Skip to content
Sentinel Unity
International standard

ISO/IEC 27001: Information Security Management

The management-system standard most groups use as their anchor. Its value in a multi-framework programme is that almost everything else maps to it, which makes it a sensible primary standard for a shared control library.

Published by ISO and IEC. Commonly the standard a control is marked primary against, with national and sector frameworks mapped onto it.

Control

Privileged access is reviewed each quarter by the system owner

PeopleProcessTechnologyDataFacility

PPTDF applicability

One owner · one procedure · one evidence trail

Annex A

Control set

0 to 5

Maturity scored

Primary

Standard per control

Graded

Mapping to other standards

Structure

Annex A themes

A sample of the control areas. The full set lives in the library, where each control carries its own mappings.

Information security policies

Direction set at the top, and the review cycle that keeps it current.

  • Approval
  • Review cycle
  • Communication

Organisation of information security

Defined roles, separation of conflicting duties, and contact with authorities.

  • Roles
  • Segregation of duties
  • Authority contact

Asset management

Inventory, ownership, classification, and acceptable use.

  • Inventory
  • Ownership
  • Classification

Access control

Who holds which rights, how that is reviewed, and how privilege is contained.

  • User access
  • Privileged access
  • Review

Supplier relationships

Security in supplier agreements and monitoring of delivery against them.

  • Agreements
  • Monitoring
  • Change

Incident management

Reporting, assessment, response, and learning from what happened.

  • Reporting
  • Response
  • Evidence
  • Learning

Platform mapping

Using it as your primary standard

One primary standard per control

A control appears once in the tree under its primary standard, which stops the same requirement being maintained in several places.

Everything else maps onto it

National and sector frameworks map to the same controls, each mapping carrying a level rather than a tick.

Equivalence and crosswalks

Where two standards express the same requirement differently, the equivalence is recorded and applied rather than rediscovered.

Custom controls alongside

Requirements of your own become company-scoped controls with generated identifiers and a full authorship trail.

Scoped per company

Which frameworks apply is a property of the company record, so a group can run different scopes across its entities.

Readiness, not a certificate

Domain-level maturity shows where a programme stands. Sentinel Unity is not a certification body and does not claim to be one.

Maturity

How maturity is scored

Every Annex A control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

Anchor a multi-framework programme on one control library

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.