Overview
ISO/IEC 27001 is the international standard for an information security management system, or ISMS. It certifies an organisation’s management system — its risk assessment, its policies, and the controls it selects and operates — rather than any single product. Its Annex A lists controls across areas such as access control, cryptography, logging and monitoring, and operational resilience. A product supports 27001 by providing technical controls the organisation can adopt as part of its ISMS. ControlBird provides several of those controls; the ISMS itself, and certification, belong to your organisation.
Key requirements
- Access control
- Restrict access to information and systems to authenticated, authorised users.
- Cryptography
- Protect information with appropriate cryptographic controls.
- Logging and monitoring
- Record events so that security-relevant activity can be reviewed and investigated.
- Operational resilience and continuity
- Protect the availability of information systems and the ability to recover from disruption.
How ControlBird aligns
- Access control
- Authentication through native accounts, LDAP and Active Directory, or OAuth 2.0, combined with access control enforced in the data layer: role- and attribute-based permission rules that grant a scope down to the entity type, the field, and a branch of the tree, with conditions evaluated at access time. Interface permissions are managed separately.
- Cryptography in transit
- TLS 1.2 and 1.3 across the web, the API, and the supported industrial protocols, with a built-in Certificate Manager for issuing, renewing, and monitoring certificates. Cryptographic protection of data at rest is provided by the operator through disk or volume encryption.
- Logging and monitoring
- Every field write is attributed to the authenticated user and stamped with a timestamp, recorded in the write-ahead log, and the historian can be configured to retain that change history for chosen entities and fields, including who made each change and when. Rotating service and protocol logs capture operational activity alongside it. For analytics and correlation across systems, forward these to your own monitoring stack or SIEM.
- Resilience and recovery
- Multi-node replication, leader election, and failover protect availability, and point-in-time snapshots with write-ahead-log replay support recovery.
- What your organisation owns
- 27001 certifies an organisation’s ISMS, not a product: the risk assessment, the statement of applicability, the policies, and the day-to-day operation of controls are yours to define and run. ControlBird supplies technical controls that support several Annex A areas. ControlBird is not ISO 27001 certified.
Need this for a tender?
We can provide deployment-specific detail and supporting documentation for procurement and security reviews.