Security

Audit

Jalaran Audit assesses your posture against ISO 27001:2022 Annex A controls as an awareness checklist — scoped deliberately to ISO alone, and explicitly not a certification.

Who Audit is for

For organisations considering ISO 27001 certification who need to know how far away they are before committing to the process, and for anyone who has to answer a customer security questionnaire that references it.

What Audit does

Audit walks the ISO 27001:2022 Annex A controls with a status and evidence notes per control, producing a coverage score. Its usefulness is in scoping: knowing you meet forty of the controls and have never considered thirty of them turns an intimidating standard into a work list. It is scoped to ISO deliberately — Indonesian regulatory obligations live in Comply — because a tool that claims to cover every framework at once tends to cover none of them properly.

  • ISO 27001:2022 Annex A controls
  • Per-control status and evidence notes
  • Coverage scoring across the standard
  • An awareness tool, explicitly not certification

How Audit works

  1. Work through Annex A

    The controls, as the standard organises them.

  2. Record status and evidence

    What you do and what would demonstrate it. The evidence note is what an auditor will actually ask for.

  3. Read the coverage score

    Where you stand, which turns an intimidating standard into a finite work list.

  4. Take it to a real auditor

    This is preparation for certification, never a substitute for it.

What Audit does not do

Audit is not a certification and does not lead to one — only an accredited body can certify, and nothing produced here is evidence in that process. It is a self-assessment, so it reflects what you record about yourself. It covers ISO 27001:2022 only: no SOC 2, no PCI DSS, no NIST, and Indonesian regulatory obligations belong in Comply.

Common questions

Does this certify my organisation?

No. Certification comes from an accredited certification body after a formal audit. This is a self-assessment that helps you understand how far away you are.

Does it cover SOC 2 or PCI DSS?

No. It is scoped to ISO 27001:2022 Annex A alone, on the view that a tool claiming to cover every framework at once covers none of them properly.

Why record evidence notes per control?

Because a real audit asks for evidence, not for assertions. Writing down what would demonstrate a control is the part that turns a checklist into preparation.