---
title: "Control ISO 27001: framework alignment | Firevault"
description: "Satisfy ISO 27001 Annex A network controls with physical evidence. Control provides auditable proof of network segmentation and access control. See how."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/solutions/control/frameworks/iso-27001#webpage",
      "url": "https://fire-vault.com/solutions/control/frameworks/iso-27001",
      "name": "Control ISO 27001: framework alignment",
      "description": "Satisfy ISO 27001 Annex A network controls with physical evidence. Control provides auditable proof of network segmentation and access control. See how.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-solutions.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/solutions/control/frameworks/iso-27001#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/solutions/control/frameworks/iso-27001#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Solutions",
          "item": "https://fire-vault.com/solutions"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control",
          "item": "https://fire-vault.com/solutions/control"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Frameworks",
          "item": "https://fire-vault.com/solutions/control/frameworks"
        },
        {
          "@type": "ListItem",
          "position": 5,
          "name": "Control ISO 27001: framework alignment",
          "item": "https://fire-vault.com/solutions/control/frameworks/iso-27001"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

ISO 27001 

# Physical Enforcement of Annex A Controls 

ISO 27001 requires organisations to implement appropriate controls from Annex A. Control provides physical enforcement for network segmentation, access control, and business continuity controls that demonstrate a higher standard of protection.

Schedule a Demo[Back to Control](/solutions/control)

![Rows of locked server cabinets inside a secure Firevault data hall](/__l5e/assets-v1/a4d3902c-28a5-42f4-bbfb-c12ddaacce1b/hero-square-drive.png)

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Annex A controls with physical enforcement

14 Annex A controls with physical enforcement 

02 

Network segmentation physical evidence

100% Network segmentation physical evidence 

03 

Technology controls with physical backing

A.8 Technology controls with physical backing 

04 

Continuous ISMS evidence generation

Full Continuous ISMS evidence generation 

The Certification Challenge 

## Demonstrating control effectiveness is difficult.

01 

### Point-in-Time Audits

ISO 27001 surveillance audits capture a snapshot. Between audits, control effectiveness can degrade through configuration drift, human error, or undocumented changes.

02 

### Network Control Evidence

Demonstrating continuous network segmentation effectiveness requires evidence that logical controls have been maintained without interruption.

03 

### Access Control Gaps

Access reviews happen periodically, but between reviews, excessive access can accumulate as roles change and projects begin and end.

ISO 27001

> ISO 27001 certification demonstrates intent. Physical control enforcement demonstrates reality. The gap between the two is where breaches happen.

The Scenario

### Scenario: Surveillance Audit with Physical Evidence

During an ISO 27001 surveillance audit, the auditor examines network segmentation controls under Annex A.8.22 (Network segmentation). The organisation presents twelve months of continuous physical boundary state logs showing unbroken zone separation. Every conduit activation is documented with multi-party authorisation records, time stamps, and data flow logs. The auditor notes that this level of continuous evidence exceeds what they typically see with software-only implementations, where gaps between configuration audits leave uncertainty about control effectiveness. With Control, the evidence is irrefutable. Physical boundaries were maintained continuously, and every exception was explicitly authorised and logged.

"Our previous auditor accepted our firewall rules as evidence of network segmentation. Our new auditor asked how we knew the rules had been continuously correct between audits. We could not answer that question with software-only controls."

ISO 27001 mapping 

## Where ISO 27001 Annex A controls meet Control modules.

ISO 27001:2022 reorganised Annex A into 93 controls across four themes. Control provides the physical and operational enforcement for the technological and people-facing controls that hold the boundary.

Reference: ISO/IEC 27001:2022 Annex A, themed under Organisational, People, Physical and Technological controls.

SEC 01

Organisational controls

-   A.5.14 
    
    Information transfer
    
    Outbound and inter-zone data movement is a governed Transfer event with inventory and evidence.
    
    ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    
-   A.5.15 
    
    Access control
    
    Reach is named, scoped and time-bound, not standing.
    
    ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay 
    
-   A.5.16 
    
    Identity management
    
    Departures and changes revoke standing trust at the boundary.
    
    ![FV-Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)Unlink 
    

SEC 02

People controls

-   A.6.8 
    
    Information security event reporting
    
    Reportable events are captured in tamper-evident form and sealed offline.
    
    ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    

SEC 03

Technological controls

-   A.8.13 
    
    Information backup
    
    Backups live in an offline vault that is not reachable on the live network.
    
    ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer 
    
-   A.8.16 
    
    Monitoring activities
    
    Continuous attestation of conduit and vault state, signed and stored offline.
    
    ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    
-   A.8.20 
    
    Network security
    
    Zone boundaries are physically severed by default.
    
    ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate 
    
-   A.8.22 
    
    Segregation of networks
    
    Cross-zone reach is a named Relay session, not a permanent route.
    
    ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay 
    

Modules & symbols

![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer Controlled move 

![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate Integrity check 

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock Named access 

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay Time-bound path 

![FV-Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)Unlink Remove trust 

![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive Disconnected copy 

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak Physical sever 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate Zone boundary 

Direct map Module satisfies clause 

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Physical Control Enforcement

Annex A controls are enforced physically, providing a higher standard of protection than software-only implementations.

02 

### Access Control Evidence

Every access authorisation, session, and revocation is documented in tamper-proof logs for ISMS records.

03 

### Continuous ISMS Evidence

Automated logging generates continuous evidence for Statement of Applicability controls, eliminating gaps between surveillance audits.

04 

### Segmentation Assurance

Physical network segmentation provides irrefutable evidence of zone separation for A.8.22 compliance.

05 

### Audit-Ready Documentation

Tamper-proof logs and automated reports provide complete audit trails ready for certification and surveillance audits.

06 

### Recovery Assurance

Verified control-plane baselines demonstrate ICT readiness for business continuity beyond what network-connected systems can provide.

Demo to Live

## Adoption Guide

Step 1 

#### SoA Mapping Assessment

Map your Statement of Applicability against Control module capabilities to identify where physical enforcement strengthens your ISMS.

Step 2 

#### Control Architecture Design

Design physical enforcement for priority Annex A controls, starting with network segmentation and access control.

Step 3 

#### Pre-Audit Validation

Deploy and validate continuous evidence generation before your next surveillance audit to demonstrate physical control effectiveness.

Step 4 

#### ISMS Integration

Full integration with your ISMS including continuous evidence generation, automated reporting, and tamper-evident compliance record preservation.

Step 1 

#### SoA Mapping Assessment

Map your Statement of Applicability against Control module capabilities to identify where physical enforcement strengthens your ISMS.

Step 2 

#### Control Architecture Design

Design physical enforcement for priority Annex A controls, starting with network segmentation and access control.

Step 3 

#### Pre-Audit Validation

Deploy and validate continuous evidence generation before your next surveillance audit to demonstrate physical control effectiveness.

Step 4 

#### ISMS Integration

Full integration with your ISMS including continuous evidence generation, automated reporting, and tamper-evident compliance record preservation.

[Organise a Demo](/contact)

## Explore More

[

### NIS2 Framework

Operational resilience for essential and important entities.

Learn more about NIS2 Framework ](/solutions/control/frameworks/nis2)[

### Cyber Essentials

UK baseline certification with physical isolation evidence.

Learn more about Cyber Essentials ](/solutions/control/frameworks/cyber-essentials)[

### NIST CSF Framework

Identify, protect, detect, respond, recover alignment.

Learn more about NIST CSF Framework ](/solutions/control/frameworks/nist-csf)

Questions

## Frequently Asked

Which Annex A controls does Control address? 

Does Control replace our existing ISMS? 

How does continuous evidence help during audits? 

Can Control support transition from ISO 27001:2013 to 2022?