ISO 27001 Automation

Your Statement of Applicability, automated end-to-end.

Stop running ISO 27001 out of spreadsheets and screenshots. Lojycal turns every Annex A control into a live, signed evidence stream — from initial SoA to surveillance audit.

What ISO 27001 actually demands

ISO/IEC 27001:2022 is straightforward on paper and brutal in practice. Four things have to be true every day — not just the week before the auditor lands.

  • A current Statement of Applicability

    All 93 Annex A controls assessed, justified, and mapped to the controls you actually operate.

  • A live risk treatment plan

    Risks identified, owned, treated, accepted or transferred — with evidence of every decision.

  • Continuous, sampleable evidence

    Auditors sample any control on any day. Screenshots from last quarter don't count.

  • Management review and internal audit

    Documented cadence, documented outcomes, documented corrective actions.

The Lojycal SoA engine

Four connected workspaces produce every artefact your auditor will ask for — automatically, in the format ISO 27001:2022 expects.

Control register

Every Annex A control with status, owner, applicability decision and justification — kept in sync with the SoA.

Trust Center

Evidence ledger

Every workflow run, dual-control approval and policy change becomes a WORM audit-log entry tied to its control.

Workflows + Audit Log

Risk treatment

Risk register linked to assets, applications and processes. Treatment decisions are signed and dated.

Trust Center + Asset Lifecycle

Internal audit

Scheduled control sampling, nightly evidence-pack generation, cryptographically signed exports for the auditor.

Trust Center → Evidence Pack

Annex A → Lojycal control mapping

Lojycal automatically produces evidence for the majority of Annex A:2022 controls across all four themes. A sampled view:

Annex A themeExample controlLojycal source
Organisational (A.5)A.5.15 Access controlRBAC + Access Reviews
Organisational (A.5)A.5.23 Information security for cloud servicesSaaS Governance + SSPM
People (A.6)A.6.6 Confidentiality / NDAsHR Automation
Physical (A.7)A.7.10 Storage mediaAsset Lifecycle (FileVault / BitLocker evidence)
Technological (A.8)A.8.7 Protection against malwareEndpoint Governance (Intune / Jamf / Kandji)
Technological (A.8)A.8.16 Monitoring activitiesSIEM Egress + Audit Log
Technological (A.8)A.8.34 Protection during audit testingBreak-glass + Dual-control

Sampled — not exhaustive. Coverage depends on which Lojycal modules and connectors you have enabled.

Continuous evidence, not audit-week panic

Most ISO 27001 programmes collapse the week before the audit, because evidence was a manual collection exercise.

Lojycal flips that. Every workflow run, every dual-control decision, every policy change writes a WORM (write-once, read-many) entry to the audit log. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-org key — that the auditor can verify independently.

From SoA to certified — a 90-day path

We've watched teams compress what used to be a 9–12 month programme into a single quarter, because the evidence collects itself.

  1. Days 0–30

    Phase 1 — Scope & SoA

    Define ISMS scope. Generate the Statement of Applicability against all 93 Annex A controls. Lojycal pre-fills applicability and justification for every control it already operates.

  2. Days 31–75

    Phase 2 — Implementation & evidence

    Close residual gaps. Wire up integrations. Workflows, RBAC, dual-control and SIEM start producing continuous evidence the day they go live.

  3. Days 76–90

    Phase 3 — Stage 1 & Stage 2 audit

    Hand the auditor a signed Evidence Pack. Run live control samples from the Trust Center during Stage 2. Address minor findings via the corrective-actions workflow.

ISO 27001 automation — common questions

What is ISO 27001 automation?

ISO 27001 automation is the practice of producing the Statement of Applicability, risk treatment plan, control evidence and audit artefacts directly from your live operational systems — instead of collecting screenshots and spreadsheets manually. Lojycal automates the SoA, evidence ledger, internal audit sampling and Evidence Pack export end-to-end.

Does Lojycal replace an external auditor?

No. ISO 27001 certification can only be issued by an accredited certification body (e.g. BSI, DNV, TÜV). Lojycal automates everything you bring to the auditor: the SoA, the risk register, the evidence pack and the continuous control sampling. Auditors verify the artefacts; we generate them.

How does the Statement of Applicability stay in sync with the live system?

The SoA is a live document inside the Trust Center, not a Word file. When you enable a Lojycal control (e.g. dual-control approvals, BitLocker enforcement, SIEM egress), the corresponding Annex A control flips to applicable with a system-generated justification. Manual edits are tracked in the WORM audit log.

Which Annex A controls can Lojycal evidence automatically?

The majority of A.5 (Organisational), A.7 (Physical, where digital), and A.8 (Technological) controls are evidenced automatically — including access control, supplier relationships, cryptographic controls, malware protection, monitoring, secure development, and protection during audit testing. People controls (A.6) are partially automated via the HR Automation workspace.

How long does ISO 27001 take with Lojycal?

A focused team can move from kick-off to Stage 2 audit in roughly 90 days, versus 9–12 months without automation. The biggest accelerator is that evidence collects itself from day one — there is no separate evidence-gathering sprint before the audit.

Does this work for ISO 27001:2022, the 93-control revision?

Yes. Lojycal's Annex A mapping targets ISO/IEC 27001:2022 (the current 93-control structure across Organisational, People, Physical and Technological themes). Organisations transitioning from the 2013 edition can use Lojycal's mapping table to evidence the consolidated controls.

Run ISO 27001 like a live system, not a paperwork project.

Every Annex A control. Every risk decision. Every audit sample. One signed source of truth.