ISO/IEC 27001 readiness with a real SoA
We prepare an Information Security Management System against ISO/IEC 27001:2022 — clauses 4–10 plus Annex A controls — and publish our draft Statement of Applicability. This page is readiness tracking only. It does not mean PhishGuard is ISO 27001 certified.
Honest claim language
This Statement of Applicability is an internal readiness draft. It is NOT an ISO 27001 certificate. Certification requires an accredited certification body audit after ISMS operation and Stage 1/2 audits.
Combined score
52.1%
Avg of Annex A + ISMS clauses
Annex A
50.5%
86 applicable of 93
ISMS clauses
53.6%
25 requirements tracked
Status mix (Annex A)
Draft ISMS scope
Information security management for the PhishGuard SaaS product: design, development, operation, and support of phishing simulation and awareness analytics for Google Workspace organizations, primarily serving Canadian customers.
In scope
- ·PhishGuard web application and admin console
- ·Customer tenant data processed for phishing simulations and reporting
- ·Google Workspace integration credentials and sync processes
- ·Supporting cloud hosting, CI/CD, and identity services used to deliver the product
- ·Personnel (founder and future staff/contractors) with access to production systems or customer data
Out of scope / shared
- ·Customer-managed Google Workspace environments beyond PhishGuard-authorized integrations
- ·Employee personal devices not used for PhishGuard administration (until BYOD policy expands)
- ·Physical data centre facilities operated by cloud providers (treated as supplier / shared responsibility)
ISMS clauses (4–10)
Management system requirements — the part auditors check before Annex A detail.
| Clause | Requirement | Group | Status | Notes |
|---|---|---|---|---|
| 4.1 | Understanding the organization and its context | Context of the organization | Implemented | Context documented in SoA + privacy program |
| 4.2 | Understanding the needs and expectations of interested parties | Context of the organization | Implemented | Interested parties in privacy policy + SoA |
| 4.3 | Determining the scope of the information security management system | Context of the organization | Implemented | ISMS scope in SoA |
| 4.4 | Information security management system | Context of the organization | In progress | ISMS docs established; operate cadence ongoing |
| 5.1 | Leadership and commitment | Leadership | Implemented | Top management approved IS policy |
| 5.2 | Policy | Leadership | Implemented | Information security policy published internally |
| 5.3 | Organizational roles, responsibilities and authorities | Leadership | Implemented | Roles documented in access inventory |
| 6.1 | Actions to address risks and opportunities | Planning | In progress | Risk via remediation playbook + SoA |
| 6.1.2 | Information security risk assessment | Planning | Planned | Risk assessment methodology |
| 6.1.3 | Information security risk treatment | Planning | Implemented | Risk treatment via SoA draft |
| 6.2 | Information security objectives and planning to achieve them | Planning | In progress | Objectives: no credential capture, dry-run default, deletion SLAs |
| 6.3 | Planning of changes | Planning | Planned | ISMS change planning |
| 7.1 | Resources | Support | Implemented | Resources: founder + tooling documented |
| 7.2 | Competence | Support | Planned | Competence matrix |
| 7.3 | Awareness | Support | In progress | Awareness via AUP acknowledgment requirement |
| 7.4 | Communication | Support | Implemented | External security/privacy communications live |
| 7.5 | Documented information | Support | Implemented | Documented information under docs/iso27001 and legal pages |
| 8.1 | Operational planning and control | Operation | Implemented | Operational procedures documented |
| 8.2 | Information security risk assessment | Operation | Planned | Periodic risk assessment cadence |
| 8.3 | Information security risk treatment | Operation | Planned | Execute risk treatment plan |
| 9.1 | Monitoring, measurement, analysis and evaluation | Performance evaluation | Implemented | Self-assessment cadence + CI metrics |
| 9.2 | Internal audit | Performance evaluation | Planned | Internal audit before certification |
| 9.3 | Management review | Performance evaluation | Implemented | Management review cadence in self-assessment (annual/quarterly hooks) |
| 10.1 | Continual improvement | Improvement | Planned | Continual improvement log |
| 10.2 | Nonconformity and corrective action | Improvement | Planned | Corrective action process |
Annex A controls
93 controls across Organizational, People, Physical, and Technological themes. Titles follow ISO/IEC 27001:2022 for tracking; full normative text is in the official standard.
Organizational
63.9% · 37 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| A.5.1 | Policies for information security | Implemented | Information security policy v0.1 |
| A.5.2 | Information security roles and responsibilities | Implemented | Roles: founder security lead; access inventory |
| A.5.3 | Segregation of duties | Planned | Segregation as team grows; founder dual-role accepted short-term |
| A.5.4 | Management responsibilities | Implemented | Leadership approval of security policy |
| A.5.5 | Contact with authorities | Implemented | Authority contacts list (OPC, provincial, LE) |
| A.5.6 | Contact with special interest groups | Planned | Included in ISMS roadmap; not yet detailed |
| A.5.7 | Threat intelligence | Planned | Threat intel light process for phishing landscape |
| A.5.8 | Information security in project management | Planned | Included in ISMS roadmap; not yet detailed |
| A.5.9 | Inventory of information and other associated assets | Implemented | Asset/systems inventory |
| A.5.10 | Acceptable use of information and other associated assets | Implemented | Acceptable use policy v0.1 |
| A.5.11 | Return of assets | Planned | Included in ISMS roadmap; not yet detailed |
| A.5.12 | Classification of information | Implemented | Data classification policy |
| A.5.13 | Labelling of information | In progress | Labeling guidance in classification policy |
| A.5.14 | Information transfer | In progress | Customer data transfer via TLS; DPA-style pilot terms |
| A.5.15 | Access control | Implemented | Access control policy + app roles |
| A.5.16 | Identity management | Implemented | Identity lifecycle via access policy + inventory |
| A.5.17 | Authentication information | Implemented | MFA and authentication policy |
| A.5.18 | Access rights | Implemented | Access rights review log started |
| A.5.19 | Information security in supplier relationships | Implemented | Vendor policy + control map for all categories |
| A.5.20 | Addressing information security within supplier agreements | Implemented | Security requirements in supplier agreements — contract control map + checklist + DPA flow-down |
| A.5.21 | Managing information security in the ICT supply chain | Implemented | ICT supply chain + subprocessor notification + ISO control map |
| A.5.22 | Monitoring, review and change management of supplier services | Implemented | Supplier monitoring + change via subprocessor changelog, annual review, ISO control map |
| A.5.23 | Information security for use of cloud services | Implemented | Cloud use documented in subprocessors + privacy |
| A.5.24 | Information security incident management planning and preparation | Implemented | IR plan v0.1 |
| A.5.25 | Assessment and decision on information security events | Implemented | Event triage/severity in IR plan |
| A.5.26 | Response to information security incidents | Implemented | Incident response steps documented |
| A.5.27 | Learning from information security incidents | Implemented | Post-incident learning requirement |
| A.5.28 | Collection of evidence | In progress | Evidence preservation in IR plan |
| A.5.29 | Information security during disruption | Implemented | Security during disruption — BC pilot playbook |
| A.5.30 | ICT readiness for business continuity | Implemented | ICT readiness / BC for pilot support |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | Implemented | Legal/privacy requirements via privacy policy + terms |
| A.5.32 | Intellectual property rights | Planned | Included in ISMS roadmap; not yet detailed |
| A.5.33 | Protection of records | In progress | Records protection via retention + backups + contracts |
| A.5.34 | Privacy and protection of PII | Implemented | Privacy policy + PIMS program |
| A.5.35 | Independent review of information security | Planned | Independent review / pen test before scale |
| A.5.36 | Compliance with policies, rules and standards for information security | Implemented | Compliance automation in CI |
| A.5.37 | Documented operating procedures | Implemented | Operating procedures for deploy, live-send, offboarding |
People
26.9% · 8 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| A.6.1 | Screening | Planned | Included in ISMS roadmap; not yet detailed |
| A.6.2 | Terms and conditions of employment | Planned | Employment / contractor security terms |
| A.6.3 | Information security awareness, education and training | Planned | Internal security awareness |
| A.6.4 | Disciplinary process | Planned | Included in ISMS roadmap; not yet detailed |
| A.6.5 | Responsibilities after termination or change of employment | Planned | Included in ISMS roadmap; not yet detailed |
| A.6.6 | Confidentiality or non-disclosure agreements | Planned | NDAs for contractors/advisors |
| A.6.7 | Remote working | In progress | Remote work via device security checklist |
| A.6.8 | Information security event reporting | Implemented | security@ / privacy@ reporting channels published |
Physical
23.6% · 14 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| A.7.1 | Physical security perimeters | N/A | No owned data centre; cloud provider physical perimeter |
| A.7.2 | Physical entry | N/A | Physical entry at cloud DC is provider-controlled; document reliance |
| A.7.3 | Securing offices, rooms and facilities | Planned | Home/office physical baseline for founder devices |
| A.7.4 | Physical security monitoring | N/A | Cloud DC monitoring is provider control — document in SoA |
| A.7.5 | Protecting against physical and environmental threats | N/A | Provider environmental controls; document reliance |
| A.7.6 | Working in secure areas | N/A | No secure areas operated by PhishGuard |
| A.7.7 | Clear desk and clear screen | In progress | Clear desk/screen on device checklist |
| A.7.8 | Equipment siting and protection | Planned | Endpoint siting for laptops |
| A.7.9 | Security of assets off-premises | In progress | Off-premises device controls on checklist |
| A.7.10 | Storage media | Planned | Media lifecycle (USB policy) |
| A.7.11 | Supporting utilities | N/A | Utilities at cloud DC — provider |
| A.7.12 | Cabling security | N/A | Cabling at cloud DC — provider |
| A.7.13 | Equipment maintenance | Planned | Endpoint maintenance / patching |
| A.7.14 | Secure disposal or re-use of equipment | Planned | Secure disposal of devices |
Technological
47.1% · 34 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| A.8.1 | User endpoint devices | In progress | Endpoint device checklist |
| A.8.2 | Privileged access rights | Implemented | Privileged access inventory + MFA policy |
| A.8.3 | Information access restriction | Implemented | Access restriction + tenant isolation design |
| A.8.4 | Access to source code | Implemented | Source access via GitHub admin inventory |
| A.8.5 | Secure authentication | Implemented | Secure authentication + MFA policy |
| A.8.6 | Capacity management | Planned | Capacity for directory sync / send |
| A.8.7 | Protection against malware | In progress | Malware protection on device checklist |
| A.8.8 | Management of technical vulnerabilities | In progress | npm audit in CI |
| A.8.9 | Configuration management | Planned | Configuration baselines |
| A.8.10 | Information deletion | Implemented | Deletion runbook |
| A.8.11 | Data masking | Planned | Masking in non-prod if needed |
| A.8.12 | Data leakage prevention | Implemented | No credential harvest + export controls design |
| A.8.13 | Information backup | Implemented | Backup procedure documented |
| A.8.14 | Redundancy of information processing facilities | Planned | Platform redundancy via host |
| A.8.15 | Logging | Planned | Application logging |
| A.8.16 | Monitoring activities | Planned | Monitoring / alerting |
| A.8.17 | Clock synchronization | Planned | Clock sync via platform |
| A.8.18 | Use of privileged utility programs | Planned | Included in ISMS roadmap; not yet detailed |
| A.8.19 | Installation of software on operational systems | Implemented | Controlled deploy via CI |
| A.8.20 | Networks security | In progress | Network security via platform |
| A.8.21 | Security of network services | Planned | Network service security requirements |
| A.8.22 | Segregation of networks | Planned | Network segregation staging/prod |
| A.8.23 | Web filtering | Planned | Web filtering on admin endpoints if needed |
| A.8.24 | Use of cryptography | Implemented | Crypto/secrets policy v0.1 |
| A.8.25 | Secure development life cycle | Implemented | Secure SDLC policy + CI |
| A.8.26 | Application security requirements | Implemented | App security requirements: dry-run, isolation, no password capture |
| A.8.27 | Secure system architecture and engineering principles | Implemented | Secure architecture: tenant isolation design |
| A.8.28 | Secure coding | Implemented | Secure coding + compliance scanners |
| A.8.29 | Security testing in development and acceptance | Planned | Security testing in pipeline |
| A.8.30 | Outsourced development | Planned | Oversight of any outsourced development |
| A.8.31 | Separation of development, test and production environments | In progress | Staging/prod separation planned in SDLC policy |
| A.8.32 | Change management | Implemented | Change management via git + CI |
| A.8.33 | Test information | In progress | Demo uses synthetic data; protect real test tenants |
| A.8.34 | Protection of information systems during audit testing | Planned | Protect systems during audit testing |
Path to certification
- 01
Operate the ISMS
- 02
Internal audit
- 03
Management review
- 04
Stage 1 audit
- 05
Stage 2 → certificate
Certificates are issued only by an accredited certification body. We will never claim “ISO 27001 certified” until that happens.
Need the interim security pack?
Scope, SoA draft, privacy notes, and honest attestation status — without fake certificates.
ISO/IEC 27001 is a standard of ISO/IEC. Purchase the official document for full requirements. iso.org