ISO 27001 Surveillance Prep That Stays Current Year-Round
Map Annex A controls once. Keep policies, evidence, and your SoA current between surveillance audits. Show assessors exactly what changed since the last period.
- Annex A mapping:Controls mapped with applicability status and justifications
- ISMS governance trail:Policy approvals, reviews, and management decisions timestamped
- Surveillance snapshots:Point-in-time evidence state locked for each audit period
- Change tracking:Clear, auditable change tracking since the last audit period
Certification Was the Easy Part. Maintenance Is Where Teams Stall.
Your SoA Is a Spreadsheet Nobody Trusts
Annex A mappings, justifications, and ownership sit in a spreadsheet. By the time the surveillance audit arrives, the mapping is already stale.
Surveillance Prep Takes as Long as Initial Certification
Evidence was collected last year, but owners changed and policies were updated. Nobody tracked what needs refreshing.
Governance Artifacts Live in Three Different Systems
Policies in one tool, training records in another, risk assessments in a third. Assembling the auditor package takes days.
This replaces spreadsheet-based SoAs, scattered policy folders, and manual surveillance prep checklists.
Five Steps from Scope to Assessor Handoff
Surveillance audits build on the last period instead of restarting.
A Living Statement of Applicability, Not a Stale Spreadsheet

A.5.1 · Current
Information Security Policies · Applicable · 3 linked evidence items keep the SoA current between surveillance audits.
Give Assessors Exactly What They Need -- Nothing More
Requirement mapping
Policy and approval history
Evidence with change history
Want to See This with Your Control Mapping?
Share your ISMS scope or control list. We'll walk through the exact surveillance prep workflow mapped to your cycle.
ISO 27001 Readiness Questions We Hear Most
Does this cover both initial certification and surveillance audits?
How do we handle the Statement of Applicability?
Can we reuse this for SOC 2 or other frameworks?
How does the continuous improvement cycle work?
Aurora Command does not guarantee compliance outcomes. It helps you organize and document the work.
Explore the Workflow on Your Own Time
Explore the workflow first. Book time when you want your own ISMS cycle walked through end-to-end.