ISO/IEC 27001:2022 Alignment with Citadel

Citadel enhances browser security and supports compliance with ISO/IEC 27001:2022 standards. Here’s how Citadel’s functionalities align with these standards, enhancing security measures and compliance efforts.

Feature to Control Mapping

The table below summarizes how each Citadel feature maps to ISO/IEC 27001:2022 Annex A controls. Detailed descriptions follow in the sections below.

Citadel Feature Related Control(s)
Security event & threat logging A.5.7, A.5.26, A.5.28, A.8.15, A.8.16
Web attack detection (e.g. ClickFix) A.5.7, A.8.7
Phishing & malware detection / blocking A.8.7
Shadow IT detection & usage reminders A.5.9, A.5.10, A.5.23, A.8.12
Software license management & app usage statistics A.5.9
Browser extension inventory A.5.9
Browser extension policy enforcement (permissions, allow/deny lists) A.8.19, A.5.9, A.8.9
Software require/deny (installed software or running processes) A.8.19
Clipboard & file secret scanning (API keys, tokens) A.5.10, A.5.14, A.8.12
Download & upload monitoring A.5.14, A.8.12
Print detection (paper/PDF) A.8.12
External filesystem / removable media detection A.7.10, A.8.1, A.8.12
Session duration management A.5.15, A.8.1
Password policy enforcement A.5.15, A.5.17
MFA enforcement A.8.5
Network access management (site/app blacklisting) A.5.15, A.8.20, A.8.23
Web filtering (malicious/illegal content) A.5.32, A.8.20, A.8.23
Device posture checks (firewall, AV, OS updates) A.8.1, A.8.7, A.8.8, A.8.9
Update reminders (OS/browser restart) A.8.8
Data masking (URL & e-mail hashing), DPIA & LIA A.5.34, A.8.11
Unencrypted connection & SSL issue detection A.8.11, A.8.20, A.8.24
Unsafe Wi-Fi protocol detection A.8.20, A.8.24

A.5 Organizational Controls

A.5.7 – Threat Intelligence

Citadel logs security events and potential threats, enhancing organizational threat intelligence and situational awareness, allowing for proactive response to emerging threats. This includes detection of common web-based attack techniques such as ClickFix, feeding real-world attack telemetry back into the organization’s threat intelligence.

A.5.9 – Inventory of Information and Other Associated Assets

Citadel identifies shadow IT and manages software licenses by providing application usage statistics, supporting effective asset management and compliance. It also inventories installed browser extensions, giving visibility into browser-level software assets.

A.5.10 – Acceptable Use of Information and Associated Assets

Citadel supports acceptable-use policies by reminding users when they are using non-authorized (Shadow IT) applications, steering them toward sanctioned tools. Its scanning of clipboard and file contents for secrets (such as API keys and tokens) further discourages misuse of credentials and information assets.

A.5.14 – Information Transfer

Citadel enhances the security of information transfer by monitoring and logging download and upload activities within the browser environment. By detecting when files are downloaded, Citadel ensures that these actions are recorded as security events. This capability, together with frequency analysis, enables organizations to oversee the transfer of potentially sensitive information, allowing for proactive responses to unauthorized or suspicious transfers. Citadel further inspects the contents of the clipboard and of selected or dragged files to detect known secret types (such as API keys and tokens), helping prevent inadvertent or malicious transfer of credentials.

A.5.15 – Access Control

  • Session Duration Management: Ensures sessions do not persist longer than configured by deleting cookies, reducing risks of unauthorized access from unattended sessions.
  • Password Policy Enforcement: Reviews passwords against configured policies, supporting stringent access control.
  • Network Access Management: Allows blacklisting of sites or applications, supporting stringent access control.

A.5.17 – Authentication Information

Citadel enforces password quality through real-time policy checks. It verifies that passwords used in web applications meet organizational standards for length and complexity. Any non-compliance is logged, supporting security audits and strengthening overall access control.

A.5.23 – Information Security for Use of Cloud Services

By detecting Shadow IT and enabling the blocking of unauthorized cloud and SaaS applications, Citadel helps organizations control which cloud services are used, supporting governance over the acquisition and use of cloud services.

A.5.26 – Response to Information Security Incidents

The security events logged by Citadel allow for more rapid and detailed DFIR after a security incident.

A.5.28 – Collection of Evidence

Citadel’s security event logs provide a reliable, timestamped record of browser- and endpoint-level activity that can serve as evidence during investigations. When forwarded to a SIEM or retained per policy, these logs support the identification, collection and preservation of evidence following an information security incident.

A.5.32 – Intellectual Property Rights

Citadel blocks access to sites known to share illegal content.

A.5.34 – Privacy and Protection of PII

Citadel applies extensive data masking — including hashing of URLs and personal e-mail addresses — to minimize the personal data captured in logs. A Data Protection Impact Assessment (DPIA) and Legitimate Interest Assessment (LIA) have been performed for Citadel’s processing activities, supporting privacy-by-design and demonstrable compliance with PII protection requirements.

A.5.36 – Compliance with Policies, Rules and Standards for Information Security

Citadel increases visibility into user actions and security incidents, allowing better monitoring of policy adherence and regulatory compliance.

A.7 Physical Controls

A.7.10 – Storage Media

Citadel detects the mounting of external filesystems (such as USB drives and other removable media), enabling organizations to monitor and respond to the use of removable storage that could be used to exfiltrate data or introduce malware.

A.8 Technological Controls

A.8.1 – User Endpoint Devices

  • Citadel enforces policies that sessions that are no longer needed are logged off.
  • Citadel checks general device posture — verifying that the firewall is enabled, that operating system and antivirus updates are applied, and flagging other posture issues — helping ensure endpoint devices remain in a secure, compliant state.
  • Citadel detects the mounting of external filesystems and removable media, supporting control over what can be connected to endpoint devices.

A.8.5 – Secure Authentication

Citadel enforces multi-factor authentication (MFA) policies for browser-based applications, ensuring that authentication requires more than just passwords. By requiring MFA, Citadel significantly strengthens the authentication process and protects against brute force attacks, even if passwords are weak, reused, or compromised.

A.8.7 – Protection Against Malware

  • Citadel raises awareness by flagging security incidents such as phishing and malware based on detections made by the browser.
  • It actively detects potential threats by blocking attempts to interact with malicious content.
  • It detects common web-based attack techniques, such as ClickFix and other social-engineering-driven command execution attacks, that attempt to trick users into compromising their own endpoint.
  • It verifies that antivirus definitions and scans are up to date as part of device posture checks.

A.8.8 – Management of Technical Vulnerabilities

  • Citadel reminds users to restart their laptop and browser so that pending operating system and browser updates are applied, reducing exposure to known vulnerabilities.
  • It verifies that operating system and antivirus updates are performed, surfacing devices that are missing critical patches.

A.8.9 – Configuration Management

Citadel helps maintain secure configuration by verifying device posture — such as firewall status and update state — and by enforcing browser extension policies, ensuring endpoints and browsers remain in an approved, hardened configuration.

A.8.11 – Data Masking

Citadel hashes URLs and personal e-mail addresses for logging to protect sensitive information, and detects unencrypted traffic.

A.8.12 – Data Leakage Prevention

  • Citadel detects when files are uploaded or downloaded, and when pages are printed (to paper or PDF).
  • Citadel scans the contents of the clipboard and of selected or dragged files to detect known secret types (such as API keys and tokens), preventing sensitive credentials from leaking out of the organization.
  • Citadel detects the mounting of external filesystems and removable media, a common channel for data exfiltration.
  • Citadel enables the detection of Shadow IT applications and can block access to them.

A.8.15 – Logging

By logging security events, Citadel enhances monitoring capabilities and facilitates comprehensive analysis by SIEM systems.

A.8.16 – Monitoring

Citadel allows you to monitor outgoing network traffic, and detect traffic to known malicious IP addresses or domains.

A.8.19 – Installation of Software on Operational Systems

  • Citadel enforces policy on browser extensions: when an extension is installed, Citadel scans it and, based on its requested permissions and configured blacklist/whitelist, allows or denies it. This prevents unauthorized or over-permissioned extensions from being introduced into the browser environment.
  • Based on a configured whitelist/blacklist, Citadel can require or deny the installation or running of software — for example, allowing an action only if a mandated application or process is present, or blocking it when a prohibited application or process is detected. This enforces organizational standards for which software may run on operational systems.
  • Reminders about non-authorized (Shadow IT) applications further support controlled software installation and use.

A.8.20 – Networks Security

  • Citadel detects unencrypted connections, improving communication security by flagging vulnerabilities due to unencrypted data transfer.
  • Citadel detects the use of unsafe Wi-Fi protocols (such as weak or outdated wireless encryption), helping protect users on insecure networks.
  • It performs web filtering, controlling access to potentially malicious or unauthorized websites.

A.8.23 – Web Filtering

Citadel restricts access to websites containing malicious or illegal content.

A.8.24 – Use of Cryptography

Citadel detects non-compliance with encryption policies by identifying non-encrypted web connections and flagging SSL issues, such as self-signed or expired certificates. It also detects the use of unsafe or outdated Wi-Fi encryption protocols, flagging weak cryptography in the network layer.