Frameworks
Available nowISO/IEC 27001
The international standard for an information security management system, certified by an accredited body.
Overview
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system.
Certification is granted by an accredited certification body following a two-stage audit and maintained through surveillance audits. The management system itself — context, leadership, planning, support, operation, evaluation and improvement — is assessed alongside the Annex A controls an organisation has determined to be applicable.
The Statement of Applicability is central: it records which controls apply, why, and how they are implemented.
Who this is for
- Organisations needing internationally recognised information security certification
- Suppliers to government, financial services and large enterprise
- Groups consolidating several security programmes under one management system
Governance areas
Context and scope
Interested parties, boundaries of the management system and the issues that affect it.
Leadership and policy
Management commitment, the information security policy and assigned responsibilities.
Risk management
Risk assessment methodology, treatment plans and residual risk acceptance.
Annex A controls
Organisational, people, physical and technological controls determined to be applicable.
Performance evaluation
Internal audit, monitoring, measurement and management review.
How NOVA supports this framework
- Maintain the Statement of Applicability alongside the controls it refers to
- Run the risk assessment and treatment cycle with owners and acceptance records
- Keep policies versioned, approved and scheduled for review
- Plan internal audit activity and record findings against controls
- Produce management review inputs from live records instead of reassembling them
Controls and evidence focus
- Risk register entries with treatment plans and explicit acceptance
- Statement of Applicability with justification for inclusion or exclusion
- Internal audit reports and corrective actions
- Awareness and competence records for people controls
Cross-framework reuse
Annex A control evidence maps extensively onto SOC 2 Trust Services Criteria
Technical controls overlap with Essential Eight mitigation strategies
The management system structure is reused when adding ISO/IEC 42001
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
Structure
Management system clauses and Annex A themes
Certification assesses the management system clauses alongside the Annex A controls determined to be applicable in the Statement of Applicability.
Context and leadership
Interested parties, scope boundaries, the information security policy and assigned responsibilities.
Planning and support
Risk assessment and treatment methodology, objectives, competence, awareness and documented information.
Operation and improvement
Operational planning, internal audit, management review, nonconformity and corrective action.
Organisational controls
Policies, roles, supplier relationships, incident management and continuity arrangements.
People controls
Screening, terms of employment, awareness, disciplinary process and post-employment obligations.
Physical controls
Secure areas, equipment protection, clear desk and secure disposal.
Technological controls
Access control, cryptography, logging, secure development and network security.
Evidence
Typical evidence held in NOVA
The Statement of Applicability anchors the record: each applicable control needs implementation evidence, and each exclusion needs a justification.
| Artefact | Typical source | Expected cadence |
|---|---|---|
| Statement of Applicability | NOVA control register | On change |
| Risk register and treatment plan | NOVA risk module | Quarterly review |
| Internal audit report | Internal or external auditor | Annual programme |
| Management review minutes | Manual upload | Annual |
| Awareness training records | Learning platform export | Annual |
| Supplier assessment | NOVA vendor register | Annual |
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
How it runs
Working through ISO/IEC 27001 in NOVA
- Step 1
Define scope
Set the boundaries of the management system and the interested parties it must satisfy.
- Step 2
Assess risk
Run the risk assessment, agree treatments and record residual risk acceptance.
- Step 3
Build the SoA
Decide which Annex A controls apply, justify exclusions and link implementation evidence.
- Step 4
Operate and audit
Run the controls, complete the internal audit programme and hold management review.
- Step 5
Stage 1 and Stage 2
The certification body reviews documentation, then tests implementation. Surveillance audits follow.
Questions
ISO 27001 questions we are asked
- Does NOVA certify our ISMS?
- No. Certification is granted only by an accredited certification body. NOVA maintains the management system record — scope, risk, Statement of Applicability, audit and review — that the body assesses.
- Do we have to implement every Annex A control?
- No. Annex A is a reference set. You determine applicability through risk assessment and record the reasoning in the Statement of Applicability, which NOVA keeps beside the controls it refers to.
- How does this relate to ISO/IEC 42001?
- Both use the same management system clause structure, so an existing ISO/IEC 27001 programme can be extended to AI governance rather than rebuilt.
Capabilities that support this framework
Pricing
Plans that cover ISO 27001
Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.
Launch
AUD $99 /month
A first certification or attestation programme run properly from the start.
- One activated framework
- Control ownership and review cadence
- Evidence mapping and reviewer validation
- Policy versioning and approval
Growth
Most chosenAUD $249 /month
Multiple frameworks on one shared control set, with reuse across requirements.
- Multiple activated frameworks
- Cross-framework control and evidence reuse
- Risk register with treatment and acceptance
- GitHub evidence connector
Professional
AUD $499 /month
Assurance-grade operation with external review workflows included.
- Everything in Growth
- Auditor Portal with scoped engagement access
- Trust Centre publication
- Asset register and classification
Enterprise
On request
Quoted per organisation against scope, users and assurance requirements.
- Everything in Business
- Scope defined per organisation
- Commercial terms agreed with Eredox
- Structured onboarding programme
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
Getting started
How to start with ISO 27001
Four steps from an empty workspace to a reviewable readiness position.
- Step 1
Activate the framework
Create the workspace and activate ISO 27001 so its requirements load into your control set.
- Step 2
Assign control ownership
Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.
- Step 3
Map and validate evidence
Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.
- Step 4
Review readiness
Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
Talk to us
Ask about ISO/IEC 27001
Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.