Frameworks · ISO/IEC 27001:2022

Technical controls, documented.

Pentr packages technical-vulnerability and security-testing evidence the way surveillance auditors expect to receive it. Annex A controls A.8.8 and A.8.29 map to phases in the agent, and the locker hands your auditor a signed, control-mapped deliverable.

Annex A theme
Technological
Controls mapped
7 controls
Cadence
Surveillance + annual
Auditor-tested
9 firms
Controls covered

Annex A — tested and sealed.

Each row is a 2022 Annex A control, the phase in the agent that satisfies it, and the deliverables the locker holds for your auditor.

ID
Control
Phase
Artifacts
A.8.8
Management of technical vulnerabilities
The core control — discovery, validation, and remediation evidence.
04 · vuln analysis
14 sealed
A.8.29
Security testing in development and acceptance
Confirmed exploit with a re-viewable proof, sealed to the locker.
05 · exploitation
11 sealed
A.8.19
Installation of software on operational systems
Detects unauthorised or unmanaged software surfaces.
03 · threat modeling
4 sealed
A.8.15
Logging
Cross-references detector logs with the run timeline.
02 · intelligence
3 sealed
A.8.16
Monitoring activities
Every agent action logged, signed, and attributable.
07 · reporting
2 sealed
A.8.32
Change management
Re-runs the failing phase after remediation, signed.
05 + 07
3 sealed
A.8.31
Separation of development, test and production
Verifies isolation between prod and out-of-scope networks.
03 · threat modeling
4 sealed
Phase → control mapping

Where each phase earns its evidence.

01 · Pre-engagement

Scope & consent

Locks the scope and seals a signed consent attestation.

A.8.32
02 · Intelligence

Surface & logs

Identifies in-scope operational surfaces and log sources.

A.8.15
03 · Threat modeling

Software & environments

Enumerates installed software and environment boundaries.

A.8.19A.8.31
04 · Vuln analysis

Technical vuln mgmt

The A.8.8 core — matched against KEV + NIST NVD.

A.8.8A.8.7
05 · Exploitation

Confirmed exploit

Re-viewable chain proving the vulnerability is live.

A.8.29
06 · Post-exploitation

Isolation checks

Verifies separation between prod and out-of-scope nets.

A.8.31
07 · Reporting

Locker seal

sha-256 chain signed at seal time. Surveillance-ready.

A.8.16A.8.32

Run your next surveillance cycle.

Plug in a scope. The agent works the Annex A technological controls, and the locker hands your auditor a signed, control-mapped deliverable before the surveillance visit.