ISO/IEC 27001:2022

ShipShape and ISO 27001

Evidence for the technical vulnerability control. Not certification, and not a management system.

The control we speak to

Annex A 8.8

Information about technical vulnerabilities of information systems in use shall be obtained, the organisation's exposure to such vulnerabilities evaluated and appropriate measures taken.

What we produce for it

  • Regular, dated evidence that vulnerability information is being obtained for your public applications.
  • Severity and confidence per finding, which is the 'exposure evaluated' half of the control.
  • A record of remediation: the finding, the fix, and a later scan showing it gone.
  • A machine-readable findings file, if your ISMS tooling wants to ingest it.

What we do NOT do

  • We are not an accredited certification body and no ShipShape output contributes to a certificate.
  • ISO 27001 is fundamentally about a management system — policies, risk assessment, internal audit, management review. We are a tool that feeds one Annex A control.
  • We do not cover your internal systems, your staff, your suppliers, or your physical security.
Run a scan