Enterprise GRC Platform
Tyndora for ISO 27001
ISO 27001 is the international information security management standard. Tyndora implements all 114 controls and maps them to your SOC 2, GDPR, and other frameworks.
ISO 27001 Compliance Framework
The global standard for information security management. Trusted by enterprises and regulators worldwide.
ISO 27001 Structure
- 14 Domains (A.5–A.18 + Governance)
- 114 Controls (detailed security requirements)
- ISMS Requirements (Information Security Management System)
- Continual Improvement (Plan-Do-Check-Act cycle)
Why ISO 27001 Matters
ISO 27001 is recognized globally. It's required by many enterprises as a vendor condition. It's also more comprehensive than SOC 2—14 domains covering every aspect of information security.
Tyndora implements all 114 controls and makes certification auditable.
Explore the Annex A control set
ISO/IEC 27001:2022 organises its controls into four themes. Click a theme to browse representative controls, each with a plain-language description of what it requires.
These requirement descriptions are a faithful plain-language working summary of ISO/IEC 27001:2022 Annex A — not verbatim official text. Control titles and reference numbers follow the standard; always consult the official ISO/IEC 27001:2022 publication for the authoritative wording.
ISO 27001 Implementation in Tyndora
From domain leadership to control implementation to certification.
14 Domains of ISO 27001
ISO 27001 spans 14 domains. Tyndora implements all of them with dedicated dashboards for each domain's status.
- A.5: Organizational controls
- A.6: People (HR)
- A.7: Physical security
- A.8: Network and infrastructure
- A.9: Identity and access
- A.10: Cryptography
- A.11: Physical and operational security
- A.12: Communication and operations
- A.13: System acquisition, development
- A.14: Supplier relationships
- A.15: Incident management
- A.16: Business continuity
- A.17: Compliance
- A.18: Information security assessment/testing
ISO 27001 IMPLEMENTATION
Total Controls
114
Implemented & Tested
66/114 (58%)
In Progress
48 (not yet implemented)
Assessment Readiness
Targeting Stage 2 certification in ~9–12 months
DOMAIN COVERAGE
ISMS Governance & Continual Improvement
ISO 27001 isn't just controls—it's an Information Security Management System (ISMS). Tyndora tracks governance, management reviews, and continuous improvement cycles.
- ISMS governance structure (roles, committees)
- Management review cycles (annual/quarterly)
- Incident review and control improvement
- PDCA (Plan-Do-Check-Act) cycle tracking
ISO 27001 Certification Audit
ISO 27001 certification involves two audit stages: Stage 1 (readiness) and Stage 2 (compliance audit over 3 days). Tyndora prepares you for both.
Stage 1: Readiness Audit
- ✓ ISMS design review (management, documentation)
- ✓ Risk assessment review (completeness, accuracy)
- ✓ Control selection verification
- ✓ Gap identification (non-compliances)
Stage 2: Compliance Audit
- ✓ Control testing and verification
- ✓ Evidence review (documentation, logs)
- ✓ Interview management and staff
- ✓ Findings identification and rating
See ISO 27001 Certification Ready
Book a discovery and we'll show you how Tyndora implements all 14 domains and prepares you for Stage 1 & Stage 2 certification audits.
Book a discovery