Search SecureTrace

Jump to a file, transfer or page

ISO/IEC 27001:2022 control mapping

Where each Annex A control is satisfied in the product, and where the evidence lives. This is the page you hand to the auditor first.

18 demonstrated5 partial2 production scope
Who received it
A.5.15 · A.5.19 · A.8.15

Recipients are named individuals in the vendor registry, identity-verified by OTP before access. Every open and download is attributed to a person, IP and device.

Whether they should have
A.5.12 · A.5.14 · A.5.20 · A.8.3

Classification ceilings per vendor tier and NDA validity are checked before the link exists. Confidential and above require a documented manager approval.

What happens afterwards
A.5.18 · A.8.10 · A.8.12 · A.8.16

Links expire, downloads are capped, access is revocable in one click, and retention schedules drive disposal. Forward and print attempts are refused and logged.

ControlAnnex A titleImplementation in SecureTraceDemo
A.5.10Acceptable use of information and other associated assetsHandling acknowledgement gate before any vendor downloadOpen
A.5.11Return of assetsDestruction of vendor-side copies is requested at expiry and tracked to confirmationOpen
A.5.12Classification of informationClassification is mandatory at upload — files cannot exist unclassifiedOpen
A.5.13Labelling of informationPersistent classification badge plus identity watermark on every previewOpen
A.5.14Information transferTransfer wizard enforcing purpose, recipient rules, agreement and approvalOpen
A.5.15Access controlPer-recipient policy: view-only, download ceiling, domain lock, expiryOpen
A.5.16Identity managementRecipients are named, verified individuals in the vendor registry — never a shared linkOpen
A.5.18Access rightsExpiry, download ceilings and one-click revocation of an issued linkOpen
A.5.19Information security in supplier relationshipsVendor registry with risk tier and scheduled security reviewOpen
A.5.20Addressing information security within supplier agreementsNDA validity checked before a transfer can be created — expired NDA blocks the sendOpen
A.5.21Managing information security in the ICT supply chainApplies to the platform's own hosting and sub-processors, not to the design vendors — production scope, not shown hereOpen
A.5.22Monitoring, review and change management of supplier servicesPer-vendor transfer history, blocked-event attribution and review schedulingOpen
A.5.23Information security for use of cloud servicesThe reason this product exists: a sanctioned, governed channel that removes the need for unapproved consumer cloud storage, with endpoint DLP signals ingested as evidenceOpen
A.5.28Collection of evidenceHash-sealed evidence pack export per transfer and across the whole logOpen
A.5.32Intellectual property rightsProprietary design data is classified, watermarked to the recipient and released only under a current agreementOpen
A.5.33Protection of recordsAppend-only audit log, integrity-sealed and not deletable by any roleOpen
A.5.34Privacy and protection of PIIPII flag on classification; PII files restricted from release to lower-tier vendorsOpen
A.8.3Information access restrictionClassification ceiling per vendor tier; releases above the ceiling are refused unless an ISMS exception is recordedOpen
A.8.5Secure authenticationOne-time code to the registered address before a recipient can open anythingOpen
A.8.7Protection against malwareFiles scanned on upload and on the vendor return channel before releaseOpen
A.8.10Information deletionRetention schedule per file and post-expiry disposal queueOpen
A.8.12Data leakage preventionForward, print and out-of-policy send attempts are refused and loggedOpen
A.8.15LoggingEvery event captures actor, timestamp, IP, device and locationOpen
A.8.16Monitoring activitiesAnomaly detection on download velocity and geography, surfaced on the dashboardOpen
A.8.24Use of cryptographyEncryption in transit and at rest, and key management — required in production, represented rather than performed in this prototypeOpen

Mapping is indicative for this proposal and is not a statement of certification. Control identifiers and titles are quoted from ISO/IEC 27001:2022 Annex A; the claim that a given feature satisfies a control is ours, and final scope and applicability must be confirmed with the organisation's ISMS manager and lead auditor in the Statement of Applicability.