How the mapping works
Every safe check BreakMesh runs on a verified target is linked to the ISO/IEC 27001:2022 ISO/IEC 27001:2022 Annex A controls it produces evidence for. When a scan completes you get a report that groups findings and passed checks by ISO/IEC 27001:2022 Annex A controls, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.
ISO/IEC 27001:2022 coverage
A.5.18
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
A.5.24
- Mail Security SPF/DKIM/DMARC
- Blocklist and Reputation Checks
- Security Contact Evidence
A.5.34
- Cookie Consent Mechanism
- GDPR/CCPA Data Subject Rights
- Privacy and Terms Evidence
A.8.14
- API Rate-Limit Readiness
- Availability Status Evidence
- Bot Protection Detection
- DDoS Readiness Evidence
- Rate-Limit Readiness
- WAF/CDN Detection
- WAF Harmless Canary Probe
A.8.20
- DNS Basics
- DNSSEC Review
- WHOIS and Domain Expiry
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- Origin Exposure Check
- Open Risky Ports
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
A.8.24
- HSTS Strength
- HTTP/2 and HTTP/3 Support
- HTTPS Redirect
- Mixed Content Detection
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
A.8.26
- API Documentation Exposure
- API Third-Party Dependency Inventory
- CORS Edge Cases (null origin / preflight)
- CORS Policy
- Excessive API CORS Checks
- GraphQL DoS Readiness (Batching / Alias / Depth)
- GraphQL Introspection Exposure
- HTTP Method Exposure
- JWT Weakness Detection
- Shadow API Discovery
- Versioned Endpoint Discovery
- WebSocket Security Check
A.8.28
- AI Response Data Leakage
- AI Endpoint Discovery
- AI Endpoint Rate-Limit Readiness
- Business Logic — Price Manipulation
- Web Cache Poisoning Readiness
- Command Injection (Timing)
- Content Moderation Bypass Canary Probe
- File Upload Bypass
- Header Injection
- Insecure Deserialization (Timing)
- Jailbreak Pattern Indicator
- Model Extraction Risk Indicator
- Open Redirect
- Open Redirect (Active)
- HTTP Parameter Pollution (HPP)
- Path Traversal
- Prompt Injection Indicator
- AI Prompt Reflection Check
- Harmless Reflected XSS Indicators
- HTTP Request Smuggling / Desync Readiness
- Safe SQL Injection Indicators
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- SSRF (Callback)
- SSTI Template Injection Indicator
- AI System Prompt Exposure
- Training Data Extraction Indicator
- XSS — Reflected
- XSS — Stored
- XXE Injection
A.8.3
- Account Enumeration Indicators
- Auth Bypass Probes
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Credentialed Test-Account Checks
- CSRF Protection Enforcement
- Endpoint Auth Indicators
- IDOR (Two-Account)
- Login Rate-Limit Simulation
- Login Surface Controls
- API Mass Assignment
- MFA Configuration Indicators
- OAuth 2.0 / OIDC Security Checks
- Password Reset Flow Checks
- Password Spray Indicator
- Session Fixation Check
- Weak Password Policy Review
A.8.5
- Account Enumeration Indicators
- Auth Bypass Probes
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Credentialed Test-Account Checks
- CSRF Protection Enforcement
- Endpoint Auth Indicators
- IDOR (Two-Account)
- Login Rate-Limit Simulation
- Login Surface Controls
- API Mass Assignment
- MFA Configuration Indicators
- OAuth 2.0 / OIDC Security Checks
- Password Reset Flow Checks
- Password Spray Indicator
- Session Fixation Check
- Weak Password Policy Review
A.8.8
- Dependency CVE Matching (SBOM)
- Drive-by Download / Malicious Redirect Chain
- Mobile App Static Analysis (APK/IPA)
- Service/Version CVE Hints (Advisory)
A.8.9
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- Cookie Security
- CSP Quality Review
- Deprecated Browser APIs
- Directory Listing
- Sitemap and Robots Exposure
- Error Disclosure
- Error Disclosure Expansion
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
- Secrets in JavaScript Bundles
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Server Header Disclosure
- Session Cookie Scope
- Source Map Exposure
- Subresource Integrity (SRI) Missing
- Trusted Types Signal