Compliance
ISO/IEC 27001:2022 with PuReAI
The Annex A controls that fail surveillance audits most often are the ones about other people's systems. PuReAI produces the dated, repeatable evidence those controls ask for.
Where PuReAI fits
ISO 27001:2022 introduced A.5.7 Threat intelligence as a new control and tightened supplier monitoring in A.5.19–A.5.22. Both expect an ongoing process, not an annual questionnaire.
Requirement → module → evidence
Each row is a control or requirement, the PuReAI module that produces relevant signal, and the artefact you can put in front of an auditor.
| Requirement | Module | Evidence produced |
|---|---|---|
| A.5.7 — Threat intelligence | News / Threats, Threat graph | Collected, analysed and contextualised actor and TTP intelligence relevant to your sector, retrievable on demand. |
| A.5.19–A.5.22 — Supplier relationships and monitoring | Supply Chain | Continuous supplier scoring with change history, so review is evidence-based rather than declarative. |
| A.5.9 / A.8.1 — Inventory of assets | Domain, IP, Certificate, Technology | Externally discovered assets, including shadow IT the internal CMDB does not list. |
| A.8.8 — Management of technical vulnerabilities | Vulnerability | NVD and KEV-matched findings with severity, confidence, owner and status lifecycle. |
| A.8.9 — Configuration management | Misconfiguration | DNS, SPF/DKIM/DMARC and TLS configuration deviations on discovered assets. |
| A.5.34 / A.8.12 — Data leakage | Leaked Data, Git Leaks, Sensitive Files | Exposed credentials, secrets in public repositories and indexed sensitive documents. |
Scope and limits
- Findings carry a status lifecycle — Open, In Progress, Resolved, Accepted Risk, Monitored — which maps directly to the risk treatment records an auditor samples.
- Accepted Risk keeps the finding visible in evidence while stopping the repeat alert, matching ISO's risk acceptance expectation.
Questions we get asked
Can PuReAI output be used as audit evidence?
Yes. Findings and scores are dated records with the underlying evidence attached — the certificate, DNS record, banner or commit — and export for the ISMS file.
Does this cover the whole Annex A?
No. PuReAI covers external exposure, supplier monitoring, threat intelligence and technical vulnerability controls. Organisational, people and physical controls are out of scope.
See the evidence for your own domain
Start with a free domain report, or read the full scoring methodology.