ISO 27001:2022 Compliance
Validate your DDoS controls for ISO 27001 certification
ISO 27001 requires testing availability controls, not just implementing them. DDactic provides the active validation of DDoS resilience that your ISMS needs, with OPI scores that go directly into your risk register.
What ISO 27001:2022 Requires
ISO 27001:2022 (third edition) introduced significant changes to availability and resilience requirements. A key principle throughout: controls must be tested to demonstrate effectiveness, not just documented.
"Information about technical vulnerabilities of information systems in use shall be obtained in a timely fashion, the organisation's exposure to such vulnerabilities shall be evaluated and appropriate measures shall be taken to address the associated risk."
"ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements."
"Security testing practices shall be defined and implemented in the development life cycle."
"Networks and network devices shall be secured, managed and controlled to protect information in systems and applications."
The key insight: ISO 27001 auditors increasingly expect to see evidence that DDoS protection controls have been tested under realistic attack conditions. A Cloudflare or Akamai subscription does not satisfy Control 5.30 without evidence that ICT continuity was verified. DDactic provides that evidence.
How DDactic Maps to ISO 27001:2022
DDactic addresses availability controls across multiple Annex A controls, with structured OPI evidence suitable for inclusion in your Statement of Applicability (SoA) and risk register.
| ISO 27001 Control | Section | DDactic Feature |
|---|---|---|
| Technical vulnerability management | 8.8 | Passive recon discovers CDN bypass vectors and exposed origin IPs; classified by severity and exploitability |
| ICT readiness testing | 5.30 | Active DDoS simulation validates that ICT continuity holds under realistic attack conditions; OPI Operational Resilience component measures availability and latency under load |
| Security testing | 8.29 | L3/L4/L7 attack simulation across 233+ vectors provides structured security test evidence for DDoS-relevant controls |
| Network security | 8.20 | Validates rate limiting, scrubbing, and WAF configurations are effective under attack; fingerprints 25+ CDN/WAF vendors |
| Information security risk assessment | Clause 8.2 | OPI Passive score quantifies availability risk before active testing; enables risk register entry with numeric severity |
| Performance evaluation | Clause 9.1 | OPI Validated score tracks DDoS resilience over time; run before and after remediation to demonstrate control improvement |
| Asset management | 5.9 | Attack surface discovery produces a complete inventory of internet-facing assets including those not previously known to the asset register |
| Corrective action | Clause 10.1 | Vendor-specific hardening steps provide documented corrective actions; before/after OPI delta confirms effectiveness |
Evidence DDactic Produces for Your ISMS
Risk Register Entry
OPI Passive score provides a numeric availability risk rating before testing. Feeds directly into your Clause 8.2 risk assessment. Annotated with threat source, vulnerability, and likelihood/impact ratings.
Control Effectiveness Evidence
OPI Validated score demonstrates that Annex A Controls 5.30, 8.8, 8.20, and 8.29 were tested and effective (or identifies gaps requiring corrective action under Clause 10.1).
Asset Inventory Supplement
Attack surface discovery output lists all discovered internet-facing SLDs, subdomains, and IPs, including those not in your current asset register. Supports Control 5.9 (asset management).
Corrective Action Evidence
Before and after OPI scores with vendor-specific hardening steps. Demonstrates that nonconformities from the assessment were addressed, supporting Clause 10.1 corrective action documentation.
What Your ISO 27001 Auditor Sees
- Documented evidence that ICT readiness (Control 5.30) was tested under simulated attack conditions
- A numeric OPI Validated score covering six resilience dimensions, referencing an open published methodology
- Technical vulnerability findings (Control 8.8) from passive recon, including origin IP exposure and CDN bypass paths
- Network security validation results (Control 8.20) including WAF and rate limiter effectiveness
- A complete internet-facing asset inventory supplement from attack surface discovery (Control 5.9)
- Before and after OPI scores showing corrective action effectiveness (Clause 10.1)
- PDF report formatted for inclusion in your Statement of Applicability evidence package
Who Benefits
ISO 27001 certification is pursued across a wide range of sectors. DDoS resilience testing is most relevant where availability is a primary business requirement.
See all compliance frameworks: DDactic Compliance Coverage