ISO 27001 Annex A, answered.
The 31 questions from ISO 27001 Annex A we have written up so far. Each one covers what it is really asking, which of your documents answers it, what to attach alongside, and the specific ways it gets answered badly.
Are background checks performed on employees with access to customer data?
Confirmed in your documentsOne of the few questions answered from an HR document rather than a security one, which is exactly why it is often answered from memory.
People · A.6.1
Are backups tested by performing restores?
Implied, not statedEverybody takes backups. This question is about the last time one was proved to work.
Resilience · A.8.13
Are user access rights reviewed periodically?
Implied, not statedPolicies say quarterly. The reviewer is asking about the person who left in March, and periodic review is the wrong instrument for finding them.
Access control · A.5.18
Do employees complete security awareness training?
Confirmed in your documentsAn easy yes for most teams, and one of the few questions where the follow-up is a date rather than a document.
People · A.6.3
Do you allow customers to audit your security controls?
Answered “no” from your documentsAnswering yes to be agreeable grants a contractual right to send an assessor. Answering no with nothing offered instead leaves a gap in the reviewer's file. The useful answer is no, and here is what you get.
Certifications and audits
Do you assess the security of your vendors and sub-processors?
Implied, not statedThe question your customer is really asking is whether their data can reach somewhere they have not been told about.
Third-party risk · A.5.19
Do you classify data by sensitivity?
Not in your documentsOne of the few questions where most small companies genuinely have nothing, and where inventing a scheme is worse than saying so.
Data governance · A.5.12
Do you have a documented change management process?
Confirmed in your documentsAt fifteen people this is not a change advisory board. It is whether your pipeline records who changed what.
Engineering practice · A.8.32
Do you have a documented incident response plan, and what is your breach notification window?
Confirmed in your documentsTwo questions in one, and the second half, the notification window, is the one with contractual teeth. It comes from your DPA, not from GDPR.
Incident response · A.5.24
Do you have a secure software development lifecycle?
Confirmed in your documentsReviewers are testing one thing: what prevents an unreviewed change from reaching your customers' data.
Engineering practice · A.8.25
Do you have a vulnerability disclosure policy or bug bounty programme?
Not in your documentsVery few small companies run a bounty. Almost all of them should have the one-page policy, and it takes an afternoon.
Vulnerability management · A.8.8
Do you hold ISO 27001 certification?
Answered “no” from your documentsOne of the few questions where the answer is usually no, and where no is a perfectly good answer.
Certifications and audits
Do you log and monitor access to production systems?
Confirmed in your documentsTwo questions in one: what you record, and what happens when something in the record is worth waking up for.
Logging and monitoring · A.8.15
Do you maintain a business continuity and disaster recovery plan, and is it tested?
Reused from your libraryTwo numbers carry this answer, RTO and RPO, and they are the two a reviewer can hold you to during a real outage. Do not publish ones you have not measured.
Resilience · A.5.30
Do you maintain an inventory of systems and assets?
Implied, not statedYou probably have three inventories already and have never called them that.
Infrastructure · A.5.9
Do you perform annual penetration testing by an independent third party?
Implied, not statedThis is the question FillTrust most often grades as inferred rather than confirmed, because policies state a cadence and cadences are not evidence that a test happened.
Vulnerability management · A.8.8
Do you perform regular security risk assessments?
Not in your documentsThe most enterprise-shaped question on the questionnaire, and the one small teams most often answer with an aspiration.
Governance · Clause 6.1.2
How are credentials, API keys and other secrets managed?
Confirmed in your documentsThe question is about the credentials your software runs on, not the password manager the team uses. Rotation is the part most likely to be aspirational, and the follow-up is always the date of the last one.
Encryption and key management
How are employee laptops secured?
Implied, not statedThe question moved on from antivirus. It is now about encryption, updates, and whether you can take a device away.
Devices · A.8.1
How is one customer's data kept separate from another's?
Implied, not statedLogical separation is the true answer for nearly every SaaS, and also what somebody says when they have not thought about it. The difference is whether you can say how the boundary is enforced and tested.
Data governance
How quickly do you patch known vulnerabilities?
Implied, not statedThe question is not whether you patch. It is whether you can name the window and show that you meet it.
Vulnerability management · A.8.8
How quickly is access revoked when someone leaves?
Confirmed in your documentsThe strongest version of this answer is not a time. It is a single action that covers everything, plus a list of what it does not.
Access control · A.5.18
How quickly will you notify us of a data breach?
Confirmed in your documentsThe one answer that must match your contract word for word, because the contract is what a court reads.
Incident response · A.5.26
Is access granted on a least-privilege basis?
Implied, not statedThe honest small-company answer is rarely a clean yes, and the answer that names its exceptions is stronger than the one that does not.
Access control · A.5.15
Is customer data encrypted at rest?
Confirmed in your documentsOne of the most common questions on any questionnaire, and one of the most commonly over-answered: most teams encrypt the database and forget the backups.
Encryption and key management · A.8.24
Is customer data encrypted in transit?
Confirmed in your documentsEasy to answer yes to and easy to check from the outside, which makes it one of the few questions where a wrong answer is found rather than believed.
Encryption and key management · A.8.24
Is multi-factor authentication enforced for administrative access?
Confirmed in your documentsThe gap here is almost always between "enabled" and "enforced", and between staff logins and the two or three accounts that could not take a second factor.
Access control · A.8.5
What are your recovery time and recovery point objectives?
Not in your documentsTwo numbers with no scenario attached mean nothing, and a reviewer who has to guess will assume the flattering reading and hold you to it.
Resilience · A.5.30
What is your data retention period, and how is customer data deleted after termination?
Reused from your libraryThe number is easy. What separates a good answer from one that unravels is whether it accounts for backups, logs and every other place a copy came to rest.
Data governance · A.8.10
What is your password policy?
Confirmed in your documentsOne of the few questions where the modern answer looks weaker than the old one and is in fact much stronger.
Access control · A.5.17
What physical security controls protect your data centres?
Confirmed in your documentsYou do not run a data centre. Saying so, and naming who does, is the complete answer.
Infrastructure · A.7.1
Answer the whole ISO 27001 Annex A at once.
Upload the file you were sent. FillTrust drafts each answer from your own documents and shows the passage it came from.