Skip to main content

ISO 27001/27002 Control Matrix

The ISO 27001/27002 Control Matrix is PensionsPortal.ie’s formal mapping of ISO 27002:2022 controls to platform capabilities, implementation evidence, and regulatory obligations under IORP II (EU Directive 2016/2341, transposed as S.I. 128/2021). It is the primary artefact for demonstrating information security assurance to trustees, auditors, scheme advisers, and regulators. This page provides a representative subset of the control matrix. The complete matrix — covering all 93 ISO 27002:2022 controls — is available to enterprise customers under our security documentation programme.

What the Control Matrix Is

The control matrix is a structured, living document that answers a single question for each ISO 27002:2022 control: how does PensionsPortal.ie implement this control, and how can it be evidenced? Each row contains:
  • Control ID: ISO 27002:2022 reference (e.g., A.5.1)
  • Control Name: The ISO 27002 control title
  • Implementation: How PensionsPortal.ie has implemented the control in platform design, operations, or policy
  • Evidence Artifact: The specific artifact that demonstrates the control is operating effectively
  • Status: Implemented / Partially Implemented / Planned / Not Applicable
  • IORP II Relevance: The specific IORP II obligation or S.I. 128/2021 regulation that this control supports
ISO 27002:2022 uses a flat numbering scheme (e.g., 5.1, 8.24) rather than the A.x.x format used in ISO 27001:2013. We use both formats interchangeably in this documentation. All control references are to the 2022 edition of ISO 27002.

How the Control Matrix Is Used

Audit Support

Provide to external auditors as the primary evidence index during ISO 27001 surveillance audits, SOC 2 readiness assessments, or regulator-requested security reviews.

Customer Due Diligence

Trustees and their legal/technical advisers can assess PensionsPortal.ie’s security posture against ISO 27002 controls as part of outsourcing due diligence under IORP II Article 31.

Trustee Governance Evidence

Reference the control matrix in scheme governance documentation to demonstrate that ICT risk from the PensionsPortal.ie platform has been identified, assessed, and managed.

Regulator Conversations

Provide to the Pensions Authority in response to ICT risk or operational risk queries. Demonstrates a systematic, standards-based approach to information security.

Representative Control Matrix

The following table covers the most material controls for a pension compliance SaaS platform. Controls are drawn from across all four ISO 27002:2022 domains.
This is a representative subset of the full control matrix. It covers controls most relevant to pension scheme trustees and IORP II compliance. Controls covering detailed infrastructure hardening, internal physical security, and HR processes are included in the complete matrix available on request.

Control Status Definitions


Requesting the Full Control Matrix

The complete 93-control matrix, including the Statement of Applicability (SoA) and detailed evidence references, is available to enterprise customers and scheme auditors under our security documentation programme.
To request the full control matrix, contact PensionsPortal.ie via your account manager or through the security documentation request process. We require a signed NDA before releasing the detailed SoA and evidence pack.
The full matrix includes:
  • All 93 ISO 27002:2022 controls (including those assessed as not applicable, with justification)
  • Detailed evidence references with document identifiers
  • Control owner assignments
  • Last review date and next review date for each control
  • Links to the GCP and third-party provider controls that underpin PensionsPortal.ie’s cloud infrastructure security