Overview
Overview
ISO 27001:2022 Annex A defines 93 controls across four groups — A.5 Organizational (37), A.6 People (8), A.7 Physical (14), and A.8 Technological (34) — that organizations implement to manage information security risk.
ISO 27001:2022 was previously available in the Cye platform as a mapping reference from within the NIST maturity view. It is now also available as a standalone Primary framework for maturity assessment, with its own scoring, coverage, and Statement of Applicability support.
Prerequisites
Prerequisites
Admin access required to change the primary framework.
License required — ISO 27001:2022 is available only when your organization's license includes it. If you don't see it in Settings, contact your Cye representative.
Set ISO 27001:2022 as your primary framework (admin only)
Set ISO 27001:2022 as your primary framework (admin only)
Go to Settings > Maturity.
Under Primary Framework, select ISO/IEC 27001:2022(E).
Once set:
ISO 27001:2022 becomes the active framework for maturity assessments, findings, assets, reports, and risk calculations.
Only the primary framework drives platform-wide calculations; the non-primary framework is visible only within the maturity assessment screen.
Note: Switching to ISO 27001:2022 starts you from a clean state. There is no data to carry over from a previous NIST-based assessment. ISO 27001:2022 and NIST are standalone frameworks; changes to scores, targets, or mappings in one do not affect the other.
Complete a maturity assessment with ISO 27001:2022
Complete a maturity assessment with ISO 27001:2022
Scoring works at the individual control level. Work through the 93 Annex A controls across four groups, using the search and filter to navigate them.
Navigate to the Maturity tab. Confirm that ISO 27001:2022 is shown as your active framework.
Score your controls. The 93 Annex A controls are organized across four Control Groups: A.5 Organizational, A.6 People, A.7 Physical, and A.8 Technological.
Each control accepts up to four inputs:
Manual rating (1–5)
Linked findings
Linked technologies
Linked processes
Each input present contributes equally to the control's score. A control with a manual rating and one linked finding, for example, weights each at 50%.
How findings and assets map to controls:
Findings, technologies, and processes already mapped to NIST CSF 2.0 subcategories count toward ISO controls automatically — no separate ISO mapping step needed.
Review a control's NIST CSF 2.0 mapping in its Standards tab on the Maturity view.
Override the derived ISO mapping on any individual finding or asset from its own Standards tab.
Note: ISO 27001:2022 maps to NIST CSF 2.0 subcategories only. NIST CSF 1.1 is not involved in the mapping. To explore the relationship from the NIST side, see Viewing ISO 27001:2022 Mappings from the NIST View.
Note: A small number of controls have limited automatic mapping and may require a manual rating to contribute to your score.
Check your coverage. Scoring works in two tiers:
Control Group score — the unweighted average of that group's scored controls. At least 50% of a group's enabled controls must be scored before the group shows a value (for example, A.6 People needs 4 of 8; A.5 Organizational needs 18 of 37).
Organization score — the unweighted average of the four Control Group scores. At least 3 of the 4 groups must have a value.
Controls marked Not Relevant are excluded from both the count and the average, so the thresholds recalculate as you mark controls.
Note: Your benchmark shows the average maturity score of other customer companies in your industry sector, labeled "Framework benchmark."
Mark a control as Not Relevant
Mark a control as Not Relevant
ISO 27001 certification requires a Statement of Applicability (SoA), a formal record of which controls apply to your organization and, for controls that don't, why not. Use the Not Relevant toggle to mark controls that don't apply.
Open the control's detail panel.
Toggle it to Not Relevant.
Enter a justification note. This is required before you can save.
Save.
When a control is marked Not Relevant:
It is excluded from organization maturity, coverage, Cost of Breach, and Likelihood of Breach calculations.
It remains visible and commentable, not hidden.
The number of excluded controls appears next to the framework name (e.g.
· 5 excluded).The change is logged in the audit history, including your justification note.
To reverse a Not Relevant marking, follow the same steps — a justification note is required in both directions. Only users with manual maturity rating permission can mark or unmark controls as Not Relevant.
Next Steps
Next Steps
Use the search and filter on the Maturity view to work through the four Control Groups systematically, build your Statement of Applicability with Not Relevant markings, and track your maturity trend over time.
