Your Statement of Applicability, automated end-to-end.
Stop running ISO 27001 out of spreadsheets and screenshots. Lojycal turns every Annex A control into a live, signed evidence stream — from initial SoA to surveillance audit.
What ISO 27001 actually demands
ISO/IEC 27001:2022 is straightforward on paper and brutal in practice. Four things have to be true every day — not just the week before the auditor lands.
A current Statement of Applicability
All 93 Annex A controls assessed, justified, and mapped to the controls you actually operate.
A live risk treatment plan
Risks identified, owned, treated, accepted or transferred — with evidence of every decision.
Continuous, sampleable evidence
Auditors sample any control on any day. Screenshots from last quarter don't count.
Management review and internal audit
Documented cadence, documented outcomes, documented corrective actions.
The Lojycal SoA engine
Four connected workspaces produce every artefact your auditor will ask for — automatically, in the format ISO 27001:2022 expects.
Control register
Every Annex A control with status, owner, applicability decision and justification — kept in sync with the SoA.
Trust Center
Evidence ledger
Every workflow run, dual-control approval and policy change becomes a WORM audit-log entry tied to its control.
Workflows + Audit Log
Risk treatment
Risk register linked to assets, applications and processes. Treatment decisions are signed and dated.
Trust Center + Asset Lifecycle
Internal audit
Scheduled control sampling, nightly evidence-pack generation, cryptographically signed exports for the auditor.
Trust Center → Evidence Pack
Annex A → Lojycal control mapping
Lojycal automatically produces evidence for the majority of Annex A:2022 controls across all four themes. A sampled view:
| Annex A theme | Example control | Lojycal source |
|---|---|---|
| Organisational (A.5) | A.5.15 Access control | RBAC + Access Reviews |
| Organisational (A.5) | A.5.23 Information security for cloud services | SaaS Governance + SSPM |
| People (A.6) | A.6.6 Confidentiality / NDAs | HR Automation |
| Physical (A.7) | A.7.10 Storage media | Asset Lifecycle (FileVault / BitLocker evidence) |
| Technological (A.8) | A.8.7 Protection against malware | Endpoint Governance (Intune / Jamf / Kandji) |
| Technological (A.8) | A.8.16 Monitoring activities | SIEM Egress + Audit Log |
| Technological (A.8) | A.8.34 Protection during audit testing | Break-glass + Dual-control |
Sampled — not exhaustive. Coverage depends on which Lojycal modules and connectors you have enabled.
Continuous evidence, not audit-week panic
Most ISO 27001 programmes collapse the week before the audit, because evidence was a manual collection exercise.
Lojycal flips that. Every workflow run, every dual-control decision, every policy change writes a WORM (write-once, read-many) entry to the audit log. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-org key — that the auditor can verify independently.
From SoA to certified — a 90-day path
We've watched teams compress what used to be a 9–12 month programme into a single quarter, because the evidence collects itself.
- Days 0–30
Phase 1 — Scope & SoA
Define ISMS scope. Generate the Statement of Applicability against all 93 Annex A controls. Lojycal pre-fills applicability and justification for every control it already operates.
- Days 31–75
Phase 2 — Implementation & evidence
Close residual gaps. Wire up integrations. Workflows, RBAC, dual-control and SIEM start producing continuous evidence the day they go live.
- Days 76–90
Phase 3 — Stage 1 & Stage 2 audit
Hand the auditor a signed Evidence Pack. Run live control samples from the Trust Center during Stage 2. Address minor findings via the corrective-actions workflow.
ISO 27001 automation — common questions
What is ISO 27001 automation?
ISO 27001 automation is the practice of producing the Statement of Applicability, risk treatment plan, control evidence and audit artefacts directly from your live operational systems — instead of collecting screenshots and spreadsheets manually. Lojycal automates the SoA, evidence ledger, internal audit sampling and Evidence Pack export end-to-end.
Does Lojycal replace an external auditor?
No. ISO 27001 certification can only be issued by an accredited certification body (e.g. BSI, DNV, TÜV). Lojycal automates everything you bring to the auditor: the SoA, the risk register, the evidence pack and the continuous control sampling. Auditors verify the artefacts; we generate them.
How does the Statement of Applicability stay in sync with the live system?
The SoA is a live document inside the Trust Center, not a Word file. When you enable a Lojycal control (e.g. dual-control approvals, BitLocker enforcement, SIEM egress), the corresponding Annex A control flips to applicable with a system-generated justification. Manual edits are tracked in the WORM audit log.
Which Annex A controls can Lojycal evidence automatically?
The majority of A.5 (Organisational), A.7 (Physical, where digital), and A.8 (Technological) controls are evidenced automatically — including access control, supplier relationships, cryptographic controls, malware protection, monitoring, secure development, and protection during audit testing. People controls (A.6) are partially automated via the HR Automation workspace.
How long does ISO 27001 take with Lojycal?
A focused team can move from kick-off to Stage 2 audit in roughly 90 days, versus 9–12 months without automation. The biggest accelerator is that evidence collects itself from day one — there is no separate evidence-gathering sprint before the audit.
Does this work for ISO 27001:2022, the 93-control revision?
Yes. Lojycal's Annex A mapping targets ISO/IEC 27001:2022 (the current 93-control structure across Organisational, People, Physical and Technological themes). Organisations transitioning from the 2013 edition can use Lojycal's mapping table to evidence the consolidated controls.
Run ISO 27001 like a live system, not a paperwork project.
Every Annex A control. Every risk decision. Every audit sample. One signed source of truth.
