin trust.

    Threats:T17T29T47
  • A.5.20Addressing information security within supplier agreements.organizational

    Supplier contract terms.

  • A.5.21Managing information security in the ICT supply chain.mappable

    Upstream model/prompt/plugin/framework compromise.

    Threats:T17T25T29T47
  • A.5.22Monitoring, review, and change management of supplier services.organizational

    Supplier service oversight.

  • A.5.23Information security for use of cloud services.mappable

    Hosting/deployment exposing the system beyond its intended boundary.

    Threats:T43
  • A.5.24Information security incident management planning and preparation.organizational

    Incident-management planning.

  • A.5.25Assessment and decision on information security events.organizational

    Event triage process.

  • A.5.26Response to information security incidents.organizational

    Incident response process.

  • A.5.27Learning from information security incidents.organizational

    Post-incident learning.

  • A.5.28Collection of evidence.organizational

    Evidence handling.

  • A.5.29Information security during disruption.organizational

    Continuity of security during disruption.

  • A.5.30ICT readiness for business continuity.organizational

    ICT continuity readiness.

  • A.5.31Legal, statutory, regulatory, and contractual requirements.organizational

    Legal & regulatory requirements.

  • A.5.32Intellectual property rights.organizational

    IP rights.

  • A.5.33Protection of records.organizational

    Records protection.

  • A.5.34Privacy and protection of PII.mappable

    Exposure of retrieved/stored data via the RAG or memory surface.

    Threats:T28T22
  • A.5.35Independent review of information security.organizational

    Independent review.

  • A.5.36Compliance with policies, rules, and standards for information security.organizational

    Internal compliance review.

  • A.5.37Documented operating procedures.organizational

    Operating-procedure documentation.

A.6People controls

Screening, training, conduct & termination

  • A.6.1Screening.organizational

    Background screening.

  • A.6.2Terms and conditions of employment.organizational

    Employment terms.

  • A.6.3Information security awareness, education, and training.organizational

    Security awareness training.

  • A.6.4Disciplinary process.organizational

    Disciplinary process.

  • A.6.5Responsibilities after termination or change of employment.organizational

    Post-termination duties.

  • A.6.6Confidentiality or non-disclosure agreements.organizational

    NDAs.

  • A.6.7Remote working.organizational

    Remote-work security.

  • A.6.8Information security event reporting.organizational

    Human event-reporting channel.

A.7Physical controls

Facilities, media & equipment protection

  • A.7.1Physical security perimeters.organizational

    Physical perimeters.

  • A.7.2Physical entry.organizational

    Physical entry control.

  • A.7.3Securing offices, rooms, and facilities.organizational

    Facility security.

  • A.7.4Physical security monitoring.organizational

    Physical monitoring.

  • A.7.5Protecting against physical and environmental threats.organizational

    Environmental protection.

  • A.7.6Working in secure areas.organizational

    Secure-area procedures.

  • A.7.7Clear desk and clear screen.organizational

    Clear desk/screen.

  • A.7.8Equipment siting and protection.organizational

    Equipment siting.

  • A.7.9Security of assets off-premises.organizational

    Off-premises assets.

  • A.7.10Storage media.organizational

    Media handling.

  • A.7.11Supporting utilities.organizational

    Utilities resilience.

  • A.7.12Cabling security.organizational

    Cabling security.

  • A.7.13Equipment maintenance.organizational

    Equipment maintenance.

  • A.7.14Secure disposal or re-use of equipment.organizational

    Equipment disposal.

A.8Technological controls

Access, logging, cryptography, network & secure development

  • A.8.1User endpoint devices.organizational

    Endpoint device management.

  • A.8.2Privileged access rights.mappable

    Privilege compounding across a delegation chain.

    Threats:T3T50
  • A.8.3Information access restriction.mappable

    Restricting access to retrieved/stored data and service accounts.

    Threats:T28T22
  • A.8.4Access to source code.mappable

    Tampering with the code paths an agent executes.

    Threats:T20T29
  • A.8.5Secure authentication.mappable

    Agent/client identity spoofing and impersonation.

    Threats:T9T40
  • A.8.6Capacity management.mappable

    Resource exhaustion from runaway or fan-out agent behaviour.

    Threats:T4T32T39
  • A.8.7Protection against malware.mappable

    Malicious code entering via execution, framework, or plugin paths.

    Threats:T11T20T29
  • A.8.8Management of technical vulnerabilities.mappable

    Vulnerability monitoring of the supply chain and dependencies.

    Threats:T17T25T29T47
  • A.8.9Configuration management.mappable

    Config drift bypassing dynamic policy or exposing a server beyond its boundary.

    Threats:T24T43
  • A.8.10Information deletion.organizational

    Data-deletion process.

  • A.8.11Data masking.mappable

    Reducing exposure of retrieved/stored sensitive data.

    Threats:T28
  • A.8.12Data leakage prevention.mappable

    Exfiltration via retrieval or cross-origin browsing.

    Threats:T28T51
  • A.8.13Information backup.organizational

    Backup process.

  • A.8.14Redundancy of information processing facilities.organizational

    Infrastructure redundancy.

  • A.8.15Logging.mappable

    Traceability of agent actions, incl. MCP request/tool-invocation logs.

    Threats:T8T23T44T46
  • A.8.16Monitoring activities.mappable

    Monitoring of autonomous-write and resource-consuming behaviour.

  • A.8.17Clock synchronization.organizational

    Time sync.

  • A.8.18Use of privileged utility programs.mappable

    Privileged tooling that can escalate an agent beyond its scope.

    Threats:T3
  • A.8.19Installation of software on operational systems.mappable

    Unvetted plugins/dependencies entering a running system.

    Threats:T17T29
  • A.8.20Networks security.mappable

    Network-boundary exposure of tools/servers and cross-origin reach.

    Threats:T43T51
  • A.8.21Security of network services.mappable

    Insecure inter-agent protocols (A2A/MCP) carrying tampered messages.

    Threats:T16T30
  • A.8.22Segregation of networks.mappable

    Cross-tenant/cross-client interference from insufficiently isolated agent actions.

    Threats:T31T42T45
  • A.8.23Web filtering.mappable

    A browser/computer-use tool reaching untrusted origins.

    Threats:T51
  • A.8.24Use of cryptography.mappable

    Signing-key and credential compromise.

    Threats:T34T22
  • A.8.25Secure development life cycle.mappable

    Verification & validation across the tool/execution surface.

  • A.8.26Application security requirements.mappable

    Hardening the code-execution paths an agent exposes.

    Threats:T11
  • A.8.27Secure system architecture and engineering principles.organizational

    Architecture-level design principles.

  • A.8.28Secure coding.mappable

    Code-execution, framework, and plugin vulnerabilities.

    Threats:T11T20T29
  • A.8.29Security testing in development and acceptance.mappable

    Pre-release testing of code-execution, framework, and plugin paths.

    Threats:T11T20T29
  • A.8.30Outsourced development.mappable

    Third-party-built agents/plugins/MCP servers entering the ecosystem.

    Threats:T17T29T47
  • A.8.31Separation of development, test, and production environments.mappable

    Isolation between agent actions and across client sessions.

    Threats:T31T42
  • A.8.32Change management.mappable

    Verification & validation of tool/execution changes before release.

  • A.8.33Test information.organizational

    Test-data handling.

  • A.8.34Protection of information systems during audit testing.organizational

    Audit-testing safeguards.

The management-system clauses (4–10)

Annex A is only half the standard. The management-system requirements — the part you are actually certified against — live in clauses 4 through 10, and they are organizational by nature. Helmwart does not assess these; they are audited process, not design-time surface. They are listed here so you can see the whole shape of an ISMS, not just its reference controls.

  • Clause 4Context of the organizationUnderstand the organization, interested parties and the scope of the ISMS.
  • Clause 5LeadershipTop-management commitment, an information-security policy, and assigned roles and responsibilities.
  • Clause 6PlanningActions to address risks and opportunities, security objectives, and the risk-assessment/treatment process.
  • Clause 7SupportResources, competence, awareness, communication, and documented information.
  • Clause 8OperationOperational planning and control, and running the risk-assessment and risk-treatment process.
  • Clause 9Performance evaluationMonitoring, measurement, internal audit, and management review.
  • Clause 10ImprovementHandling nonconformity and driving continual improvement of the ISMS.

Sources