NURIE Nurie Darknet Monitor

ISO/IEC 27001:2022 control mapping

How the current features of this service can support controls in Annex A of ISO/IEC 27001:2022. The mapping only covers what the service does today.

Important: Using this service does not by itself satisfy any control or make an organization compliant or certified. Each control is met by your organization's own policies, processes and records; the service can provide part of the implementation and supporting evidence. Your auditor decides whether a control is effectively implemented. This page does not claim that the service itself is ISO/IEC 27001 certified.
ControlStatus How the service helpsWhat remains your responsibility
A.5.7
Threat intelligence
Planned Once approved darknet and leak-site sources are configured, mentions of your domains will be collected, reviewed and reported as threat intelligence. Decide which threat intelligence you need, analyse it and act on it. No live darknet sources are configured today.
A.5.9
Inventory of information and other associated assets
Supports (partial) Keeps a list of your registered domains with the ownership basis, registrar, expiry date, name servers, mail servers and published DNS records. Maintain the complete asset inventory, including asset owners and systems that are not represented by these domains.
A.5.14
Information transfer
Supports (partial) Checks SPF, DMARC and MX records every week and recommends fixes that make it harder for others to send email as your domain. Set information transfer rules and agreements, and protect message content (for example with encryption and DKIM, which is not checked).
A.5.36
Compliance with policies, rules and standards for information security
Supports (partial) Dated weekly reports give a repeatable record that the external configuration of each domain was reviewed. Review compliance with your own policies and record the actions taken on each finding.
A.8.8
Management of technical vulnerabilities
Supports (partial) Identifies externally visible weaknesses in DNS, email authentication and domain registration (for example an expiring domain or a missing transfer lock), with severity and recommendations. Scan software and systems for vulnerabilities, patch them and track remediation. The service does not scan your hosts.
A.8.9
Configuration management
Supports (partial) Records the published DNS configuration every week and reports added or removed records, so unexpected changes can be noticed. Define secure baseline configurations and approve changes through your own change process.
A.8.12
Data leakage prevention
Planned Darknet and leak-site monitoring will help detect your data after it has leaked. Prevention measures such as data classification and DLP tools. Leak detection is not active yet.
A.8.16
Monitoring activities
Supports (partial) Runs scheduled, automated weekly monitoring of the external security posture of your domains. Monitor your networks, systems and applications for anomalous behaviour, and evaluate and respond to events.
A.8.21
Security of network services
Supports (partial) Checks the security of your DNS service: DNSSEC, CAA records, name server redundancy and registrar transfer lock. Agree security requirements and service levels with your DNS, registrar and other network service providers.

Evidence you can keep

Dated weekly PDF reports stored in VaultSage, showing coverage, findings, recommendations and DNS changes since the previous report. Domain records show whether ownership was proved by DNS TXT or accepted by SuperAdmin exemption, and changes are written to an audit log.

Not covered by the current features

Active vulnerability scanning, subdomain discovery, darknet and leak-site monitoring, incident response and email alerts are not active in the current version. Controls that depend on them are marked Planned or are not listed.

Control numbers and titles are from ISO/IEC 27001:2022 Annex A. Translated titles are informal; the official standard prevails.
Mapping last reviewed: Oct 4, 2026