MRIS for ISO/IEC 27001:2022 (Annex A)

Do your controls still work when the attacker is an AI?

MRIS assesses the 93 controls of ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022) against AI-accelerated attacks — and names concrete compensating controls for every gap.

Free framework · 2 PDF documents · No registration · For CISOs and security leaders

Why “Mythos”?

Mythos (Anthropic) was the first frontier AI model whose capabilities in an attacker’s hands fundamentally changed the security landscape. MRIS uses it as the reference threat model: every control is measured against an attacker with Mythos-level capabilities.

What has changed

Four findings on the AI-accelerated threat

Patch gap

Collapse of the patch window

The time between a known vulnerability and its exploitation is shrinking toward zero.

Timeline

Timeline compression

Minutes, not days, pass between initial access and damage.

Scaling

Fragmentation

Attacks run in parallel and distributed to overwhelm the response.

Actor

Capability decoupling

Attack capability no longer depends on the actor's resources.

In the work's gap analysis (ch. 8), these four shifts condense into seven systematic gaps in ISO/IEC 27002:2022 – requirements that other frameworks already mandate and that deliver hard protective effect under Mythos conditions:

Post-quantum & crypto agilitySupply-chain transparency (SBOM mandate)Containers, confidential computing & multi-tenancyTime-based reporting deadlines & root-cause dutyContinuous verification instead of periodic auditsPhishing-resistant MFA & workload identityAutomation mandate & parallel incident testing
Market comparison

Market position: leading against the Gen-AI threat landscape

Thirteen established security works, one question: what does a work contribute to an ISMS under the current Gen-AI threat landscape? The X-axis measures Mythos/Gen-AI coverage, the Y-axis implementation readiness and auditability.

implementation-strong · Gen-AI gapcomprehensively stronglimited positiontopic-strong · execution open00224466881010Mythos / Gen-AI coverage →Implementation readiness & auditability →ISO/IEC 27002:2022BSI IT-GrundschutzCSA CCM v4BSI C5:2026ISO/IEC 42001:2023CIS Controls v8.1NIST CSF 2.0CISA Zero Trust MM v2.0NIST AI RMF + GenAI ProfileMITRE ATT&CK v19 / ATLASMythos-Ready (CSA/SANS/OWASP)OWASP Agentic Top 10 (ASI)MRIS for ISO 27001 (v1.8)★ ISO/IEC 27002 + MRIS
Norm / standardPractice frameworkCommunity workKnowledge baseMRIS for ISO 27001Combination (hardened framework)
Show all 14 positions as a table
WorkCategoryGen-AI coverage (X)Implementation readiness (Y)
ISO/IEC 27002 + MRIS (hardened framework)Combination9.89.0
MRIS for ISO 27001 (v1.8)*Hardening layer9.87.9
Mythos-Ready (CSA/SANS/OWASP)Community work8.84.6
OWASP Agentic Top 10 (ASI)Community work7.83.8
MITRE ATT&CK v19 / ATLASKnowledge base6.86.4
BSI C5:2026Norm / standard5.49.0
NIST AI RMF + GenAI ProfilePractice framework5.05.8
ISO/IEC 42001:2023Norm / standard4.66.2
CISA Zero Trust MM v2.0Practice framework4.06.8
NIST CSF 2.0Practice framework3.67.0
CSA Cloud Controls Matrix v4Norm / standard3.58.6
CIS Controls v8.1Practice framework3.27.6
BSI IT-GrundschutzNorm / standard3.08.4
ISO/IEC 27002:2022Norm / standard2.29.0

* MRIS single position per the work’s figure; Table 1 of the work lists MRIS within the combination.

Reading on three levels: (1) ISO/IEC 27002 alone is maximally certifiable, yet as a 2022 work it has no answer to the Gen-AI threat landscape. (2) MRIS alone reaches the highest Gen-AI coverage in the field (9.8) but is deliberately not a standalone ISMS. (3) The combination – the golden star at 9.8 / 9.0 – is the decision-relevant unit in practice: highest Gen-AI coverage and highest execution strength. Certification still targets the ISMS under ISO/IEC 27001, with an SoA extended by the 13 MHC.

Qualitative expert scoring (0–10 scale, uncertainty band ±0.3 on X, ±0.4 on Y, shown as error bars on the MRIS point). Methodology, scoring rationale and rubric are fully disclosed in the work. Assessment status: July 2026.

1
Assess93 controls against the Mythos threat model
2
ClassifyFour categories, bridge into ISO/IEC 27005
3
Harden13 MHC close the gaps
Risk Classification

Four categories. One clear verdict per control.

Each of the 93 controls from ISO/IEC 27001:2022 Annex A is assessed against the AI threat landscape. The result feeds directly into your risk assessment under ISO/IEC 27005.

93Controls total
Bridge to ISO/IEC 27005: A partially degraded control raises the likelihood by one level, a pure-friction control by two levels.
Compensating Controls

Select a control — see the flanking hardening

Select a control from ISO/IEC 27002:2022. MRIS shows the flanking Mythos-Hardening Controls (MHC) that close the gap.

Select a control on the left
to see the matching MHC.

Mappings per MRIS, Annex A/C. Flanked controls per v1.8 – including proactively flanked robust controls.

Leverage

A few controls cover many gaps

Number of controls each MHC flanks. Prioritization starts with the broadest impact.

Scope

What MRIS does — and deliberately does not

MRIS provides

  • +Effectiveness assessment of all 93 ISO 27002 controls against the AI threat
  • +Gap analysis against C5:2026, NIST, DORA, CRA and NIS2
  • +Audit-ready catalog of 13 Mythos-Hardening Controls with maturity levels
  • +Bridge into the risk process under ISO/IEC 27005

MRIS deliberately does not provide

  • Not a full ISMS — an established ISMS is assumed
  • No risk-management process of its own
  • Not a compliance-mapping or certification tool
  • No organization-specific policy hierarchy
Assessed against
ISO/IEC 27001:2022ISO/IEC 27002:2022BSI C5:2026NISTDORACRANIS2-RichtlinieNIS2-DVO
Download

Both documents. Free.

New in v1.8 · July 2026 Mappings extended: A.5.22 (monitoring of supplier services) and A.8.15 (logging) added to the MHC mapping · proactive flanking of robust controls introduced (A.5.9 → MHC-13) · market comparison with four-quadrant positioning added.

Main document

MRIS v1.8 – Mythos-Resistant Information Security

Complete assessment of the 93 controls from ISO/IEC 27001:2022 Annex A, with gap analysis and MHC catalog.

PDF · July 2026 · CC BY-NC 4.0 · English
Download
Implementation guideline

MRIS Implementation Guide v1.4

Prioritization with Threat Priority Score, roadmap and RACI for the 13 MHC.

PDF · July 2026 · CC BY-NC 4.0 · English
Download
Usage note

MRIS and the Implementation Guide are working aids for assessing the effectiveness of existing security controls. They assume an established ISMS and do not replace it. They do not constitute legal, compliance or certification advice, make no claim to completeness and establish no warranty. Use is at your own responsibility. Named standards, frameworks and trademarks belong to their respective owners.