Aller au contenu principal

ISO/IEC 27001:2022 Annex A — Mapping Noxys

Bilingue / Bilingual. Each control of ISO/IEC 27001:2022 Annex A is mapped to (i) the corresponding section of the Noxys PAS template and (ii) the Noxys technical control(s) that implement it.

ISO/IEC 27001:2022 Annex A regroups the 93 controls of ISO/IEC 27002:2022 into 4 themes:

  • A.5 — Organizational controls (37 controls)
  • A.6 — People controls (8 controls)
  • A.7 — Physical controls (14 controls)
  • A.8 — Technological controls (34 controls)

Statuts / Status legend:

  • OK — Implemented & verified
  • PARTIAL — Implemented, additional evidence in progress
  • PLANNED — In roadmap for 2026

A.5 — Contrôles organisationnels (Organizational)

IDContrôle ISOPAS §Implémentation NoxysStatut
A.5.1Policies for information security§4noxys-doc policy repo, revue annuelleOK
A.5.2Information security roles & responsibilities§3RACI documented, CISO appointedOK
A.5.3Segregation of duties§3.3feat → staging → main, double approval, separation dev/prodOK
A.5.4Management responsibilities§3.1Comité sécurité trimestriel, CEO sponsorOK
A.5.5Contact with authorities§14.3Liaisons CNIL, ANSSI, CERT-FR documentéesOK
A.5.6Contact with special interest groups§4CLUSIF, OWASP, FIRSTOK
A.5.7Threat intelligence§8, §12Trivy, OSV, CVE feeds, CERT-FROK
A.5.8Information security in project management§12Threat modeling per projectOK
A.5.9Inventory of information & other associated assets§5.1CMDB auto-updated via CIOK
A.5.10Acceptable use of information§6.2Charte sécurité signée par tousOK
A.5.11Return of assets§5.3, §6.3Process départ < 5 joursOK
A.5.12Classification of information§5.2C1-C4 schemaOK
A.5.13Labelling of information§5.2Metadata tagging in CMDB + S3OK
A.5.14Information transfer§11TLS 1.3, HMAC webhooks, no transfer outside EUOK
A.5.15Access control§9RBAC + SSO + MFAOK
A.5.16Identity management§9.1SSO SAML/OIDCOK
A.5.17Authentication information§9, §10Argon2id, no plaintext storageOK
A.5.18Access rights§9.2Quarterly review, JIT for prodOK
A.5.19Information security in supplier relationships§13CAIQ-Lite + DPA + audit annuelOK
A.5.20Addressing information security within supplier agreements§13.1DPA template, sub-processor listOK
A.5.21Managing information security in the ICT supply chain§12.3, §13SBOM, lockfiles, RenovateOK
A.5.22Monitoring, review and change management of supplier services§13.2Annual review, 30-day noticeOK
A.5.23Information security for use of cloud services§7, §17OVH ISO 27001 + HDS + SecNumCloud-in-progressOK
A.5.24Information security incident management planning§14Runbook + P0-P3 classificationOK
A.5.25Assessment and decision on information security events§14.2Triage CISO < 30 minOK
A.5.26Response to information security incidents§14.2Runbook documentedOK
A.5.27Learning from information security incidents§14.2Post-mortem < 5 daysOK
A.5.28Collection of evidence§14, §8.5SIEM, 18-month retentionOK
A.5.29Information security during disruption§15BCP / DR plan, semi-annual testOK
A.5.30ICT readiness for business continuity§15.2Multi-region failover OVHOK
A.5.31Legal, statutory, regulatory & contractual requirements§16GDPR, NIS 2, DORA trackerOK
A.5.32Intellectual property rights§6.1, §12Open source license compliance, NDAOK
A.5.33Protection of records§5, §8Retention 10 yrs (billing), 18 mo (logs)OK
A.5.34Privacy and protection of PII§10, §16, §17DPA, DPIA, KMS per-tenantOK
A.5.35Independent review of information security§16.3External pentest + ISO auditOK
A.5.36Compliance with policies, rules and standards§4, §16Annual reviewOK
A.5.37Documented operating procedures§8Runbooks in noxys-doc (internal)OK

A.6 — Contrôles humains (People)

IDContrôle ISOPAS §Implémentation NoxysStatut
A.6.1Screening§6.1Casier B3 pour accès prodOK
A.6.2Terms and conditions of employment§6.1NDA + charte sécuritéOK
A.6.3Information security awareness, education and training§6.2Formation < 30 jours + recyclage annuelOK
A.6.4Disciplinary process§6.2Process RH documentéOK
A.6.5Responsibilities after termination§6.3NDA actif post-emploiOK
A.6.6Confidentiality or non-disclosure agreements§6.1NDA signé par tousOK
A.6.7Remote working§6.2, §15.3VPN + MFA + endpoint hardeningOK
A.6.8Information security event reporting§14.1Channel #sec-incident + emailOK

A.7 — Contrôles physiques (Physical)

IDContrôle ISOPAS §Implémentation NoxysStatut
A.7.1Physical security perimeters§7OVH datacenters ISO 27001 + bureaux badge + alarmeOK
A.7.2Physical entry§7.3Badge nominatif + journalOK
A.7.3Securing offices, rooms and facilities§7.3Salle sensible, contrôle d'accèsOK
A.7.4Physical security monitoring§7.3Vidéosurveillance + alarme télésurveilléeOK
A.7.5Protecting against physical and environmental threats§7.1OVH multi-AZ, incendie/inondation/électricitéOK
A.7.6Working in secure areas§7.3Visiteurs accompagnésOK
A.7.7Clear desk and clear screen§6.2Charte sécuritéOK
A.7.8Equipment siting and protection§7Hébergement OVH exclusifOK
A.7.9Security of assets off-premises§6.2, §6.3Endpoint management Intune/MDMOK
A.7.10Storage media§5, §8.4Chiffrement at-rest AES-256, destruction certifiéeOK
A.7.11Supporting utilities§7.1OVH redondance électrique N+1OK
A.7.12Cabling security§7.1Géré par OVHOK
A.7.13Equipment maintenance§7.1OVH SLA matérielOK
A.7.14Secure disposal or re-use of equipment§5.3Crypto-shred + destruction OVHOK

A.8 — Contrôles technologiques (Technological)

IDContrôle ISOPAS §Implémentation NoxysStatut
A.8.1User end point devices§6.2MDM + chiffrement disque obligatoireOK
A.8.2Privileged access rights§9.3JIT + WebAuthn + bastionOK
A.8.3Information access restriction§9RBAC fine-grained, tenant isolationOK
A.8.4Access to source code§12Github EU, 2-factor, branch protectionOK
A.8.5Secure authentication§9.1, §10SSO + MFA + Argon2idOK
A.8.6Capacity management§15Auto-scaling + monitoringOK
A.8.7Protection against malware§8EDR + sandbox + scan emailOK
A.8.8Management of technical vulnerabilities§8.3, §12.2Trivy/Semgrep/OSV + 24h/72h SLAOK
A.8.9Configuration management§8, §12IaC Terraform versionnéOK
A.8.10Information deletion§5.3, §10.2Crypto-shred + GDPR Art. 17OK
A.8.11Data masking§5.2, §17.3Tier hashed / redacted par défautOK
A.8.12Data leakage prevention§11, §17Sortie réseau EU-only, DLP intégré NoxysOK
A.8.13Information backup§8.4Hourly snap + WAL + DE-LIMOK
A.8.14Redundancy of information processing facilities§15.2Multi-AZ + multi-régionOK
A.8.15Logging§8.5SIEM 18 mo + journaux structurésOK
A.8.16Monitoring activities§8.5Alertes 24×7 + astreinteOK
A.8.17Clock synchronisation§8NTP authentifié + chronyOK
A.8.18Use of privileged utility programs§9.3Sudo audité, sessions enregistréesOK
A.8.19Installation of software on operational systems§8, §12Immutable images, pas d'install manuelleOK
A.8.20Networks security§8.1, §11TOFU-3, deny-by-defaultOK
A.8.21Security of network services§8.1mTLS, service meshOK
A.8.22Segregation of networks§8.23 zones (DMZ, prod, observabilité)OK
A.8.23Web filtering§11DNS filtering Quad9 + politique entrepriseOK
A.8.24Use of cryptography§10AES-256-GCM + TLS 1.3 + Ed25519OK
A.8.25Secure development life cycle§12.1SDLC schématisé + obligatoireOK
A.8.26Application security requirements§12OWASP ASVS L2 minimumOK
A.8.27Secure system architecture and engineering principles§8.1Defense-in-depth, least privilegeOK
A.8.28Secure coding§12.2Standards documentés + reviewsOK
A.8.29Security testing in development and acceptance§12.4SAST + DAST + pentestOK
A.8.30Outsourced development§13Pas de dev externalisé sur le coreOK
A.8.31Separation of development, test and production environments§3.3, §123 environnements isolés (dev / staging / prod)OK
A.8.32Change management§8, §12Pull request + CI + double approval prodOK
A.8.33Test information§12.4Datasets synthétiques, pas de prod dataOK
A.8.34Protection of information systems during audit testing§16.3Sandbox dédiés pentestOK

Résumé / Summary

ThemeTotalOKPARTIALPLANNED
A.5 Organizational373700
A.6 People8800
A.7 Physical141400
A.8 Technological343400
Total939300

Évidences disponibles sur demande motivée client (NDA requis). Audit ISO/IEC 27001 par organisme accrédité COFRAC en cours — certification visée Q4 2026.

References

  • ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  • ISO/IEC 27002:2022 — Information security controls
  • ANSSI — PSSI-MCAS, RGS v2.0, SecNumCloud v3.2
  • NIST SP 800-53 Rev. 5 (cross-reference)
  • CIS Controls v8 (cross-reference)