ISO 27001:2022Annex A.7 coverage · audit-ready 

ISO 27001 Annex A.7, covered.

ISO 27001's Annex A.7 is where most audit findings sit - and where Cyber Aware lives. Every A.7 control mapped, evidence collected automatically, exported as a branded audit pack under your name.

WHAT IS IT?

The international information security standard.

ISO/IEC 27001:2022 is the global benchmark for information security management. Annex A.7 specifically covers human-resource security - onboarding, training, awareness, and termination - the area Cyber Aware addresses directly.

ANNEX A.7 MAPPING

Every Annex A.7 control, covered.

A.7.1 · SCREENING
Background verification of candidates. Pair with our onboarding checklist; Cyber Aware logs the attestation that screening was performed before access was granted.
A.7.2 · TERMS & CONDITIONS
Employment terms include information security responsibilities. Our policy acknowledgement engine captures attestations per learner.
A.7.3 · DISCIPLINARY
Documented disciplinary process for policy violations. Phishing simulation failures + repeat training assignment logged as evidence of corrective action.
A.7.4 · INFOSEC AWARENESS
This is the headline control. Regular, role-relevant training across the workforce. 120+ Cyber Aware modules, branded as yours, completion-tracked and reportable.
A.7.5 · REMOTE WORKING
Awareness content covering home network hygiene, public WiFi, device controls. Delivered via Auto Enrol.
A.7.6 · INFOSEC EVENTS
Report-a-phish in-portal button + Outlook / Gmail add-in. Every report logged and surfaced to your SOC.
EVIDENCE PACKS

What an auditor actually wants.

Training completion log.

Per-learner, per-module record with timestamps, scores, and certificate IDs. Exported as a branded PDF on demand.

Policy acknowledgements.

Each policy attested by each learner, with IP, timestamp, and a hash of the document version. Audit-grade.

Phishing resilience.

Click rates, report rates, compromise rates over time. Proof that A.7.4 training is having a real effect.

Management review pack.

Auto-generated quarterly summary that maps directly to ISMS clause 9.3 - risk score, trends, corrective actions.

Get audit-ready

One platform.
Every framework.

Spin up a fully branded compliance assessment portal under your name. Evidence collected automatically as learners complete training.