ISO/IEC 27001:2022 Annex A — Mapping Noxys
Bilingue / Bilingual. Each control of ISO/IEC 27001:2022 Annex A is mapped to (i) the corresponding section of the Noxys PAS template and (ii) the Noxys technical control(s) that implement it.
ISO/IEC 27001:2022 Annex A regroups the 93 controls of ISO/IEC 27002:2022 into 4 themes:
- A.5 — Organizational controls (37 controls)
- A.6 — People controls (8 controls)
- A.7 — Physical controls (14 controls)
- A.8 — Technological controls (34 controls)
Statuts / Status legend:
- OK — Implemented & verified
- PARTIAL — Implemented, additional evidence in progress
- PLANNED — In roadmap for 2026
A.5 — Contrôles organisationnels (Organizational)
| ID | Contrôle ISO | PAS § | Implémentation Noxys | Statut |
|---|---|---|---|---|
| A.5.1 | Policies for information security | §4 | noxys-doc policy repo, revue annuelle | OK |
| A.5.2 | Information security roles & responsibilities | §3 | RACI documented, CISO appointed | OK |
| A.5.3 | Segregation of duties | §3.3 | feat → staging → main, double approval, separation dev/prod | OK |
| A.5.4 | Management responsibilities | §3.1 | Comité sécurité trimestriel, CEO sponsor | OK |
| A.5.5 | Contact with authorities | §14.3 | Liaisons CNIL, ANSSI, CERT-FR documentées | OK |
| A.5.6 | Contact with special interest groups | §4 | CLUSIF, OWASP, FIRST | OK |
| A.5.7 | Threat intelligence | §8, §12 | Trivy, OSV, CVE feeds, CERT-FR | OK |
| A.5.8 | Information security in project management | §12 | Threat modeling per project | OK |
| A.5.9 | Inventory of information & other associated assets | §5.1 | CMDB auto-updated via CI | OK |
| A.5.10 | Acceptable use of information | §6.2 | Charte sécurité signée par tous | OK |
| A.5.11 | Return of assets | §5.3, §6.3 | Process départ < 5 jours | OK |
| A.5.12 | Classification of information | §5.2 | C1-C4 schema | OK |
| A.5.13 | Labelling of information | §5.2 | Metadata tagging in CMDB + S3 | OK |
| A.5.14 | Information transfer | §11 | TLS 1.3, HMAC webhooks, no transfer outside EU | OK |
| A.5.15 | Access control | §9 | RBAC + SSO + MFA | OK |
| A.5.16 | Identity management | §9.1 | SSO SAML/OIDC | OK |
| A.5.17 | Authentication information | §9, §10 | Argon2id, no plaintext storage | OK |
| A.5.18 | Access rights | §9.2 | Quarterly review, JIT for prod | OK |
| A.5.19 | Information security in supplier relationships | §13 | CAIQ-Lite + DPA + audit annuel | OK |
| A.5.20 | Addressing information security within supplier agreements | §13.1 | DPA template, sub-processor list | OK |
| A.5.21 | Managing information security in the ICT supply chain | §12.3, §13 | SBOM, lockfiles, Renovate | OK |
| A.5.22 | Monitoring, review and change management of supplier services | §13.2 | Annual review, 30-day notice | OK |
| A.5.23 | Information security for use of cloud services | §7, §17 | OVH ISO 27001 + HDS + SecNumCloud-in-progress | OK |
| A.5.24 | Information security incident management planning | §14 | Runbook + P0-P3 classification | OK |
| A.5.25 | Assessment and decision on information security events | §14.2 | Triage CISO < 30 min | OK |
| A.5.26 | Response to information security incidents | §14.2 | Runbook documented | OK |
| A.5.27 | Learning from information security incidents | §14.2 | Post-mortem < 5 days | OK |
| A.5.28 | Collection of evidence | §14, §8.5 | SIEM, 18-month retention | OK |
| A.5.29 | Information security during disruption | §15 | BCP / DR plan, semi-annual test | OK |
| A.5.30 | ICT readiness for business continuity | §15.2 | Multi-region failover OVH | OK |
| A.5.31 | Legal, statutory, regulatory & contractual requirements | §16 | GDPR, NIS 2, DORA tracker | OK |
| A.5.32 | Intellectual property rights | §6.1, §12 | Open source license compliance, NDA | OK |
| A.5.33 | Protection of records | §5, §8 | Retention 10 yrs (billing), 18 mo (logs) | OK |
| A.5.34 | Privacy and protection of PII | §10, §16, §17 | DPA, DPIA, KMS per-tenant | OK |
| A.5.35 | Independent review of information security | §16.3 | External pentest + ISO audit | OK |
| A.5.36 | Compliance with policies, rules and standards | §4, §16 | Annual review | OK |
| A.5.37 | Documented operating procedures | §8 | Runbooks in noxys-doc (internal) | OK |
A.6 — Contrôles humains (People)
| ID | Contrôle ISO | PAS § | Implémentation Noxys | Statut |
|---|---|---|---|---|
| A.6.1 | Screening | §6.1 | Casier B3 pour accès prod | OK |
| A.6.2 | Terms and conditions of employment | §6.1 | NDA + charte sécurité | OK |
| A.6.3 | Information security awareness, education and training | §6.2 | Formation < 30 jours + recyclage annuel | OK |
| A.6.4 | Disciplinary process | §6.2 | Process RH documenté | OK |
| A.6.5 | Responsibilities after termination | §6.3 | NDA actif post-emploi | OK |
| A.6.6 | Confidentiality or non-disclosure agreements | §6.1 | NDA signé par tous | OK |
| A.6.7 | Remote working | §6.2, §15.3 | VPN + MFA + endpoint hardening | OK |
| A.6.8 | Information security event reporting | §14.1 | Channel #sec-incident + email | OK |
A.7 — Contrôles physiques (Physical)
| ID | Contrôle ISO | PAS § | Implémentation Noxys | Statut |
|---|---|---|---|---|
| A.7.1 | Physical security perimeters | §7 | OVH datacenters ISO 27001 + bureaux badge + alarme | OK |
| A.7.2 | Physical entry | §7.3 | Badge nominatif + journal | OK |
| A.7.3 | Securing offices, rooms and facilities | §7.3 | Salle sensible, contrôle d'accès | OK |
| A.7.4 | Physical security monitoring | §7.3 | Vidéosurveillance + alarme télésurveillée | OK |
| A.7.5 | Protecting against physical and environmental threats | §7.1 | OVH multi-AZ, incendie/inondation/électricité | OK |
| A.7.6 | Working in secure areas | §7.3 | Visiteurs accompagnés | OK |
| A.7.7 | Clear desk and clear screen | §6.2 | Charte sécurité | OK |
| A.7.8 | Equipment siting and protection | §7 | Hébergement OVH exclusif | OK |
| A.7.9 | Security of assets off-premises | §6.2, §6.3 | Endpoint management Intune/MDM | OK |
| A.7.10 | Storage media | §5, §8.4 | Chiffrement at-rest AES-256, destruction certifiée | OK |
| A.7.11 | Supporting utilities | §7.1 | OVH redondance électrique N+1 | OK |
| A.7.12 | Cabling security | §7.1 | Géré par OVH | OK |
| A.7.13 | Equipment maintenance | §7.1 | OVH SLA matériel | OK |
| A.7.14 | Secure disposal or re-use of equipment | §5.3 | Crypto-shred + destruction OVH | OK |
A.8 — Contrôles technologiques (Technological)
| ID | Contrôle ISO | PAS § | Implémentation Noxys | Statut |
|---|---|---|---|---|
| A.8.1 | User end point devices | §6.2 | MDM + chiffrement disque obligatoire | OK |
| A.8.2 | Privileged access rights | §9.3 | JIT + WebAuthn + bastion | OK |
| A.8.3 | Information access restriction | §9 | RBAC fine-grained, tenant isolation | OK |
| A.8.4 | Access to source code | §12 | Github EU, 2-factor, branch protection | OK |
| A.8.5 | Secure authentication | §9.1, §10 | SSO + MFA + Argon2id | OK |
| A.8.6 | Capacity management | §15 | Auto-scaling + monitoring | OK |
| A.8.7 | Protection against malware | §8 | EDR + sandbox + scan email | OK |
| A.8.8 | Management of technical vulnerabilities | §8.3, §12.2 | Trivy/Semgrep/OSV + 24h/72h SLA | OK |
| A.8.9 | Configuration management | §8, §12 | IaC Terraform versionné | OK |
| A.8.10 | Information deletion | §5.3, §10.2 | Crypto-shred + GDPR Art. 17 | OK |
| A.8.11 | Data masking | §5.2, §17.3 | Tier hashed / redacted par défaut | OK |
| A.8.12 | Data leakage prevention | §11, §17 | Sortie réseau EU-only, DLP intégré Noxys | OK |
| A.8.13 | Information backup | §8.4 | Hourly snap + WAL + DE-LIM | OK |
| A.8.14 | Redundancy of information processing facilities | §15.2 | Multi-AZ + multi-région | OK |
| A.8.15 | Logging | §8.5 | SIEM 18 mo + journaux structurés | OK |
| A.8.16 | Monitoring activities | §8.5 | Alertes 24×7 + astreinte | OK |
| A.8.17 | Clock synchronisation | §8 | NTP authentifié + chrony | OK |
| A.8.18 | Use of privileged utility programs | §9.3 | Sudo audité, sessions enregistrées | OK |
| A.8.19 | Installation of software on operational systems | §8, §12 | Immutable images, pas d'install manuelle | OK |
| A.8.20 | Networks security | §8.1, §11 | TOFU-3, deny-by-default | OK |
| A.8.21 | Security of network services | §8.1 | mTLS, service mesh | OK |
| A.8.22 | Segregation of networks | §8.2 | 3 zones (DMZ, prod, observabilité) | OK |
| A.8.23 | Web filtering | §11 | DNS filtering Quad9 + politique entreprise | OK |
| A.8.24 | Use of cryptography | §10 | AES-256-GCM + TLS 1.3 + Ed25519 | OK |
| A.8.25 | Secure development life cycle | §12.1 | SDLC schématisé + obligatoire | OK |
| A.8.26 | Application security requirements | §12 | OWASP ASVS L2 minimum | OK |
| A.8.27 | Secure system architecture and engineering principles | §8.1 | Defense-in-depth, least privilege | OK |
| A.8.28 | Secure coding | §12.2 | Standards documentés + reviews | OK |
| A.8.29 | Security testing in development and acceptance | §12.4 | SAST + DAST + pentest | OK |
| A.8.30 | Outsourced development | §13 | Pas de dev externalisé sur le core | OK |
| A.8.31 | Separation of development, test and production environments | §3.3, §12 | 3 environnements isolés (dev / staging / prod) | OK |
| A.8.32 | Change management | §8, §12 | Pull request + CI + double approval prod | OK |
| A.8.33 | Test information | §12.4 | Datasets synthétiques, pas de prod data | OK |
| A.8.34 | Protection of information systems during audit testing | §16.3 | Sandbox dédiés pentest | OK |
Résumé / Summary
| Theme | Total | OK | PARTIAL | PLANNED |
|---|---|---|---|---|
| A.5 Organizational | 37 | 37 | 0 | 0 |
| A.6 People | 8 | 8 | 0 | 0 |
| A.7 Physical | 14 | 14 | 0 | 0 |
| A.8 Technological | 34 | 34 | 0 | 0 |
| Total | 93 | 93 | 0 | 0 |
Évidences disponibles sur demande motivée client (NDA requis). Audit ISO/IEC 27001 par organisme accrédité COFRAC en cours — certification visée Q4 2026.
References
- ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27002:2022 — Information security controls
- ANSSI — PSSI-MCAS, RGS v2.0, SecNumCloud v3.2
- NIST SP 800-53 Rev. 5 (cross-reference)
- CIS Controls v8 (cross-reference)