ISO 27001 controls and the receipts that map evidence to them.
Every ISO 27001 control Déjà's control table lists, with the receipt types that map evidence to each. Only controls a receipt type maps evidence to are listed; the rest of the standard is evidenced outside Déjà. References and titles are from ISO/IEC 27001:2022, Annex A.
2 of the 2 ISO 27001 controls listed here have a receipt type that maps evidence to them. Only those are listed: the rest of the standard is evidenced outside Déjà.
What a receipt covers, and what is not.
2 of the 2 ISO 27001 controls listed here have a receipt type that maps evidence to them. Only those are listed: the rest of the standard is evidenced outside Déjà.
Only the Annex A controls a receipt type maps evidence to are listed. Every other Annex A control is evidenced outside Déjà, and is not listed here.
- Edition
- ISO/IEC 27001:2022, Annex A
- Controls listed
- 2
- A receipt type maps evidence
- 2
- Evidenced outside Déjà
- 0
A receipt is evidence for a control, never the whole of it: the rest of each control is tested outside Déjà.
ISO 27001, in the standard's own words.
Organizational controls
1 of 1 with a receipt type
The evidence, and what each one is.
The receipt types that map evidence to at least one ISO 27001 control. The fields each one carries in its signed or hashed bytes are listed under receipt types.
R1Signed
Attribution Receipt
Incident attributed to a causal PR with CCS above threshold.
Maps evidence to A.5.24 and A.8.32 · what R1 records
R1-LSigned
Low-Confidence Attribution
Candidate PRs identified but CCS in the low-confidence range (0.60–0.79).
Maps evidence to A.5.24 and A.8.32 · what R1-L records
R2Signed
Resolution Receipt
An incident marked resolved, with its five gate scores and whether they passed. References its R1.
Maps evidence to A.5.24 · what R2 records
Checked on the auditor's own machine.
An audit engagement opened for ISO 27001 covers the receipt types that map evidence to its controls: R1, R1-L and R2. The auditor gets a token link, sees the receipts in scope, downloads a signed period report and checks it on their own machine with dsr-verifier-cli, against Déjà's published keys.
The period report packs R1 and R1-L. R2 is listed in the auditor's portal and not packed.
Déjà's integrity monitor, every 15 minutes, checks R1 and R2; it does not check R1-L.
What Déjà does not do for you.
- Determine root cause
- An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
- Certify a control
- A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
- Attest
- Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.
Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.
Walk the list with us, control by control.
Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.