Evidence for the ISO 27001 controls that face the internet
Hadrian keeps an inventory of your internet-facing assets, validates which vulnerabilities can be exploited and runs pentests on demand. Your ISMS gets current records for Annex A 5.9, 8.8 and related controls.
Budenheim added continuous external visibility to a governance framework built on internal controls, regular audits and scheduled penetration tests.
ISO 27001 requirements Hadrian supports
ISO/IEC 27001:2022 sets requirements for an information security management system (ISMS), and organizations of any size or sector can be certified against it. Annex A lists 93 controls in four themes. Your risk assessment and Statement of Applicability decide which apply.
Keep an asset inventory with owners
Develop and maintain an inventory of your information and the assets associated with it, including who owns each one.
Atlas keeps a continuously updated inventory of your internet-facing assets, technologies and services. Role-based access lets you assign parts of the attack surface to the teams that own them.
An exported inventory of internet-facing assets that you can reconcile with your asset register, with team ownership in the platform.
Use threat information to make decisions
Collect and analyze information about information security threats so you can act on it. This control was added in the 2022 revision.
Hadrian's risk scoring adds threat intelligence and business context to severity, such as whether a vulnerability is actively exploited. Hadrian's in-house hackers update the platform to find emerging threats.
Findings ranked with exploitation context, showing how threat information shaped your remediation priorities.
Find, evaluate and fix technical vulnerabilities
Get information about technical vulnerabilities in the systems you use, evaluate how exposed you are, and take appropriate measures.
Atlas validates vulnerabilities on internet-facing systems and retests after fixes. Nova pentests add depth on the apps and APIs you choose, and Hadrian maps the Nova report to this control.
Validated findings with reproduction steps, remediation and retest records, and Nova pentest reports.
Secure the networks and devices you expose
Secure, manage and control networks and network devices to protect the information in your systems and applications.
Atlas tests internet-facing servers and network devices from the outside and flags exposed services and misconfigurations an attacker could use.
Validated findings on internet-facing network services, with remediation and retest status.
Manage information security risk from suppliers
Manage security risk in supplier relationships and agreements, across the ICT supply chain, and by monitoring supplier services and changes over time.
Atlas shows the third-party technologies and hosted services on your external attack surface and the exposures they introduce. Secure Share sends a specific risk to a supplier to fix, without platform access.
A list of third-party technologies in your perimeter, and the supplier-related risks you shared and closed.
Hadrian supports these Annex A controls for your external attack surface. It does not certify ISO 27001 compliance.
An inventory that includes what IT never registered
Control 5.9 expects an inventory of information and other associated assets. Atlas discovers internet-facing assets from the outside, including shadow IT, forgotten subdomains and acquired infrastructure. Cloud integrations with AWS, Azure and GCP refresh the inventory every hour.
Technical vulnerability management with validation
Control 8.8 asks you to find technical vulnerabilities, evaluate your exposure and act. Hadrian confirms which vulnerabilities are exploitable in your environment, ranks them by business context and retests after remediation, so your records show each issue through to closure.
Pentest reports you can hand to your auditor
Nova runs scoped pentests of web apps and APIs on demand. Hadrian's offensive security team validates every finding. The report includes an executive summary, methodology, reproduction steps and remediation guidance, and Hadrian maps it to ISO 27001 control 8.8.
More from customers
WeatherTech
WeatherTech, often asked to prove compliance to partners, uses Hadrian's Executive Summary export to produce an external risk report in one click.
Damen Shipyards Group
Damen maps its attack surface automatically, with certificates, technologies and services per asset, and works from Verified Risks with reproduction steps.
The standard does not name one test type. Control 8.8 asks you to identify technical vulnerabilities, evaluate your exposure and act, and the ISO/IEC 27002 guidance for that control describes ways to find vulnerabilities, including testing. Many organizations use penetration tests for this and as input to internal audit. Your risk assessment and Statement of Applicability decide what you need.
Mainly 5.9 (asset inventory) and 8.8 (management of technical vulnerabilities) for your internet-facing systems. Hadrian also supports 5.7 (threat intelligence), 8.20 (networks security) and the supplier controls 5.19 to 5.22 where they concern your external attack surface. It does not cover internal systems, physical controls or people controls.
Yes. Nova reports are written to share with auditors. They include an executive summary, methodology, risk ratings, reproduction steps and remediation guidance, and Hadrian's offensive security team validates every finding. Hadrian maps the report to control 8.8. Your certification body decides what evidence it accepts, so confirm its expectations on scope and tester independence.
ISO/IEC 27001:2022 regrouped Annex A into 93 controls across four themes. Threat intelligence (5.7) is new. Management of technical vulnerabilities (8.8) replaces 12.6.1 and absorbs the old 18.2.3 technical compliance review.
No. Hadrian is a fully managed cloud service with no sensors or agents to deploy. It tests from the internet, the way an attacker sees you, and sets up in minutes.
Keep your ISO 27001 evidence current all year
Book a demo to see how Hadrian tracks your internet-facing assets, validates vulnerabilities and produces reports your ISMS team and auditors can use.