This checklist provides a structured path for executing an ISO 27001:2022 audit within CISO Assistant, leveraging the platform's core "bootstrap" and "compliance" workflows.
Before launching the audit, you must define the organizational boundaries within the platform.
Create Your Domain: Set up a top-level Folder (e.g., "Corporate IT") to house your compliance efforts.1
Define the Perimeter: Create a Perimeter to strictly define the scope of your ISO 27001 certification (e.g., "Production SaaS Environment").1
Identify Assets: Populate your inventory with Primary Assets (e.g., Customer Data, Intellectual Property) and Supporting Assets (e.g., AWS Infrastructure, Employee Laptops).1
Initiate the formal audit process by linking the framework to your defined scope.
Import the Framework: Load the ISO 27001:2022 library into your environment (URN: urn:intuitem:risk:library:iso27001-2022).1
Create the Compliance Assessment: Generate a new audit container linked specifically to your Perimeter.1
Enable X-rays: Ensure the X-rays feature is active in global settings to catch quality issues (like missing evidence) in real-time.1
Transition from planning to active assessment by engaging your team.
Delegate via Assignments: From the Assignments page, select specific ISO controls and assign them to the relevant "Actors" (e.g., assign Cloud Controls to your DevOps Lead).1
Evidence Collection: Require all respondents to upload files or external URLs (e.g., links to backup logs or policy docs) directly to the Applied Controls.1
Review Process: Use the Review Responses link to see exactly what the respondent sees. You can then Close the requirement or Request Changes with specific feedback if the evidence is insufficient.1
Ensure your platform data matches your official SoA records. Based on your current spreadsheet, ensure the following critical Annex A controls are addressed:
Control 5.21 (ICT Supply Chain): Document incident management clauses in supplier contracts.2
Control 5.24 (Incident Management): Upload evidence of tabletop exercises or "wargaming" with executives.2
Control 5.33 (Protection of Records): Link your Data Retention Policy and document SharePoint RBAC configurations.2
Control 8.23 (Web Filtering): Document your use of Defender for blocking malicious content categories.2
Maintain the health of your certification through automated quality checks.
Run X-rays Analysis: Check the X-rays dashboard to identify "Compliant" requirements that are missing evidence or "Risk Scenarios" that lack linked assets.1
Apply Mapping: If you need to produce a SOC2 or NIST report later, use the Apply Mapping feature to "Map To" a new framework, reusing all the evidence you gathered for ISO 27001.1
The X-rays feature acts as your automated quality assurance layer. For an ISO 27001 audit, focusing on these specific rules ensures that your assessment is not just "complete" but "auditable" by external certification bodies.
The Check: Scans for any control marked as "Compliant" or "Partially Compliant" that lacks a linked file or URL.1
ISO 27001 Impact: Directly addresses the requirement for "documented information" as evidence of control effectiveness.
Action: Use the "Applied Controls" view to filter for items flagged by this X-ray and attach the missing policy or log extract.
The Check: Identifies risk scenarios that are not linked to at least one primary or supporting asset.1
ISO 27001 Impact: ISO 27001 requires risks to be associated with assets. A risk without an asset is considered "orphaned" and cannot be accurately valued.
Action: Revisit the Risk Assessment domain and link the identified scenario to the relevant infrastructure (e.g., linking a "Data Breach" scenario to your "Customer Database" asset).
The Check: Flags any "Applied Control" that has not been reviewed within its defined frequency (e.g., 90 days, 1 year).1
ISO 27001 Impact: Supports the "Continuous Improvement" (Clause 10) and "Internal Audit" (Clause 9.2) requirements.
Action: Update the review status of the control or re-assign it to the owner for a fresh validation.
The Check: Flags scenarios where the "Residual Risk" score is higher than the "Current Risk" score after controls are applied.1
ISO 27001 Impact: Highlights a logical error in your risk treatment plan. Controls should reduce or maintain risk levels, not increase them.
Action: Adjust the mitigation factors in your Risk Assessment or re-evaluate the effectiveness of the assigned controls.
The Check: Detects assessments, perimeters, or controls that do not have an assigned "Owner" or "Manager".1
ISO 27001 Impact: Vital for Clause 5.3 (Organizational roles, responsibilities, and authorities). Every security element must have a clear point of accountability.
Action: Assign a specific user or role to the object to clear the warning.
The Check: Identifies mandatory framework requirements that have no linked "Applied Controls."
ISO 27001 Impact: Essential for building your Statement of Applicability (SoA). If a control is "In Scope" but has no mapping, you have a security gap.
Action: Create a new Applied Control or link an existing organizational measure to the requirement.
Report Date: Jul 08, 2026
Scope: ISO 27001:2022 Audit (Production Perimeter)
This report summarizes the findings from the automated X-rays quality check within CISO Assistant, focusing on the current ISO 27001:2022 compliance posture. While the platform architecture supports "decoupling" and "map once, use many" efficiency, several critical data integrity gaps must be addressed prior to formal external certification.12
A. Evidence & Documentation Integrity
Finding: 12 requirements marked as "Compliant" lack linked evidence files or URLs.12
ISO 27001 Impact: Non-conformity with Clause 7.5 (Documented Information). Evidence is mandatory to prove control effectiveness to auditors.2
Required Action: Attach policy extracts (e.g., Secure Coding Policy) or system screenshots (e.g., Azure MFA logs) directly to the Applied Controls.13
B. Risk Management Logic
Finding: 3 scenarios identified where Residual Risk is higher than Current Risk.12
ISO 27001 Impact: Violation of Clause 6.1.2 (Information Security Risk Assessment). It is logically inconsistent for security controls to increase risk levels.2
Required Action: Re-evaluate the effectiveness ratings of applied controls within the Risk Assessment domain to ensure they correctly mitigate probability or impact.12
C. Accountability & Ownership
Finding: Several "Supporting Assets" (e.g., AWS Infrastructure) do not have assigned owners.12
ISO 27001 Impact: Non-compliance with Control A.5.9 (Inventory of Information and Other Associated Assets), which mandates clear ownership for all assets.23
Required Action: Assign technical leads as "Owners" in the Asset Management module to establish clear accountability.1
The following table reflects the current state of audit delegation within the platform:12
Assignment State
Action Required by Manager
Respondent Capability
Draft
Start individual or "Start All" assignments.1
In Progress
Monitor progress via the Review Responses link.12
Can assess requirements and upload evidence.1
Changes Requested
Provide specific feedback in the observation field.12
Must edit and re-submit for review.12
Submitted
Close to finalize or Request Changes.12
View-only (Assessment locked).12
Remediate "Compliant without Evidence" Warnings: This is the highest priority for the upcoming audit.12
Establish Periodic Reviews: Leverage the "Review Staleness" X-ray to ensure controls like A.5.24 (Incident Management) are reviewed annually.23
Formalize Supplier Reviews: Ensure all vendors in the Technology Portfolio have completed the Part 1 Supplier Questionnaire.3