ShipShape and ISO 27001
Evidence for the technical vulnerability control. Not certification, and not a management system.
The control we speak to
Annex A 8.8
Information about technical vulnerabilities of information systems in use shall be obtained, the organisation's exposure to such vulnerabilities evaluated and appropriate measures taken.
What we produce for it
- Regular, dated evidence that vulnerability information is being obtained for your public applications.
- Severity and confidence per finding, which is the 'exposure evaluated' half of the control.
- A record of remediation: the finding, the fix, and a later scan showing it gone.
- A machine-readable findings file, if your ISMS tooling wants to ingest it.
What we do NOT do
- We are not an accredited certification body and no ShipShape output contributes to a certificate.
- ISO 27001 is fundamentally about a management system — policies, risk assessment, internal audit, management review. We are a tool that feeds one Annex A control.
- We do not cover your internal systems, your staff, your suppliers, or your physical security.
Run a scan
Free, and the report states its own scope.