ISO/IEC 27001:2022

ISO 27001:2022 coverage

How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to ISO 27001:2022 Annex A controls, so you can see, control by control, what your environment evidences.

Indicative mapping, not certification. These mappings show which technical findings support each Annex A control. They are guidance to focus your readiness work. Confirm scope and applicability with your auditor.
Annex A controlWhat LockList assesses
A.5.15Access controlMFA for admins and all users, Security Defaults, Conditional Access coverage, named locations, guest/external access.
A.8.5Secure authenticationMFA registration coverage and methods (M365), 2-Step Verification coverage and admin enrollment (Google), and blocking of legacy authentication.
A.5.17Authentication informationSelf Service Password Reset configuration and required verification methods.
A.5.18Access rightsPrivileged role assignments, directory roles and membership, guest privileges, and suspended/dormant accounts.
A.8.2Privileged access rightsSuper administrator count, admin role inventory, and Privileged Identity Management (just in time) usage.
A.8.15LoggingSign in and directory audit log accessibility (M365); login and admin audit log accessibility (Google); activity log accessibility (NinjaOne).
A.8.16Monitoring activitiesRisky users (Identity Protection), Microsoft Secure Score, and Conditional Access policy visibility in sign in logs; open alert review and stale / offline agent detection (NinjaOne).
A.8.20Networks securityNamed locations and legacy authentication blocking via Conditional Access.
A.5.14Information transferSharePoint/OneDrive external sharing posture and external email auto forwarding rules.
A.8.12Data leakage preventionExternal sharing controls and external forwarding detection across mailboxes.
A.8.1User endpoint devicesIntune device management coverage and non compliant managed devices; RMM device inventory and agent coverage (NinjaOne).
A.8.7Protection against malwareMicrosoft Defender for Office 365 / email security licensing and posture; antivirus coverage and health across managed endpoints (NinjaOne).
A.8.8Management of technical vulnerabilitiesMicrosoft Secure Score (M365); OS patch status across managed endpoints (NinjaOne).
A.8.9Configuration managementApp registrations with high risk Graph permissions and overall identity configuration baseline.
A.5.9Inventory of information & assetsTenant licensing/subscribed SKUs, verified domains, and a tenant/organisation overview; RMM device and organisation inventory (NinjaOne).

Every finding in your LockList Report carries its ISO 27001 control alongside SOC 2, CIS, HIPAA, HITRUST CSF, and CMMC 2.0 mappings. Run a free assessment →

GitHub

The GitHub connector assesses organisation level security controls mapped to these ISO 27001:2022 Annex A controls.

Annex A controlWhat the GitHub connector assesses
A.5.15Access controlOrg wide 2FA enforcement and SAML SSO configuration, ensuring all members authenticate with a second factor before accessing organisation resources.
A.8.2Privileged access rightsAdmin and member role inventory and deploy key review, identifying accounts with owner privileges beyond least privilege and stale keys with write access.
A.8.4Access to source codeOutside collaborator access review and repository visibility posture, verifying that access to source code is limited to authorised individuals.
A.8.9Configuration managementDefault branch protection rules (required reviews, status checks, force push restrictions) and secret scanning / push protection enablement across the organisation.