Skip to content
ISMS program · not a certificate

ISO/IEC 27001 readiness with a real SoA

We prepare an Information Security Management System against ISO/IEC 27001:2022 — clauses 4–10 plus Annex A controls — and publish our draft Statement of Applicability. This page is readiness tracking only. It does not mean PhishGuard is ISO 27001 certified.

Honest claim language

This Statement of Applicability is an internal readiness draft. It is NOT an ISO 27001 certificate. Certification requires an accredited certification body audit after ISMS operation and Stage 1/2 audits.

Combined score

52.1%

Avg of Annex A + ISMS clauses

Annex A

50.5%

86 applicable of 93

ISMS clauses

53.6%

25 requirements tracked

Status mix (Annex A)

In progress: 13Planned: 32Implemented: 41Evidenced: 0N/A: 7

Draft ISMS scope

Information security management for the PhishGuard SaaS product: design, development, operation, and support of phishing simulation and awareness analytics for Google Workspace organizations, primarily serving Canadian customers.

In scope

  • ·PhishGuard web application and admin console
  • ·Customer tenant data processed for phishing simulations and reporting
  • ·Google Workspace integration credentials and sync processes
  • ·Supporting cloud hosting, CI/CD, and identity services used to deliver the product
  • ·Personnel (founder and future staff/contractors) with access to production systems or customer data

Out of scope / shared

  • ·Customer-managed Google Workspace environments beyond PhishGuard-authorized integrations
  • ·Employee personal devices not used for PhishGuard administration (until BYOD policy expands)
  • ·Physical data centre facilities operated by cloud providers (treated as supplier / shared responsibility)

ISMS clauses (4–10)

Management system requirements — the part auditors check before Annex A detail.

ClauseRequirementGroupStatusNotes
4.1Understanding the organization and its contextContext of the organizationImplementedContext documented in SoA + privacy program
4.2Understanding the needs and expectations of interested partiesContext of the organizationImplementedInterested parties in privacy policy + SoA
4.3Determining the scope of the information security management systemContext of the organizationImplementedISMS scope in SoA
4.4Information security management systemContext of the organizationIn progressISMS docs established; operate cadence ongoing
5.1Leadership and commitmentLeadershipImplementedTop management approved IS policy
5.2PolicyLeadershipImplementedInformation security policy published internally
5.3Organizational roles, responsibilities and authoritiesLeadershipImplementedRoles documented in access inventory
6.1Actions to address risks and opportunitiesPlanningIn progressRisk via remediation playbook + SoA
6.1.2Information security risk assessmentPlanningPlannedRisk assessment methodology
6.1.3Information security risk treatmentPlanningImplementedRisk treatment via SoA draft
6.2Information security objectives and planning to achieve themPlanningIn progressObjectives: no credential capture, dry-run default, deletion SLAs
6.3Planning of changesPlanningPlannedISMS change planning
7.1ResourcesSupportImplementedResources: founder + tooling documented
7.2CompetenceSupportPlannedCompetence matrix
7.3AwarenessSupportIn progressAwareness via AUP acknowledgment requirement
7.4CommunicationSupportImplementedExternal security/privacy communications live
7.5Documented informationSupportImplementedDocumented information under docs/iso27001 and legal pages
8.1Operational planning and controlOperationImplementedOperational procedures documented
8.2Information security risk assessmentOperationPlannedPeriodic risk assessment cadence
8.3Information security risk treatmentOperationPlannedExecute risk treatment plan
9.1Monitoring, measurement, analysis and evaluationPerformance evaluationImplementedSelf-assessment cadence + CI metrics
9.2Internal auditPerformance evaluationPlannedInternal audit before certification
9.3Management reviewPerformance evaluationImplementedManagement review cadence in self-assessment (annual/quarterly hooks)
10.1Continual improvementImprovementPlannedContinual improvement log
10.2Nonconformity and corrective actionImprovementPlannedCorrective action process

Annex A controls

93 controls across Organizational, People, Physical, and Technological themes. Titles follow ISO/IEC 27001:2022 for tracking; full normative text is in the official standard.

Organizational

63.9% · 37 controls

IDControlStatusNotes
A.5.1Policies for information securityImplementedInformation security policy v0.1
A.5.2Information security roles and responsibilitiesImplementedRoles: founder security lead; access inventory
A.5.3Segregation of dutiesPlannedSegregation as team grows; founder dual-role accepted short-term
A.5.4Management responsibilitiesImplementedLeadership approval of security policy
A.5.5Contact with authoritiesImplementedAuthority contacts list (OPC, provincial, LE)
A.5.6Contact with special interest groupsPlannedIncluded in ISMS roadmap; not yet detailed
A.5.7Threat intelligencePlannedThreat intel light process for phishing landscape
A.5.8Information security in project managementPlannedIncluded in ISMS roadmap; not yet detailed
A.5.9Inventory of information and other associated assetsImplementedAsset/systems inventory
A.5.10Acceptable use of information and other associated assetsImplementedAcceptable use policy v0.1
A.5.11Return of assetsPlannedIncluded in ISMS roadmap; not yet detailed
A.5.12Classification of informationImplementedData classification policy
A.5.13Labelling of informationIn progressLabeling guidance in classification policy
A.5.14Information transferIn progressCustomer data transfer via TLS; DPA-style pilot terms
A.5.15Access controlImplementedAccess control policy + app roles
A.5.16Identity managementImplementedIdentity lifecycle via access policy + inventory
A.5.17Authentication informationImplementedMFA and authentication policy
A.5.18Access rightsImplementedAccess rights review log started
A.5.19Information security in supplier relationshipsImplementedVendor policy + control map for all categories
A.5.20Addressing information security within supplier agreementsImplementedSecurity requirements in supplier agreements — contract control map + checklist + DPA flow-down
A.5.21Managing information security in the ICT supply chainImplementedICT supply chain + subprocessor notification + ISO control map
A.5.22Monitoring, review and change management of supplier servicesImplementedSupplier monitoring + change via subprocessor changelog, annual review, ISO control map
A.5.23Information security for use of cloud servicesImplementedCloud use documented in subprocessors + privacy
A.5.24Information security incident management planning and preparationImplementedIR plan v0.1
A.5.25Assessment and decision on information security eventsImplementedEvent triage/severity in IR plan
A.5.26Response to information security incidentsImplementedIncident response steps documented
A.5.27Learning from information security incidentsImplementedPost-incident learning requirement
A.5.28Collection of evidenceIn progressEvidence preservation in IR plan
A.5.29Information security during disruptionImplementedSecurity during disruption — BC pilot playbook
A.5.30ICT readiness for business continuityImplementedICT readiness / BC for pilot support
A.5.31Legal, statutory, regulatory and contractual requirementsImplementedLegal/privacy requirements via privacy policy + terms
A.5.32Intellectual property rightsPlannedIncluded in ISMS roadmap; not yet detailed
A.5.33Protection of recordsIn progressRecords protection via retention + backups + contracts
A.5.34Privacy and protection of PIIImplementedPrivacy policy + PIMS program
A.5.35Independent review of information securityPlannedIndependent review / pen test before scale
A.5.36Compliance with policies, rules and standards for information securityImplementedCompliance automation in CI
A.5.37Documented operating proceduresImplementedOperating procedures for deploy, live-send, offboarding

People

26.9% · 8 controls

IDControlStatusNotes
A.6.1ScreeningPlannedIncluded in ISMS roadmap; not yet detailed
A.6.2Terms and conditions of employmentPlannedEmployment / contractor security terms
A.6.3Information security awareness, education and trainingPlannedInternal security awareness
A.6.4Disciplinary processPlannedIncluded in ISMS roadmap; not yet detailed
A.6.5Responsibilities after termination or change of employmentPlannedIncluded in ISMS roadmap; not yet detailed
A.6.6Confidentiality or non-disclosure agreementsPlannedNDAs for contractors/advisors
A.6.7Remote workingIn progressRemote work via device security checklist
A.6.8Information security event reportingImplementedsecurity@ / privacy@ reporting channels published

Physical

23.6% · 14 controls

IDControlStatusNotes
A.7.1Physical security perimetersN/ANo owned data centre; cloud provider physical perimeter
A.7.2Physical entryN/APhysical entry at cloud DC is provider-controlled; document reliance
A.7.3Securing offices, rooms and facilitiesPlannedHome/office physical baseline for founder devices
A.7.4Physical security monitoringN/ACloud DC monitoring is provider control — document in SoA
A.7.5Protecting against physical and environmental threatsN/AProvider environmental controls; document reliance
A.7.6Working in secure areasN/ANo secure areas operated by PhishGuard
A.7.7Clear desk and clear screenIn progressClear desk/screen on device checklist
A.7.8Equipment siting and protectionPlannedEndpoint siting for laptops
A.7.9Security of assets off-premisesIn progressOff-premises device controls on checklist
A.7.10Storage mediaPlannedMedia lifecycle (USB policy)
A.7.11Supporting utilitiesN/AUtilities at cloud DC — provider
A.7.12Cabling securityN/ACabling at cloud DC — provider
A.7.13Equipment maintenancePlannedEndpoint maintenance / patching
A.7.14Secure disposal or re-use of equipmentPlannedSecure disposal of devices

Technological

47.1% · 34 controls

IDControlStatusNotes
A.8.1User endpoint devicesIn progressEndpoint device checklist
A.8.2Privileged access rightsImplementedPrivileged access inventory + MFA policy
A.8.3Information access restrictionImplementedAccess restriction + tenant isolation design
A.8.4Access to source codeImplementedSource access via GitHub admin inventory
A.8.5Secure authenticationImplementedSecure authentication + MFA policy
A.8.6Capacity managementPlannedCapacity for directory sync / send
A.8.7Protection against malwareIn progressMalware protection on device checklist
A.8.8Management of technical vulnerabilitiesIn progressnpm audit in CI
A.8.9Configuration managementPlannedConfiguration baselines
A.8.10Information deletionImplementedDeletion runbook
A.8.11Data maskingPlannedMasking in non-prod if needed
A.8.12Data leakage preventionImplementedNo credential harvest + export controls design
A.8.13Information backupImplementedBackup procedure documented
A.8.14Redundancy of information processing facilitiesPlannedPlatform redundancy via host
A.8.15LoggingPlannedApplication logging
A.8.16Monitoring activitiesPlannedMonitoring / alerting
A.8.17Clock synchronizationPlannedClock sync via platform
A.8.18Use of privileged utility programsPlannedIncluded in ISMS roadmap; not yet detailed
A.8.19Installation of software on operational systemsImplementedControlled deploy via CI
A.8.20Networks securityIn progressNetwork security via platform
A.8.21Security of network servicesPlannedNetwork service security requirements
A.8.22Segregation of networksPlannedNetwork segregation staging/prod
A.8.23Web filteringPlannedWeb filtering on admin endpoints if needed
A.8.24Use of cryptographyImplementedCrypto/secrets policy v0.1
A.8.25Secure development life cycleImplementedSecure SDLC policy + CI
A.8.26Application security requirementsImplementedApp security requirements: dry-run, isolation, no password capture
A.8.27Secure system architecture and engineering principlesImplementedSecure architecture: tenant isolation design
A.8.28Secure codingImplementedSecure coding + compliance scanners
A.8.29Security testing in development and acceptancePlannedSecurity testing in pipeline
A.8.30Outsourced developmentPlannedOversight of any outsourced development
A.8.31Separation of development, test and production environmentsIn progressStaging/prod separation planned in SDLC policy
A.8.32Change managementImplementedChange management via git + CI
A.8.33Test informationIn progressDemo uses synthetic data; protect real test tenants
A.8.34Protection of information systems during audit testingPlannedProtect systems during audit testing

Path to certification

  1. 01

    Operate the ISMS

  2. 02

    Internal audit

  3. 03

    Management review

  4. 04

    Stage 1 audit

  5. 05

    Stage 2 → certificate

Certificates are issued only by an accredited certification body. We will never claim “ISO 27001 certified” until that happens.

Need the interim security pack?

Scope, SoA draft, privacy notes, and honest attestation status — without fake certificates.

ISO/IEC 27001 is a standard of ISO/IEC. Purchase the official document for full requirements. iso.org