FeaturesCompliance Reports

ISO/IEC 27001:2022 Evidence Report

Evidence for ISO 27001 Annex A change management controls — A.8.32 Change Management, A.8.25 Secure Development Lifecycle, A.8.34 Protection During Audit Testing.

Overview

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). Annex A contains 93 controls grouped into organizational, people, physical, and technological domains.

Koalr's ISO 27001 report focuses on three Annex A controls from the technological domain that are directly evidenced by engineering change management data. The report is designed for delivery to an accredited certification body or internal ISMS auditor.

Controls covered

A.8.32 — Change Management

Control language: Changes to information processing facilities and information systems shall be subject to change management procedures.

Koalr evidence: Every merged pull request has a recorded peer review, approver, and risk score prior to merge. Pass rate: percentage of merged PRs with required approval before merge.

A.8.25 — Secure Development Life Cycle

Control language: Rules for the secure development of software and systems shall be established and applied.

Koalr evidence: Automated deploy risk scoring, DDL migration detection, and blast radius analysis run on every PR before merge. Pass rate: percentage of merged PRs with a recorded risk assessment.

A.8.34 — Protection of Information Systems During Audit Testing

Control language: Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed to minimize disruptions.

Koalr evidence: CODEOWNERS enforcement restricts changes to protected paths during audit windows. Pass rate: percentage of merged PRs with no CODEOWNERS violation.

Report output

  • Dark navy cover page with ISO 27001 Annex A control badges and metadata block prepared for ISO 27001 Certification Body / Internal Audit
  • Executive summary with six KPI tiles
  • Per-control detail blocks with status badge and evidence count
  • Change log table with approval, CODEOWNERS, and risk columns
  • Page number footer with CONFIDENTIAL marking
  • Machine-readable CSV export with all PR-level evidence fields

Generating a report

  1. Navigate to ComplianceISO 27001:2022
  2. Select your reporting period (typically 12 months for certification, shorter for surveillance audits)
  3. Click Download evidence package (PDF) or Export CSV

ISMS integration

For an ISO 27001-certified ISMS, the Koalr report supports:

  • Stage 2 certification audit: Evidence for Annex A.8.32, A.8.25, A.8.34 change management controls
  • Surveillance audits: Quarterly or annual evidence of control operation
  • Internal audits: Continuous monitoring between external audits
  • Management reviews: KPI tiles provide inputs for ISMS performance reporting

Integration requirements

  • GitHub (required) — provides PRs, reviews, CODEOWNERS files
  • Optional: Confluence/Jira integration for policy-to-evidence traceability

Certification body review notes

  • The PDF cover page explicitly names "ISO 27001 Certification Body / Internal Audit" in the Prepared For field
  • Evidence is generated point-in-time from live data
  • Controls are scored EVIDENCED (95%+ coverage), PARTIAL (50–95%), or NOT_COVERED (< 50% or no changes)
  • For the full Annex A control set (93 controls), pair the Koalr report with your broader ISMS documentation

Disclaimer

This report is designed to support ISO 27001 evidence collection. It does not constitute a formal certification. Engage an accredited certification body for ISO 27001 certification.