ISO 27001

Evidence for the ISO 27001 controls that face the internet

Hadrian keeps an inventory of your internet-facing assets, validates which vulnerabilities can be exploited and runs pentests on demand. Your ISMS gets current records for Annex A 5.9, 8.8 and related controls.

Customer story

Budenheim added continuous external visibility to a governance framework built on internal controls, regular audits and scheduled penetration tests.

Budenheim
Read the story →
Requirements

ISO 27001 requirements Hadrian supports

ISO/IEC 27001:2022 sets requirements for an information security management system (ISMS), and organizations of any size or sector can be certified against it. Annex A lists 93 controls in four themes. Your risk assessment and Statement of Applicability decide which apply.

0
1
Annex A 5.9 Inventory of information and other associated assets

Keep an asset inventory with owners

Develop and maintain an inventory of your information and the assets associated with it, including who owns each one.

How Hadrian helps

Atlas keeps a continuously updated inventory of your internet-facing assets, technologies and services. Role-based access lets you assign parts of the attack surface to the teams that own them.

Evidence you can show

An exported inventory of internet-facing assets that you can reconcile with your asset register, with team ownership in the platform.

0
2
Annex A 5.7 Threat intelligence

Use threat information to make decisions

Collect and analyze information about information security threats so you can act on it. This control was added in the 2022 revision.

How Hadrian helps

Hadrian's risk scoring adds threat intelligence and business context to severity, such as whether a vulnerability is actively exploited. Hadrian's in-house hackers update the platform to find emerging threats.

Evidence you can show

Findings ranked with exploitation context, showing how threat information shaped your remediation priorities.

0
3
Annex A 8.8 Management of technical vulnerabilities

Find, evaluate and fix technical vulnerabilities

Get information about technical vulnerabilities in the systems you use, evaluate how exposed you are, and take appropriate measures.

How Hadrian helps

Atlas validates vulnerabilities on internet-facing systems and retests after fixes. Nova pentests add depth on the apps and APIs you choose, and Hadrian maps the Nova report to this control.

Evidence you can show

Validated findings with reproduction steps, remediation and retest records, and Nova pentest reports.

0
4
Annex A 8.20 Networks security

Secure the networks and devices you expose

Secure, manage and control networks and network devices to protect the information in your systems and applications.

How Hadrian helps

Atlas tests internet-facing servers and network devices from the outside and flags exposed services and misconfigurations an attacker could use.

Evidence you can show

Validated findings on internet-facing network services, with remediation and retest status.

0
5
Annex A 5.19 to 5.22 (supplier relationships)

Manage information security risk from suppliers

Manage security risk in supplier relationships and agreements, across the ICT supply chain, and by monitoring supplier services and changes over time.

How Hadrian helps

Atlas shows the third-party technologies and hosted services on your external attack surface and the exposures they introduce. Secure Share sends a specific risk to a supplier to fix, without platform access.

Evidence you can show

A list of third-party technologies in your perimeter, and the supplier-related risks you shared and closed.

Hadrian supports these Annex A controls for your external attack surface. It does not certify ISO 27001 compliance.

How Hadrian helps

An inventory that includes what IT never registered

Control 5.9 expects an inventory of information and other associated assets. Atlas discovers internet-facing assets from the outside, including shadow IT, forgotten subdomains and acquired infrastructure. Cloud integrations with AWS, Azure and GCP refresh the inventory every hour.

See attack surface management
01

Technical vulnerability management with validation

Control 8.8 asks you to find technical vulnerabilities, evaluate your exposure and act. Hadrian confirms which vulnerabilities are exploitable in your environment, ranks them by business context and retests after remediation, so your records show each issue through to closure.

See adversarial exposure validation
02

Pentest reports you can hand to your auditor

Nova runs scoped pentests of web apps and APIs on demand. Hadrian's offensive security team validates every finding. The report includes an executive summary, methodology, reproduction steps and remediation guidance, and Hadrian maps it to ISO 27001 control 8.8.

See agentic penetration testing
03
Case studies

More from customers

All case studies
Case study

WeatherTech

WeatherTech, often asked to prove compliance to partners, uses Hadrian's Executive Summary export to produce an external risk report in one click.

Read the story →
Case study

Damen Shipyards Group

Damen maps its attack surface automatically, with certificates, technologies and services per asset, and works from Verified Risks with reproduction steps.

Read the story →
FAQ

Frequently asked questions

Does ISO 27001 require penetration testing?
+

The standard does not name one test type. Control 8.8 asks you to identify technical vulnerabilities, evaluate your exposure and act, and the ISO/IEC 27002 guidance for that control describes ways to find vulnerabilities, including testing. Many organizations use penetration tests for this and as input to internal audit. Your risk assessment and Statement of Applicability decide what you need.

Which Annex A controls does Hadrian support?
+

Mainly 5.9 (asset inventory) and 8.8 (management of technical vulnerabilities) for your internet-facing systems. Hadrian also supports 5.7 (threat intelligence), 8.20 (networks security) and the supplier controls 5.19 to 5.22 where they concern your external attack surface. It does not cover internal systems, physical controls or people controls.

Can we give a Nova report to our auditor?
+

Yes. Nova reports are written to share with auditors. They include an executive summary, methodology, risk ratings, reproduction steps and remediation guidance, and Hadrian's offensive security team validates every finding. Hadrian maps the report to control 8.8. Your certification body decides what evidence it accepts, so confirm its expectations on scope and tester independence.

What changed for these controls between the 2013 and 2022 versions?
+

ISO/IEC 27001:2022 regrouped Annex A into 93 controls across four themes. Threat intelligence (5.7) is new. Management of technical vulnerabilities (8.8) replaces 12.6.1 and absorbs the old 18.2.3 technical compliance review.

Does Hadrian need agents or access to our network?
+

No. Hadrian is a fully managed cloud service with no sensors or agents to deploy. It tests from the internet, the way an attacker sees you, and sets up in minutes.

Get a 15 minute demo

Keep your ISO 27001 evidence current all year

Book a demo to see how Hadrian tracks your internet-facing assets, validates vulnerabilities and produces reports your ISMS team and auditors can use.