Docs · Compliance
ISO 27001 controls
Annex A control mapping for every infrastructure change reviewed on pull request.
Annex A control mapping
DriftGuard automates operating evidence for the Annex A controls most relevant to infrastructure-as-code. It does not certify your ISMS — it produces the artefacts an auditor asks for.
A.8.9Configuration management — Checkov scans every Terraform plan for misconfiguration.
A.8.32Change management — Required GitHub Check gates merges; drift detection blocks stale plans.
A.8.15Logging — Append-only audit log records analysis outcomes, policy and settings changes, and token issuance.
A.8.13Information backup — Checkov flags data stores missing backup or retention configuration.
Evidence per PR
Every pull request emits an evidence record listing the Annex A controls exercised, from the fixed catalog above — no configuration required. Export the audit log (dashboard → Audit log → Export CSV) to attach change-management evidence to your Statement of Applicability. DriftGuard is in early access.