ISO/IEC 27001:2022 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). UNUS London deploys database-first ISMS infrastructure that evidences conformance across all 93 Annex A controls — with immutable audit trails, automated risk treatment records, and sub-30-second evidence retrieval.
ISO/IEC 27001:2022 follows the ISO High Level Structure (HLS/Annex SL), enabling integration with other management system standards. Clauses 4–10 are normative — organisations shall comply with every requirement to claim conformance. Prescriptive language follows ISO/IEC Directives, Part 2.
The 2022 revision reorganised controls from 114 across 14 domains into 93 controls across four thematic groupings — Organisational, People, Physical, and Technological. Eleven controls are new to the 2022 edition. All controls are referenced in the Statement of Applicability (SoA) with implementation justification.
The table below maps key ISO/IEC 27001:2022 clauses to their mandatory requirements, prescriptive language, and UNUS London's fulfilment status. Conformance language follows ISO/IEC Directives, Part 2 — "shall" denotes a requirement; "should" a recommendation.
| Clause Ref. | Requirement (shall) | ISMS Domain | UNUS Status |
|---|---|---|---|
| Cl. 4.2 | The organisation shall determine the interested parties that are relevant to the ISMS and their requirements relevant to information security. | Context | Fully Met |
| Cl. 4.3 | The organisation shall determine the boundaries and applicability of the ISMS and shall document the scope, including justified exclusions. | Scope | Fully Met |
| Cl. 5.2 | Top management shall establish an information security policy that is appropriate to the purpose of the organisation, includes information security objectives, and is available as documented information. | Policy | Fully Met |
| Cl. 6.1.2 | The organisation shall define and apply an information security risk assessment process that identifies risks associated with the loss of confidentiality, integrity, and availability of information. | Risk Assessment | Fully Met |
| Cl. 6.1.3 | The organisation shall produce a Statement of Applicability that includes the necessary controls, justification for inclusions, and justification for exclusions of Annex A controls. | Statement of Applicability | Fully Met |
| Cl. 7.5 | The organisation shall maintain and retain documented information required by this standard, including evidence of the results of risk assessments and the risk treatment plan. | Documented Information | Fully Met |
| Cl. 8.2 | The organisation shall perform information security risk assessments at planned intervals or when significant changes occur, and shall retain documented information of the risk assessment results. | Operational Risk | Fully Met |
| Cl. 8.3 | The organisation shall implement the information security risk treatment plan and retain documented information of the results of the risk treatment. | Risk Treatment | Fully Met |
| Cl. 9.1 | The organisation shall evaluate the information security performance and the effectiveness of the ISMS, and shall retain documented information as evidence of the monitoring and measurement results. | Performance Evaluation | Fully Met |
| Cl. 9.2 | The organisation shall conduct internal ISMS audits at planned intervals to determine whether the ISMS conforms to the requirements of this standard and is effectively implemented and maintained. | Internal Audit | Fully Met |
| Cl. 10.1 | When a nonconformity occurs, the organisation shall take action to control and correct it, evaluate the need for corrective action, and retain documented information as evidence of results. | Corrective Action | Partial — Config Req. |
| A.5.7 | Information relating to information security threats shall be collected and analysed to produce threat intelligence. This intelligence shall be used in the risk assessment process. | Threat Intelligence | Advisory Review |
| A.8.8 | Information about technical vulnerabilities of information systems in use shall be obtained in a timely fashion. The organisation's exposure to such vulnerabilities shall be evaluated and appropriate measures taken. | Vulnerability Mgmt | Fully Met |
Each component of the UNUS London compliance infrastructure maps directly to one or more clauses or Annex A controls of the standard. The following cards detail exact system capabilities and the requirements they address.
A production PostgreSQL schema implements the information security risk register required under Clause 6.1.2. Every identified risk is stored with asset reference, threat source, vulnerability, likelihood, impact, risk score, risk owner, and treatment decision.
likelihood_score × impact_score = risk_ratingThe SoA module maintains a database record for every Annex A control — all 93 — with inclusion/exclusion status, implementation justification, implementation evidence reference, and responsible owner. The SoA document is generated on-demand as a timestamped output from the database.
implemented | partial | planned | excluded | not_applicableThe risk treatment module links each identified risk to its treatment decision (accept, mitigate, transfer, avoid), the specific Annex A controls applied, implementation status, target completion date, and evidence of treatment. Treatment records satisfy Clause 8.3 documented information requirements.
All documented information required by ISO/IEC 27001:2022 is stored in the PostgreSQL evidence repository with version control, access logging, and immutable change history. This satisfies Clause 7.5 requirements for maintaining and retaining documented information as conformance evidence.
Scheduled n8n workflows execute ISMS internal audit queries at configured intervals, producing conformance evidence packs and audit findings records that satisfy Clause 9.2. Every audit execution is logged with scope, methodology, findings, and corrective actions raised.
isms_audit_findings table with severity and ownerThe vulnerability management module satisfies Annex A control A.8.8 by maintaining a structured register of known technical vulnerabilities, their severity scores (CVSS-aligned), affected assets, remediation status, and evidence of remediation. Scheduled scans feed automated database records.
The following represent the three most prevalent and highest-risk failures identified during ISO/IEC 27001 certification audits. Each is a common reason organisations fail external certification or receive major nonconformities. UNUS London's database-first architecture resolves all three structurally.
isms_audit_record row with scope, methodology, findings, auditor
identity, and timestamp. After three consecutive quarters, the organisation has an evidenced
systematic programme — a pattern of conformance, not a single data point. The audit schedule is
itself a documented information artefact, satisfying the planning sub-requirement of Cl. 9.2.
When a certification body auditor or regulator requests evidence of information security conformance, the UNUS London system produces structured, timestamped records in seconds. The following illustrates a live ISMS evidence retrieval session against the compliance database.
The UNUS London ISMS system achieves a composite readiness score of 94/100 against ISO/IEC 27001:2022. Scores are calculated across seven assessment dimensions using weighted clause and Annex A control coverage.
UNUS London delivers a production-ready ISMS aligned to ISO/IEC 27001:2022 within a 21-day structured deployment programme. All deliverables — including database schemas, workflow automations, and documentation templates — are transferred with full code ownership.
ISO/IEC 27001:2022 requires a continuously maintained Information Security Management System — not a one-time evidence pack you generate for the audit and forget. UNUS Govern is the operational wrapper that turns your ISMS from a point-in-time deliverable into a continuously-evidenced system. Statement of Applicability stays current. Risk treatment plan tracks drift in real time. Annex A controls remain mapped to your live schema. The 27001 evidence layer is always audit-ready — not just before surveillance.
Part of UNUS Govern's continuous evidence layer.
Available as a monthly subscription. Cancel anytime.
A 60-minute discovery call establishes your current information security posture, identifies your critical nonconformities against the 2022 edition, and scopes exactly what will be built and transferred to you — including the Statement of Applicability, risk register, and internal audit programme. No sales pitch — a structured technical assessment.