M ManySignal

Guide · ManySignal

ISO 27001 Monitoring Guide

ISO 27001:2022 introduced significant updates to monitoring and incident management controls, particularly in Annex A clauses 5.24–5.28 (information security incident management) and 8.15–8.16 (logging and monitoring). This guide maps the updated requirements to ManySignal capabilities and covers the evidence packages required for third-party certification audits.

MH Marcus Hale — Head of Detection Engineering
14 min read Published Jul 2, 2026 Download PDF
01

ISO 27001:2022 monitoring requirements

Annex A 8.15 (Logging) requires event logs that record user activities, exceptions, faults, and security events. 8.16 (Monitoring activities) requires monitoring of networks, systems, and applications to detect anomalous behaviour. These two controls together describe the telemetry collection and detection programme.

A.5.24 (Planning and preparation for information security incident management) requires defined roles, responsibilities, and procedures for incident management. A.5.25 (Assessment and decision on information security events) requires events to be assessed and a decision made on whether they constitute incidents. A.5.28 (Collection of evidence) requires evidence collection procedures for use in disciplinary or legal proceedings.

02

Mapping controls to ManySignal capabilities

A 8.15 is satisfied by ManySignal's connector infrastructure — every source produces an append-only event log, retained per the configured policy. The log configuration is documented and version-controlled. A 8.16 is satisfied by the active detection catalogue plus the entity graph's continuous behavioural monitoring.

A 5.25 is satisfied by the triage agent: every security event that reaches a finding is assessed against the configured question set and receives a documented decision (true positive / false positive / informational). The decision is time-stamped, evidence-linked, and auditor-readable on the case timeline.

A 5.28 is satisfied by the case timeline's immutability: every piece of evidence captured during investigation is hash-chained and exportable as a signed package. The export is suitable for use in disciplinary proceedings, legal holds, or regulatory investigations.

03

Certification audit preparation

ISO 27001 certification auditors sample — they will not review every alert or incident. They will review a representative sample of security events and ask to see: the event log (that it exists and is retained), the assessment decision (that it was documented), the evidence (that it supports the decision), and the incident management procedure (that it was followed).

Prepare an evidence index: for each Annex A control relevant to monitoring, a pointer to the ManySignal capability that satisfies it, a sample of the operating evidence (three recent cases, the current detection catalogue, a sample metrics report), and the policy document that defines the control. This index is what you hand to the auditor at the start of the monitoring controls review.

  • Evidence index mapping each Annex A monitoring control to ManySignal capability
  • Three sample cases selected: one true positive, one false positive, one informational
  • Current detection catalogue exported and annotated with Annex A mapping
  • Security Monitoring Policy and Incident Response Procedure documents current
  • Log retention policy confirmed against 27001 and local legal requirements
04

Continuous improvement for ISO 27001

ISO 27001 clause 10.1 requires continual improvement of the ISMS. For the monitoring programme, this means a documented improvement cycle: monthly detection coverage review, quarterly incident management procedure review, and annual risk assessment update that feeds new detection priorities.

Document each improvement with a before/after metric. 'MTTV improved from 12 minutes to 3 minutes after triage agent deployment' or 'ATT&CK coverage increased from 42% to 67% in Q2' are the kinds of improvements that demonstrate a maturing ISMS to a certification auditor.

Key takeaways

  • ISO 27001:2022 A 8.15–8.16 require telemetry collection and anomaly monitoring — both satisfied by ManySignal's connector and detection infrastructure.
  • A 5.25 requires documented assessment decisions for every security event — the triage agent provides this at scale.
  • A 5.28 requires evidence collection procedures — the hash-chained case timeline is the evidence artefact.
  • Prepare an evidence index mapping each monitoring control to capability, operating evidence, and policy.
  • Clause 10.1 requires continual improvement — document improvements with before/after metrics.
  • Auditors sample; prepare three representative cases (TP, FP, informational) for the monitoring controls review.

Further reading

Frequently asked questions

What is ISO 27001 Monitoring Guide in an agentic SOC?

ISO 27001 Monitoring Guide is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle iso 27001 monitoring guide?

ManySignal grounds iso 27001 monitoring guide in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for iso 27001 monitoring guide?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.