Skip to main content
NOVACompliance

Frameworks

Available now

ISO/IEC 27001

The international standard for an information security management system, certified by an accredited body.

Overview

ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system.

Certification is granted by an accredited certification body following a two-stage audit and maintained through surveillance audits. The management system itself — context, leadership, planning, support, operation, evaluation and improvement — is assessed alongside the Annex A controls an organisation has determined to be applicable.

The Statement of Applicability is central: it records which controls apply, why, and how they are implemented.

Who this is for

  • Organisations needing internationally recognised information security certification
  • Suppliers to government, financial services and large enterprise
  • Groups consolidating several security programmes under one management system

Governance areas

Context and scope

Interested parties, boundaries of the management system and the issues that affect it.

Leadership and policy

Management commitment, the information security policy and assigned responsibilities.

Risk management

Risk assessment methodology, treatment plans and residual risk acceptance.

Annex A controls

Organisational, people, physical and technological controls determined to be applicable.

Performance evaluation

Internal audit, monitoring, measurement and management review.

How NOVA supports this framework

  • Maintain the Statement of Applicability alongside the controls it refers to
  • Run the risk assessment and treatment cycle with owners and acceptance records
  • Keep policies versioned, approved and scheduled for review
  • Plan internal audit activity and record findings against controls
  • Produce management review inputs from live records instead of reassembling them

Controls and evidence focus

  • Risk register entries with treatment plans and explicit acceptance
  • Statement of Applicability with justification for inclusion or exclusion
  • Internal audit reports and corrective actions
  • Awareness and competence records for people controls

Cross-framework reuse

Annex A control evidence maps extensively onto SOC 2 Trust Services Criteria

Technical controls overlap with Essential Eight mitigation strategies

The management system structure is reused when adding ISO/IEC 42001

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Structure

Management system clauses and Annex A themes

Certification assesses the management system clauses alongside the Annex A controls determined to be applicable in the Statement of Applicability.

Clauses 4–5

Context and leadership

Interested parties, scope boundaries, the information security policy and assigned responsibilities.

Clauses 6–7

Planning and support

Risk assessment and treatment methodology, objectives, competence, awareness and documented information.

Clauses 8–10

Operation and improvement

Operational planning, internal audit, management review, nonconformity and corrective action.

Annex A.5

Organisational controls

Policies, roles, supplier relationships, incident management and continuity arrangements.

Annex A.6

People controls

Screening, terms of employment, awareness, disciplinary process and post-employment obligations.

Annex A.7

Physical controls

Secure areas, equipment protection, clear desk and secure disposal.

Annex A.8

Technological controls

Access control, cryptography, logging, secure development and network security.

Evidence

Typical evidence held in NOVA

The Statement of Applicability anchors the record: each applicable control needs implementation evidence, and each exclusion needs a justification.

ArtefactTypical sourceExpected cadence
Statement of ApplicabilityNOVA control registerOn change
Risk register and treatment planNOVA risk moduleQuarterly review
Internal audit reportInternal or external auditorAnnual programme
Management review minutesManual uploadAnnual
Awareness training recordsLearning platform exportAnnual
Supplier assessmentNOVA vendor registerAnnual

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

How it runs

Working through ISO/IEC 27001 in NOVA

  1. Step 1

    Define scope

    Set the boundaries of the management system and the interested parties it must satisfy.

  2. Step 2

    Assess risk

    Run the risk assessment, agree treatments and record residual risk acceptance.

  3. Step 3

    Build the SoA

    Decide which Annex A controls apply, justify exclusions and link implementation evidence.

  4. Step 4

    Operate and audit

    Run the controls, complete the internal audit programme and hold management review.

  5. Step 5

    Stage 1 and Stage 2

    The certification body reviews documentation, then tests implementation. Surveillance audits follow.

Questions

ISO 27001 questions we are asked

Does NOVA certify our ISMS?
No. Certification is granted only by an accredited certification body. NOVA maintains the management system record — scope, risk, Statement of Applicability, audit and review — that the body assesses.
Do we have to implement every Annex A control?
No. Annex A is a reference set. You determine applicability through risk assessment and record the reasoning in the Statement of Applicability, which NOVA keeps beside the controls it refers to.
How does this relate to ISO/IEC 42001?
Both use the same management system clause structure, so an existing ISO/IEC 27001 programme can be extended to AI governance rather than rebuilt.

Pricing

Plans that cover ISO 27001

Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.

Launch

AUD $99 /month

A first certification or attestation programme run properly from the start.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Compare plans

Growth

Most chosen

AUD $249 /month

Multiple frameworks on one shared control set, with reuse across requirements.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Compare plans

Professional

AUD $499 /month

Assurance-grade operation with external review workflows included.

  • Everything in Growth
  • Auditor Portal with scoped engagement access
  • Trust Centre publication
  • Asset register and classification
Compare plans

Enterprise

On request

Quoted per organisation against scope, users and assurance requirements.

  • Everything in Business
  • Scope defined per organisation
  • Commercial terms agreed with Eredox
  • Structured onboarding programme
Compare plans

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

Getting started

How to start with ISO 27001

Four steps from an empty workspace to a reviewable readiness position.

  1. Step 1

    Activate the framework

    Create the workspace and activate ISO 27001 so its requirements load into your control set.

  2. Step 2

    Assign control ownership

    Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.

  3. Step 3

    Map and validate evidence

    Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.

  4. Step 4

    Review readiness

    Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Talk to us

Ask about ISO/IEC 27001

Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Forms are not connected yet. Please email compliance@eredox.com.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.