Search SecureTrace
Jump to a file, transfer or page
ISO/IEC 27001:2022 control mapping
Where each Annex A control is satisfied in the product, and where the evidence lives. This is the page you hand to the auditor first.
18 demonstrated5 partial2 production scope
Scope of this mapping
25 of the 93 Annex A controls are in scope for this product. The rest — awareness training, physical security, business continuity, secure development — belong to the wider ISMS and no file-transfer tool can claim them. Controls marked production scope are real requirements that a prototype without a backend cannot demonstrate; they are listed so nothing is quietly omitted.
How this replaces consumer cloud storage
A Dropbox link fails audit on five points: no recorded recipient identity, no classification, no approval, no expiry or revocation, and no immutable log. Each row below closes one of those gaps and points to the screen that demonstrates it.
Mapping is indicative for this proposal and is not a statement of certification. Control identifiers and titles are quoted from ISO/IEC 27001:2022 Annex A; the claim that a given feature satisfies a control is ours, and final scope and applicability must be confirmed with the organisation's ISMS manager and lead auditor in the Statement of Applicability.