M ManySignal

Compliance — ISO 27001:2022

ISO 27001:2022 monitoring evidence — Annex A covered

ISO 27001:2022 added 11 new controls including A.8.16 (Monitoring Activities) and A.5.7 (Threat Intelligence). ManySignal provides machine-verifiable evidence for every Annex A control it addresses — continuous, auditor-readable, and integrated with GRC platforms.

ISO 27001:2022 — key changes from 2013

11 new controls

ISO 27001:2022 restructured 114 controls into 93 and added 11 new ones. The new controls include A.5.7 (Threat Intelligence), A.5.23 (Information Security for Cloud Services), A.8.16 (Monitoring), and A.8.12 (Data Leakage Prevention) — all directly addressed by ManySignal.

Annex A restructure

Controls are now grouped into 4 themes (Organizational, People, Physical, Technological) rather than 14 domains. ManySignal's control mapping is updated for the 2022 structure, covering the Technological controls (A.8) comprehensively.

Transition deadline

Organisations certified under ISO 27001:2013 must transition to ISO 27001:2022 by October 2025. ManySignal's mapping document is aligned to 2022, ensuring transition programmes have current-standard evidence.

Control mapping — ISO 27001:2022 Annex A to ManySignal

Control ReferenceControl NameManySignal Capability
A.8.15 Logging Centralised log collection from all in-scope systems — event logs, access logs, exception logs, and fault logs
A.8.16 Monitoring Activities Continuous monitoring of networks, systems, and applications — automated anomaly detection with machine-verifiable evidence
A.8.17 Clock Synchronisation NTP synchronisation anomaly detection — clock drift on monitored systems flagged immediately
A.5.25 Assessment and Decision on Information Security Events Triage agent evaluates every event — structured classification and evidence-based decision making
A.5.26 Response to Information Security Incidents Automated response playbooks, investigation management, and escalation workflows
A.5.27 Learning from Incidents Post-incident analysis and detection rule improvement integrated into the platform workflow
A.5.28 Collection of Evidence Tamper-evident evidence collection from incident start — entity timelines, access logs, and network flows preserved
A.8.12 Data Leakage Prevention Bulk data export detection, unusual egress volume monitoring, and unauthorised transmission alerting
A.5.7 Threat Intelligence Integrated threat intelligence feeds correlated with internal telemetry — IOC matching and actor attribution
A.6.8 Information Security Event Reporting Analyst portal with one-click incident report generation — ISO 27001 Annex A.6.8 evidence

Evidence export for certification body audits

Annex A evidence package

Per-control evidence export for the audit period. Each evidence package includes timestamped records of control operation, anomaly detection events, and incident management actions.

SoA support document

ManySignal provides a mapping document linking Annex A controls to platform capabilities and evidence types — for inclusion in your Statement of Applicability implementation documentation.

GRC integration

Push evidence to GRC platforms (ServiceNow, OneTrust, Archer, Vanta) via API — eliminating manual evidence collection for annual surveillance audits.

ManySignal certification status

ManySignal's ISO 27001:2022 certification is in progress with a target completion date of Q3 2025. SOC 2 Type II report available under NDA at trust@manysignal.com. Current certification status and the draft Statement of Applicability are available to customers under NDA.

ISO 27001 compliance — common questions

Does ManySignal itself hold ISO 27001 certification?

ManySignal's ISO 27001:2022 certification is in progress. Our Statement of Applicability and current certification status are available at trust@manysignal.com. In the interim, ManySignal's SOC 2 Type II report (available under NDA) covers the equivalent security controls with independent auditor verification.

How does ManySignal address the new ISO 27001:2022 controls not in the 2013 version?

ISO 27001:2022 added 11 new controls versus the 2013 version — including A.5.7 (Threat Intelligence), A.8.16 (Monitoring Activities), and A.8.12 (Data Leakage Prevention). ManySignal addresses all 11 new controls: threat intelligence integration (A.5.7), continuous monitoring evidence (A.8.16), and DLP-class data egress monitoring (A.8.12). These are areas where many ISMS programmes previously had gaps.

Can ManySignal integrate with our ISMS documentation and risk register?

ManySignal can push incident data and risk indicator data to GRC platforms (ServiceNow GRC, OneTrust, Archer) via API. This allows the ISMS risk register to be updated with real-world threat intelligence and incident data — improving risk assessment accuracy and reducing the gap between documented risk and operational reality.

How does ManySignal support ISO 27001 internal audit evidence?

ManySignal generates audit evidence packages covering: A.8.15 (logging) with a complete log collection coverage report, A.8.16 (monitoring) with timestamped detection event records for the audit period, and A.5.25-5.28 (incident management) with case lifecycle evidence. Internal auditors can access the evidence portal directly without requiring your security team's involvement in evidence collection.

Does ManySignal support Statement of Applicability (SoA) documentation?

ManySignal provides a mapping document linking each ISO 27001:2022 Annex A control to the specific ManySignal capability that addresses it, along with the evidence type available. This document can be incorporated into the SoA's Justification for Inclusion column for controls ManySignal addresses, and into the implementation evidence for internal audits and certification body assessments.

See ISO 27001 evidence export in action

Walk through the Annex A control mapping, evidence package generation, and GRC platform integration — in one session with our compliance team.