🌐 ISO/IEC 27001:2022 Annex A Container & Cloud Compliance Suite
Gubernator features a continuous, automated compliance engine built directly into its core to evaluate and enforce ISO/IEC 27001:2022 Annex A controls across distributed container environments and cloud infrastructure.
This guide details the technical implementation, Annex A control mappings, real-time scoring algorithm, CLI commands, REST endpoints, and formal Statement of Applicability (SoA) generation.
🏛️ 1. Architecture & Compliance Overview
ISO/IEC 27001:2022 restructured information security controls into four comprehensive themes (A.5 Organizational, A.6 People, A.7 Physical, and A.8 Technological). Gubernator automates the evaluation of the 24 critical technological and organizational controls directly governing cloud container orchestration, cluster networking, access management, cryptographic key lifecycles, and resilient operational telemetry.
┌────────────────────────────────────────────────────────────────────────┐
│ GUBERNATOR ISO/IEC 27001:2022 ENGINE │
├───────────────────────────────────┬────────────────────────────────────┤
│ Theme A.5: Organizational │ Theme A.8: Technological │
│ • A.5.15 Access Control Policy │ • A.8.1 User Endpoint & MFA │
│ • A.5.23 Cloud Services Security │ • A.8.2 Privileged Access Rights │
│ • A.5.29 ICT Readiness Continuity │ • A.8.3 Access Restriction │
│ • A.5.30 Continuity Redundancies │ • A.8.7 Protection vs Malware │
│ │ • A.8.8 Vulnerability Management │
│ │ • A.8.9 Configuration Management │
│ │ • A.8.12 Data Leakage Prevention │
│ │ • A.8.13 Information Backup │
│ │ • A.8.15 Logging & Audit Chain │
│ │ • A.8.16 Monitoring Activities │
│ │ • A.8.17 Clock Synchronization │
│ │ • A.8.20 Network Ingress Security │
│ │ • A.8.21 Network Service Security │
│ │ • A.8.22 Network Segregation │
│ │ • A.8.24 Cryptography & Cosign │
│ │ • A.8.25 Secure Development SDLC │
│ │ • A.8.26 App Security Containment │
│ │ • A.8.28 Supply Chain & SBOMs │
│ │ • A.8.31 Separation of Dev/Prod │
│ │ • A.8.32 Change Management Audit │
└───────────────────────────────────┴────────────────────────────────────┘
📋 2. Evaluated Annex A Controls Matrix
| Control ID | Theme | Title | Compliance Target | Discovered Cluster Telemetry |
|---|---|---|---|---|
| A.5.15 | A.5 Org | Access Control Policy | RBAC Separation | Validates distinct admin, operator, and auditor roles |
| A.5.23 | A.5 Org | Cloud Services Security | Isolated API Ports | Port 4000 Bearer token auth, Port 4001 JWT session isolation |
| A.5.29 | A.5 Org | ICT Readiness Continuity | Scheduled Backups | Scheduled cron backup policies across cluster volumes |
| A.5.30 | A.5 Org | Redundancy Requirements | Multi-Host Resilience | Multi-node Centurion cluster topology verification |
| A.8.1 | A.8 Tech | Secure Authentication & MFA | TOTP MFA & Lockout | Enforces MFA, <=5 failed logins, <=15 min session timeout |
| A.8.2 | A.8 Tech | Privileged Access Rights | Restricted Admins | Limits full admin accounts to designated personnel |
| A.8.3 | A.8 Tech | Information Access Restriction | Stack Segregation | Docker bridge network namespace isolation and label affinity |
| A.8.7 | A.8 Tech | Protection Against Malware | Vulnerability Defense | Container CVE vulnerability scanning and Gatekeeper admission |
| A.8.8 | A.8 Tech | Vulnerability Management | Critical CVE Threshold | Gates deployments on unpatched Critical CVEs (CVSS >= 9.0) |
| A.8.9 | A.8 Tech | Configuration Management | Declarative Tracking | Versioned Compose state tracking and drift detection |
| A.8.12 | A.8 Tech | Data Leakage Prevention | Masking & Redaction | Automated redaction of sensitive tokens and env variables |
| A.8.13 | A.8 Tech | Information Backup | AES-256-GCM Backups | PBKDF2 key derivation and SHA-256 integrity verification |
| A.8.15 | A.8 Tech | Logging & Immutable Records | SHA-256 Chain & SIEM | Blockchain-style cryptographic hash chaining and Syslog RFC 5424 |
| A.8.16 | A.8 Tech | Monitoring Activities | Continuous Observability | Prometheus metrics, health probes, Loki logs, and Jaeger tracing |
| A.8.17 | A.8 Tech | Clock Synchronization | NTP Consensus | Cluster node time synchronization verification |
| A.8.20 | A.8 Tech | Network Security & Ingress | Automated TLS Ingress | Caddy reverse proxy automated ACME TLS and CoreDNS discovery |
| A.8.21 | A.8 Tech | Security of Network Services | Join-Token Authorization | Cryptographic node join tokens and mutual API authentication |
| A.8.22 | A.8 Tech | Segregation of Networks | Container Isolation | Subnet-isolated Docker bridge networks per application stack |
| A.8.24 | A.8 Tech | Use of Cryptography | ECDSA Image Signing | Cosign ECDSA P-256 keys, TLS 1.3 in transit, AES-GCM at rest |
| A.8.25 | A.8 Tech | Secure Development Life Cycle | Pre-Flight Validation | Compose syntax linting, Gatekeeper admission verification |
| A.8.26 | A.8 Tech | Application Security Requirements | Runtime Containment | Enforces no-new-privileges, capability dropping, non-root user |
| A.8.28 | A.8 Tech | Supply Chain Security | CycloneDX/SPDX SBOMs | Automated dependency software bill of materials and license audit |
| A.8.31 | A.8 Tech | Separation of Environments | Staging / Prod Isolation | Hardware labels (gbnt.node.env) and placement constraints |
| A.8.32 | A.8 Tech | Change Management | Deployment Auditing | Immutable deployment audit records with rollback capabilities |
🧮 3. Scoring Methodology & Posture Grade
Each control is evaluated dynamically as COMPLIANT (100%), PARTIAL (60–85%), or NON_COMPLIANT (0–25%):
$$\text{Overall Readiness Score (\%)} = \frac{1}{N} \sum_{i=1}^{N} \text{Score}_i$$
Theme scores are calculated independently for Theme A.5 (Organizational) and Theme A.8 (Technological).
Posture Grade Scale
- Grade A+ (>= 95%): Pristine compliance posture across all Annex A themes.
- Grade A (>= 85%): Production-ready compliance; minimal non-critical gaps.
- Grade B (>= 75%): Good security baseline; several defense-in-depth controls require attention.
- Grade C (>= 60%): Noticeable configuration gaps; remediation recommended.
- Grade D (< 60%): Critical non-compliance; immediate remediation required.
💻 4. CLI Usage
The gbnt CLI provides native commands to inspect ISO/IEC 27001 readiness directly from your terminal:
Quick Terminal Audit
=========================================================================================
🌐 ISO/IEC 27001:2022 | ANNEX A COMPLIANCE AUDIT
=========================================================================================
Posture Grade: A
Overall Readiness: 92.4%
Theme A.5 (Org): 95.0%
Theme A.8 (Tech): 91.9%
Controls Evaluated: 24 (20 Compliant, 4 Partial, 0 Non-Compliant)
-----------------------------------------------------------------------------------------
CONTROL THEME STATUS TITLE EVIDENCE
-----------------------------------------------------------------------------------------
A.5.15 A.5 Organizational ✅ COMPLIANT Access Control Policy &... Role-Based Access Cont...
A.5.23 A.5 Organizational ✅ COMPLIANT Information Security fo... Cluster API secured on...
A.5.29 A.5 Organizational ✅ COMPLIANT Information Security Re... 1 automated backup sch...
A.5.30 A.5 Organizational ✅ COMPLIANT ICT Readiness for Redun... Multi-node HA cluster ...
A.8.1 A.8 Technological ✅ COMPLIANT User Endpoint Devices &... Account lockout (3 att...
A.8.7 A.8 Technological ✅ COMPLIANT Protection Against Malw... 1 container image vuln...
A.8.8 A.8 Technological ✅ COMPLIANT Management of Technical... Continuous vulnerabili...
A.8.9 A.8 Technological ✅ COMPLIANT Configuration Managemen... All 3 stacks authored ...
A.8.13 A.8 Technological ✅ COMPLIANT Information Backup 1 total backups creat...
A.8.15 A.8 Technological ✅ COMPLIANT Logging 120 audit events reco...
A.8.16 A.8 Technological ✅ COMPLIANT Monitoring Activities Integrated SRE observ...
A.8.20 A.8 Technological ✅ COMPLIANT Network Security Automated Caddy Ingre...
A.8.24 A.8 Technological ✅ COMPLIANT Use of Cryptography 1 Cosign ECDSA P-256 ...
A.8.28 A.8 Technological ✅ COMPLIANT Secure Coding & Supply ... 1 Software Bill of Mat...
=========================================================================================
Tip: Run 'gbnt iso27001 --report' to display the formal Statement of Applicability (SoA).
Tip: Run 'gbnt iso27001 --theme a8' or 'gbnt iso27001 --status partial' to filter.
Filtering Controls
# Filter by Technological controls (Theme A.8)
gbnt iso27001 --theme a8
# Filter by Organizational controls (Theme A.5)
gbnt iso27001 --theme a5
# Filter by status
gbnt iso27001 --status partial
Statement of Applicability (SoA) Report
JSON Export for CI/CD Pipelines
🌐 5. REST API Reference
All endpoints are authenticated via Bearer token on Port 4000:
1. Get Live Compliance Assessment
Response (200 OK):
{
"evaluated_at": "2026-09-13T15:00:00Z",
"standard_version": "ISO/IEC 27001:2022",
"total_controls": 24,
"compliant_count": 20,
"partial_count": 4,
"non_compliant_count": 0,
"overall_score": 92.4,
"theme_a5_score": 95.0,
"theme_a8_score": 91.9,
"posture_grade": "A",
"statement_of_applicability": "ISO/IEC 27001:2022 Statement of Applicability: 24 Controls Evaluated (20 Compliant, 4 Partial, 0 Non-Compliant). Readiness Score: 92.4% (Grade A).",
"controls": [
{
"id": "A.5.15",
"theme": "A.5 Organizational",
"title": "Access Control Policy & Least Privilege",
"description": "Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.",
"status": "COMPLIANT",
"score": 100.0,
"weight": 1.0,
"evidence": "Role-Based Access Control enforced across 3 users. Admin, operator, and audit roles segregated.",
"remediation": "Ensure distinct operator and auditor accounts exist in addition to administrator.",
"audit": "Inspect /v1/auth/users or LDAP group mappings to ensure least privilege role separation."
}
]
}
2. Export Statement of Applicability Report
🖥️ 6. Flutter Web UI Dashboard
Access the interactive dashboard by navigating to: Security & Directory ➔ Compliance & Regulatory Suite ➔ 🌐 ISO/IEC 27001:2022 (Annex A).
Dashboard Capabilities
- Header Banner: Displays current compliance standard with "Re-Audit" and "Export SoA Report" buttons.
- 4 Executive KPI Cards:
- POSTURE GRADE: Instant letter grade badge (
A+,A,B,C,D) with qualitative verdict. - READINESS SCORE: Overall percentage readiness bar.
- THEME A.5 (ORGANIZATIONAL): Dedicated progress gauge for organizational governance controls.
- THEME A.8 (TECHNOLOGICAL): Dedicated progress gauge for technical container & infrastructure controls.
- Interactive Filter Bar: Filter controls by Theme (
All (24),A.5,A.8) and Status (All,Action Required,Compliant,Partial,Non-Compliant). - Interactive Remediation Dialog: Clicking "Remediation" on any card opens an inspection modal showing:
- Formal ISO requirement description.
- Discovered cluster configuration evidence.
- Prescriptive step-by-step remediation advice with one-click clipboard copy.
- Exact auditor verification procedure.
- Report Export: Instantly download the official Statement of Applicability as Plain Text (
.txt) or JSON (.json) for audit submissions.