Compliance — ISO 27001:2022
ISO 27001:2022 monitoring evidence — Annex A covered
ISO 27001:2022 added 11 new controls including A.8.16 (Monitoring Activities) and A.5.7 (Threat Intelligence). ManySignal provides machine-verifiable evidence for every Annex A control it addresses — continuous, auditor-readable, and integrated with GRC platforms.
ISO 27001:2022 — key changes from 2013
11 new controls
ISO 27001:2022 restructured 114 controls into 93 and added 11 new ones. The new controls include A.5.7 (Threat Intelligence), A.5.23 (Information Security for Cloud Services), A.8.16 (Monitoring), and A.8.12 (Data Leakage Prevention) — all directly addressed by ManySignal.
Annex A restructure
Controls are now grouped into 4 themes (Organizational, People, Physical, Technological) rather than 14 domains. ManySignal's control mapping is updated for the 2022 structure, covering the Technological controls (A.8) comprehensively.
Transition deadline
Organisations certified under ISO 27001:2013 must transition to ISO 27001:2022 by October 2025. ManySignal's mapping document is aligned to 2022, ensuring transition programmes have current-standard evidence.
Control mapping — ISO 27001:2022 Annex A to ManySignal
| Control Reference | Control Name | ManySignal Capability |
|---|---|---|
| A.8.15 | Logging | Centralised log collection from all in-scope systems — event logs, access logs, exception logs, and fault logs |
| A.8.16 | Monitoring Activities | Continuous monitoring of networks, systems, and applications — automated anomaly detection with machine-verifiable evidence |
| A.8.17 | Clock Synchronisation | NTP synchronisation anomaly detection — clock drift on monitored systems flagged immediately |
| A.5.25 | Assessment and Decision on Information Security Events | Triage agent evaluates every event — structured classification and evidence-based decision making |
| A.5.26 | Response to Information Security Incidents | Automated response playbooks, investigation management, and escalation workflows |
| A.5.27 | Learning from Incidents | Post-incident analysis and detection rule improvement integrated into the platform workflow |
| A.5.28 | Collection of Evidence | Tamper-evident evidence collection from incident start — entity timelines, access logs, and network flows preserved |
| A.8.12 | Data Leakage Prevention | Bulk data export detection, unusual egress volume monitoring, and unauthorised transmission alerting |
| A.5.7 | Threat Intelligence | Integrated threat intelligence feeds correlated with internal telemetry — IOC matching and actor attribution |
| A.6.8 | Information Security Event Reporting | Analyst portal with one-click incident report generation — ISO 27001 Annex A.6.8 evidence |
Evidence export for certification body audits
Annex A evidence package
Per-control evidence export for the audit period. Each evidence package includes timestamped records of control operation, anomaly detection events, and incident management actions.
SoA support document
ManySignal provides a mapping document linking Annex A controls to platform capabilities and evidence types — for inclusion in your Statement of Applicability implementation documentation.
GRC integration
Push evidence to GRC platforms (ServiceNow, OneTrust, Archer, Vanta) via API — eliminating manual evidence collection for annual surveillance audits.
ManySignal certification status
ManySignal's ISO 27001:2022 certification is in progress with a target completion date of Q3 2025. SOC 2 Type II report available under NDA at trust@manysignal.com. Current certification status and the draft Statement of Applicability are available to customers under NDA.
ISO 27001 compliance — common questions
Does ManySignal itself hold ISO 27001 certification?
ManySignal's ISO 27001:2022 certification is in progress. Our Statement of Applicability and current certification status are available at trust@manysignal.com. In the interim, ManySignal's SOC 2 Type II report (available under NDA) covers the equivalent security controls with independent auditor verification.
How does ManySignal address the new ISO 27001:2022 controls not in the 2013 version?
ISO 27001:2022 added 11 new controls versus the 2013 version — including A.5.7 (Threat Intelligence), A.8.16 (Monitoring Activities), and A.8.12 (Data Leakage Prevention). ManySignal addresses all 11 new controls: threat intelligence integration (A.5.7), continuous monitoring evidence (A.8.16), and DLP-class data egress monitoring (A.8.12). These are areas where many ISMS programmes previously had gaps.
Can ManySignal integrate with our ISMS documentation and risk register?
ManySignal can push incident data and risk indicator data to GRC platforms (ServiceNow GRC, OneTrust, Archer) via API. This allows the ISMS risk register to be updated with real-world threat intelligence and incident data — improving risk assessment accuracy and reducing the gap between documented risk and operational reality.
How does ManySignal support ISO 27001 internal audit evidence?
ManySignal generates audit evidence packages covering: A.8.15 (logging) with a complete log collection coverage report, A.8.16 (monitoring) with timestamped detection event records for the audit period, and A.5.25-5.28 (incident management) with case lifecycle evidence. Internal auditors can access the evidence portal directly without requiring your security team's involvement in evidence collection.
Does ManySignal support Statement of Applicability (SoA) documentation?
ManySignal provides a mapping document linking each ISO 27001:2022 Annex A control to the specific ManySignal capability that addresses it, along with the evidence type available. This document can be incorporated into the SoA's Justification for Inclusion column for controls ManySignal addresses, and into the implementation evidence for internal audits and certification body assessments.
See ISO 27001 evidence export in action
Walk through the Annex A control mapping, evidence package generation, and GRC platform integration — in one session with our compliance team.