// ARTICLE

    ISO 27001: which controls a scan can prove

    Technical vs organizational evidence.

    A scanner produces technical evidence. It does not produce a compliance verdict, and the gap between those two things trips up a lot of reports.

    ISO 27001 is a management system. Most of Annex A is about process, people and decisions. A scan can speak to a specific slice of it, and pretending otherwise is where credibility leaks away.

    What a scan can genuinely evidence

    The technical controls in Annex A 8 are fair game. Vulnerability management (A.8.8) is the obvious one: a scan shows what is unpatched and where. Network security and segregation (A.8.20, A.8.22) show up as exposed services. Weak or expired crypto maps to A.8.24, insecure configuration to A.8.9, information leakage to A.8.12.

    Used this way, a finding is a data point about a control being exercised, or not, on a given asset. That is real, defensible evidence for the technical part of an audit.

    What a scan can never prove

    A scan says nothing about whether you have a risk treatment plan, whether staff are trained, whether suppliers are assessed, or whether management reviews happen. Those are the organisational controls, and they are most of the standard.

    Claiming a scan demonstrates 'ISO compliance' is not just imprecise, it invites the one question you can't answer: show me the policy. Keep the scope of your claim to what the tool actually observed.

    Evidence, not a score

    Mapping ten findings to A.8.8 does not make you '80% compliant' with A.8.8. It shows the control is weak on ten assets. The auditor decides what that means for conformity; that judgement is their job, not the scanner's.

    Reports that print a compliance percentage tend to get trusted less by the people who know the standard. A clean mapping, with no invented number, reads as the work of someone who understands the difference.

    How to use it in a real audit

    Hand the auditor a control-mapped annex alongside the findings. It lets them tick off the technical evidence quickly and spend their time on the parts that need judgement.

    That is exactly the shape of annex a good report should produce: findings attached to controls, no percentage, the conformity call left where it belongs.