Home/Case Studies/Compliance evidence
From “we think we're compliant” to an evidence pack in ten weeks.
SaaS platform · IRAP readiness · ISO 27001 certification path · government tender deadline
The situation
A government tender required demonstrable controls and a credible assessment pathway, with a submission date fourteen weeks out. The platform itself was well built — a competent engineering team, sensible architecture, no obvious weaknesses.
The evidence was another matter. Controls were real but informal: screenshots in a shared drive, knowledge held by two engineers, and an information security policy document last revised in 2023 that described a system architecture which no longer existed.
This is an extremely common position and it is not the same as being insecure. It is being unable to prove you are secure, to a reader whose job is to disbelieve you, within a deadline.
Gap assessment
Three weeks against the ACSC Essential Eight and ISO 27001 Annex A, in parallel rather than in sequence, because the overlap is substantial and running them separately wastes a fortnight.
Forty-one findings: nine high, nineteen medium, thirteen low. The nine high findings clustered into three themes, which is typical — problems in this space are rarely independent.
- Identity. Sixty-three long-lived IAM access keys across eleven accounts, including four with administrator policies attached and no rotation in over two years.
- Audit integrity. CloudTrail enabled but writing to a bucket in the same account it was auditing, with delete permissions available to the same roles it was meant to be watching.
- Evidence. No mechanism to demonstrate that any control had been operating at a given point in the past — only that it was configured now.
Remediation, in priority order
Identity first
IAM Identity Center federation with the customer's existing identity provider, MFA enforced, and a service control policy denying access key creation entirely. Human access became role assumption with session logging; machine access became IAM roles for service accounts and OIDC federation from CI.
Sixty-three keys to zero in eleven days. The engineering team expected this to be disruptive. It was mildly annoying for four days and then invisible, which is the usual shape.
Guardrails before detection
AWS Control Tower with service control policies denying region use outside Australia, root account usage, public S3 access and CloudTrail modification. Deployed in report mode for a week first, so we could see exactly what would have broken before enforcing anything.
Two legitimate workflows would have broken. Both were redesigned rather than exception-listed — an exception granted during implementation is an exception that exists forever.
Audit integrity
Organisation trail to a dedicated log archive account with Object Lock and separate access control. Nobody with production access can alter the record of what they did in production, which is the entire point and was the finding an assessor would have opened with.
The part that mattered most
We automated evidence collection. Config conformance packs mapped to the framework controls, scheduled evidence snapshots to immutable storage with retention, and a register recording the owner and test frequency for each control.
This is the difference between passing an assessment and being able to survive one. Any organisation can reconstruct evidence in the fortnight before an audit. That works exactly once, costs a fortnight of engineering time every year, and tells the assessor — and you — nothing about whether the control was operating in month seven.
Where it landed
Ten weeks from gap assessment to a signed evidence pack, four weeks inside the tender deadline. IRAP assessment commenced with no blocking findings.
Mid-assessment the assessor requested evidence of a control operating over a specific historical period — something the customer would previously have been unable to produce at all. It was generated and mapped in four days.
ISO 27001 certification followed the next quarter, which was faster than the customer's own plan because the technical control work was already complete and evidenced.
“Our IRAP assessor asked for evidence we didn't have. Seacow had it produced and mapped in four days.”
Chief Information Security Officer, SaaS platform
What we did not do
We did not assess the system. Seacow is not a registered IRAP assessor and we would not want to be for a system we had just hardened — an assessor marking their own work is worth nothing to the agency reading the report.
We also did not penetration test. An independent tester was engaged separately on the customer's contract, with no referral arrangement, and we remediated what they found.
Certification was issued by an accredited certification body, not by us. Any provider telling you they will "certify you to ISO 27001" is describing the process incorrectly.
Related case studies
Find the gaps before an assessor does
A gap assessment against Essential Eight, ISO 27001 or SOC 2 — fixed price from $14,000, with a remediation plan you own.