ISO 27001 has 93 Annex A controls. Here are two of them (access control and logging) exactly as the workbench presents them: the requirement in plain language, plus concrete examples of the evidence an auditor would actually accept. Not a mockup; this is the same content signed-in users work through.
Annex A 5.15Organizational controls
Access control
Decide who may reach what — written entitlement rules covering both buildings and systems, driven by business need.
What conforming evidence looks like
Access-control policy defining need-to-know/least-privilege rules, approved and versioned
Role-based access model or permission matrix mapping roles to systems and privileges
Access-request workflow record (ticket) showing approval before granting
Annex A 8.15Technological controls
Logging
Record security-relevant activity, guard the logs against tampering, and actually review them.
What conforming evidence looks like
Logging standard: what events are logged per system (auth, admin actions, errors)
Central log platform retention configuration matching policy — or, without a central platform: logging config export or screenshot from primary systems (e.g. CloudTrail, Google Workspace audit, GitHub audit log) with retention settings (e.g. 90 days in cloud)
Log-access restrictions and tamper protection evidence (append-only, restricted queries) — or, for smaller teams: evidence log access is restricted to admins (IdP permission or sharing setting)
Seed guidance drawn from ISO/IEC 27002:2022 practice — refine to match your organization. Not audit advice.
The other 91 controls work the same way.
Inside the workbench, every control gets this treatment, plus a status you can track, evidence you can attach, and readiness reports you can hand to leadership or an auditor. New to ISO 27001? A short setup wizard turns the standard into a simple readiness project for your team.