DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/ISO 27001
Australia & NZ compliance

ISO/IEC 27001:2022

The international standard for establishing, implementing, and maintaining an information security management system. The 2022 revision structures 93 Annex A controls across four themes: Organisational, People, Physical, and Technological.

See where NodeZero applies

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). The 2022 revision restructured the Annex A controls into four themes -- Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls) -- replacing the previous 14-domain structure. Certification requires both a functioning ISMS and evidence that controls are operating effectively, not just documented.

For organisations pursuing or maintaining ISO 27001 certification, the audit process demands proof that controls work in practice. Auditors don't just review policies -- they test whether access controls enforce what the documentation claims, whether vulnerabilities are identified and remediated, and whether monitoring systems detect anomalies. This is where the gap between a well-documented ISMS and a genuinely secure environment becomes apparent.

ISO/IEC 27001:2022

Where NodeZero applies

NodeZero provides direct, testable evidence across the Technological controls theme — the 34 controls covering access management, network security, vulnerability management, authentication, anti-malware, data protection, and monitoring. Autonomous pentesting produces audit-ready evidence that controls like A.8.5 (secure authentication), A.8.8 (technical vulnerability management), A.8.16 (monitoring activities), and A.8.20/A.8.22 (networks security and segregation) actually hold under adversarial conditions. Narrower coverage extends into Organisational (A.5.7 threat intelligence, A.5.15-A.5.17 access/identity/authentication, A.5.23 cloud services). Physical and People controls sit outside autonomous testing — we flag each one explicitly.

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following require separate evidence: People controls (8 controls) and Physical controls (14 controls).

Showing coverage grouped by compliance category.

Organisational controls (37 controls)

Minimal direct coverage — these are mostly governance controls. NodeZero validates enforcement on a small subset.

Internal pentestingCore

Chains credential and access-control weaknesses into real attack paths — proves whether the logical access rules actually hold when an attacker pushes against them.

Phishing Impact TestingCore

Takes phished credentials and demonstrates what an attacker can actually reach — concrete evidence of whether identity-management controls survive attack.

Threat Actor IntelligenceElite only

Correlates your actual attack paths with MITRE ATT&CK techniques and named threat-actor campaigns — producing environment-specific threat intelligence A.5.7 expects.

AD Password AuditCore

Directly proves weak, breached and reused passwords, plus the blast radius one compromised credential unlocks — attack-impact evidence of whether authentication-information management is actually holding, not just documented.

Cloud pentestingCore

Enumerates AWS, Azure/Entra ID and Kubernetes resources and proves IAM misconfiguration, privilege-escalation and lateral-movement paths, including full Entra ID tenant compromise — attack-impact evidence of whether cloud services are actually configured and used securely.

5 controls mapped

Technological controls (34 controls)

Strongest alignment. NodeZero generates direct evidence across the majority of technical controls.

Internal pentestingCore

Discovers endpoint misconfigurations, missing patches, and credential weaknesses that expose information stored on user devices.

AD Password AuditCore

Audits credential strength on privileged, service, and break-glass accounts and proves the real blast radius of over-provisioned access.

Insider Threat TestingCore

Proves whether an attacker or an over-provisioned, stale-access user can actually reach restricted information — attack-impact evidence that the restriction fails or holds, distinct from whether the access-control rule is merely configured.

Web application pentestingPriced separately

Tests applications for the weaknesses insecure code produces — injection, cross-site scripting, XXE, SSRF and broken access control, including IDOR and BOLA — with real exploitation as proof, in pre-production as well as production. It evidences the outcome at the application layer; secure-coding practice, code review and developer training remain development-lifecycle work.

Phishing Impact TestingCore

Uses credentials captured by your phishing tool to prove what a phished credential can actually reach — direct evidence of the blast radius when secure-authentication controls are bypassed.

Segmentation testingCore

Enumerates IPs, ports, services, and applications to validate network controls actually protect systems and applications.

Vulnerability Risk IntelligenceElite only

Ingests existing Nessus, Rapid7 or Qualys exports and re-ranks each CVE-asset pair against NodeZero's walked attack paths — attacker-first re-prioritisation of the exposure evaluation A.8.8 requires.

External pentestingCore

Maps the internet-facing footprint and chains exploitable perimeter weaknesses into attack paths — the network-layer half of the evidence, alongside the application-layer testing above.

NodeZero TripwiresPro & Elite

Decoys drop on high-risk assets and alert your SIEM the moment an attacker interacts — direct evidence of whether your monitoring and detection actually catch an in-progress attack. Broad monitoring coverage remains your SIEM/SOC's job.

Endpoint Security EffectivenessCore

Reports per-host and per-vendor EDR block/allow across 40+ vendors, mapped to MITRE ATT&CK — concrete evidence that anti-malware is actually protecting.

Advanced Data PilferingElite only

Surfaces reachable sensitive data and tags it against 12 business-risk categories — supporting evidence of lingering or forgotten data an attacker could reach. Whether that data breached a retention schedule remains a data-lifecycle governance question.

14 controls mapped
ISO 27001 kit

See every control mapped to NodeZero

The full control-by-control coverage map — every ISO 27001requirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

ISO 27001 certification is voluntary, but it is increasingly treated as a de facto requirement. Enterprise procurement teams routinely mandate ISO 27001 certification from suppliers. Government contracts in Australia, New Zealand, the UK, and the EU frequently reference it. Cyber insurance underwriters use it as a benchmark. And it is one of five frameworks approved under Australia's SOCI CIRMP rules for meeting the cyber hazard obligation.

The standard applies to any organisation, regardless of size or sector, that wants to establish a formal information security management system. In practice, it is most commonly pursued by technology companies, managed service providers, financial services firms, healthcare organisations, and any business that handles sensitive data on behalf of clients. The 2022 revision also makes it more accessible to smaller organisations by simplifying the control structure.

If your clients ask whether you're ISO 27001 certified, if you're responding to RFPs that require it, or if you need an internationally recognised standard to anchor your security programme, ISO 27001 applies to you. Certification is granted by accredited third-party auditors following a two-stage audit process.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.