Regulatory

ISO/IEC 27001 (2022)

ISO/IEC 27001:2022 is the general information-security management-system standard — distinct from ISO 42001's AI-specific scope above. The mapping below cites Annex A controls that Runback's own SSO, access control, and logging directly produce evidence for.

Below is the same static clause map the in-app Regulatory tab evaluates against your org's real data on every load — not a separate summary written for this page. There is no compliance verdict here, since that depends on your own data; sign in to see your org's live status per clause.

Swipe to see all columns →

ClauseRequirementRunback capabilityEvidence
A.5.15Access to information and other associated assets shall be controlled based on business and security requirements.SSO (OIDC) + team roles (RBAC)Whether SSO (OIDC) + RBAC is enabled for your org
See it in the dashboard →
A.8.15Logs recording activities, exceptions, faults, and other relevant events shall be produced, kept, and regularly reviewed.Immutable run ledger + full audit traceAn entry in the hash-chained, append-only ledger
See it in the dashboard →
A.5.34Privacy and protection of personally identifiable information shall be ensured as required by applicable law.In-process PII redaction before captureA run where PII was redacted before capture
See it in the dashboard →
A.5.36Compliance with information security policies, rules, and standards shall be regularly reviewed.Compliance report export (machine-readable)Aggregated from real run data into a compliance report
See it in the dashboard →
Honest limits

What this page does not claim.

  • ISO 27001 covers an organisation's entire information security management system. Runback contributes evidence to a handful of Annex A controls; it is not a substitute for the other ~90.
  • Runback itself does not hold ISO 27001 certification today. The security page states exactly what is and isn't certified.
  • This is a capability map, not a conformity determination. Whether your deployment satisfies ISO/IEC 27001 is a determination for your own assessor — what's listed above is the evidence that argument draws on.