New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Compliance evidence mapping

ISO/IEC 27001:2022 evidence mapping

BreakMesh maps each safe scan finding to the ISO/IEC 27001:2022 Annex A control it provides evidence for, supporting the technical controls layer of your ISMS with repeatable, exportable evidence.

118 checks mapped 12 ISO/IEC 27001:2022 Annex A controls Non-destructive scans

BreakMesh helps you gather audit evidence and reduce risk. It maps findings to control evidence to support your assessment — it does not by itself make your organization compliant or certified.

How the mapping works

Every safe check BreakMesh runs on a verified target is linked to the ISO/IEC 27001:2022 ISO/IEC 27001:2022 Annex A controls it produces evidence for. When a scan completes you get a report that groups findings and passed checks by ISO/IEC 27001:2022 Annex A controls, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.

ISO/IEC 27001:2022 coverage

A.5.18

  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure

A.5.24

  • Mail Security SPF/DKIM/DMARC
  • Blocklist and Reputation Checks
  • Security Contact Evidence

A.5.34

  • Cookie Consent Mechanism
  • GDPR/CCPA Data Subject Rights
  • Privacy and Terms Evidence

A.8.14

  • API Rate-Limit Readiness
  • Availability Status Evidence
  • Bot Protection Detection
  • DDoS Readiness Evidence
  • Rate-Limit Readiness
  • WAF/CDN Detection
  • WAF Harmless Canary Probe

A.8.20

  • DNS Basics
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Origin Exposure Check
  • Open Risky Ports
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk

A.8.24

  • HSTS Strength
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • Mixed Content Detection
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review

A.8.26

  • API Documentation Exposure
  • API Third-Party Dependency Inventory
  • CORS Edge Cases (null origin / preflight)
  • CORS Policy
  • Excessive API CORS Checks
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • GraphQL Introspection Exposure
  • HTTP Method Exposure
  • JWT Weakness Detection
  • Shadow API Discovery
  • Versioned Endpoint Discovery
  • WebSocket Security Check

A.8.28

  • AI Response Data Leakage
  • AI Endpoint Discovery
  • AI Endpoint Rate-Limit Readiness
  • Business Logic — Price Manipulation
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Content Moderation Bypass Canary Probe
  • File Upload Bypass
  • Header Injection
  • Insecure Deserialization (Timing)
  • Jailbreak Pattern Indicator
  • Model Extraction Risk Indicator
  • Open Redirect
  • Open Redirect (Active)
  • HTTP Parameter Pollution (HPP)
  • Path Traversal
  • Prompt Injection Indicator
  • AI Prompt Reflection Check
  • Harmless Reflected XSS Indicators
  • HTTP Request Smuggling / Desync Readiness
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • AI System Prompt Exposure
  • Training Data Extraction Indicator
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

A.8.3

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review

A.8.5

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review

A.8.8

  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
  • Mobile App Static Analysis (APK/IPA)
  • Service/Version CVE Hints (Advisory)

A.8.9

  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Cookie Security
  • CSP Quality Review
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • Error Disclosure
  • Error Disclosure Expansion
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Session Cookie Scope
  • Source Map Exposure
  • Subresource Integrity (SRI) Missing
  • Trusted Types Signal