Records for the Annex A controls you apply
Classify, log, monitor and respond, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| A.5.12 | Information classified. | DLP discovery by classification. → |
| A.5.13 | Information labelled. | Labels by rule. → |
| A.5.14 | Information transfer controlled. | DLP response actions. → |
| A.5.26 | Response to incidents. | Cases and playbook history. → |
| A.5.28 | Evidence collected. | Signed export with a verifier. → |
| A.7.10 | Storage media managed. | Device control. → |
| A.8.15 | Logging. | Signed, chained logs. → |
| A.8.16 | Monitoring activities. | Classified, MITRE-tagged events. → |
Classification
Label data by what it is
ARRTECH DLP discovery scans endpoints, file servers and SQL databases, inventories what it finds by classification and labels files by rule.
Transfer
Check data before it leaves
Each ARRTECH DLP rule blocks, allows and logs, asks a manager, asks the user for a justification, encrypts, quarantines or notifies.
Logging
Keep logs that are protected
Annex A asks for logs to be produced, stored, protected and analysed. ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Monitoring
Watch for anomalous behavior
ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Incidents
Collect evidence you can hand over
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. Any source exports with a standalone verification tool.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
A.8.17
Clock synchronization. No ARRTECH product sets or records time synchronization. The record comes from your time servers’ configuration.
A.8.5
Secure authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
A.8.13
Information backup. ARRTECH sells no backup product.
A.8.8
Technical vulnerabilities. ARRTECH sells no vulnerability scanner.
By rule
Naming a clause is not a claim of certification.
A.5.12
Classify information by its protection needs. ARRTECH: DLP discovery inventories what it finds by classification.
A.5.13
Label information by its classification. ARRTECH: DLP labels files by rule.
A.5.14
Protect information in transfer. ARRTECH: DLP rules block, ask a manager, encrypt, quarantine or notify.
A.5.26
Respond to incidents by documented procedures. ARRTECH: SIEM cases and SOAR incidents with an execution history.
A.5.28
Collect and preserve evidence of security events. ARRTECH: signed exports with a standalone verification tool.
A.7.10
Manage storage media through its life cycle. ARRTECH: device control by class, vendor, product or serial number.
A.8.15
Logs produced, stored, protected and analysed. ARRTECH: every write hashed, signed and chained.
A.8.16
Monitor for anomalous behavior. ARRTECH: classified events with MITRE ATT&CK columns.
Questions
Is ARRTECH ISO 27001 certified?
This page makes no such claim. Certification belongs to an organization’s ISMS, issued by an accredited body.
Is there a ready ISO report?
Ready reports cover ISO/IEC. Check each report against your Statement of Applicability.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Does ISO certify anyone?
No. ISO does not perform certification or issue certificates.
Sources
Guide
What is ISO 27001?
The international standard for an information security management system. The 2022 edition is current.
What is Annex A?
The list of 93 reference controls an organization selects from and justifies.
What is a Statement of Applicability?
The document that lists each Annex A control, whether it applies and why.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.