What enterprises need is not a NAS labeled “ISO 27001”, but a device that does not disrupt existing management systems (ISMS, Information Security Management System), and can continuously deliver audit evidence. QNAP designs the storage platform according to ISO/IEC 27002 control measures: configurable, monitorable, auditable, and restorable.
The certification target is the company's management system—like an exam, it tests how the “organization” manages information security, not a specific unit. Annex A lists 93 control measures that must be implemented.
It expands those 93 control clauses into guidance on “how to actually do it.” This is the layer where products can help—QNAP's features are designed accordingly, so the controls involved in the product can be implemented and logged.
From the configuration of control measures, to the generation, collection, and export of logs—once this path is clear, audits can be passed.
Access control · Encryption · WORM
Backup & Snapshot · Firewall
= Implementation points of control measures
QuLog Center Event and Access Log
HBS Backup Result · Integrity Report
Notification Center Alarm Log
Syslog Forwarding to Enterprise SIEM
(No SIEM: QuLog centralized retention
Retention can also be satisfied with period filtering)
CSV/PDF Export
Settings page as proof
SIEM Query Results
The eight categories correspond to QNAP's alignment with ISO/IEC 27002:2022 technical and organizational controls. Each card indicates the corresponding Annex A control number.
Stating “supported” in the specification table is just the starting point—each item tells you where to get the evidence and in what format it should be presented.
| General product terminology | What enterprises adopting ISO 27001 truly need |
|---|---|
| Supports MFA | Enforce two-step verification for important accounts, and enable status for inspection Get location | Control Panel → User account (status inspection format varies by version) |
| Supports encryption | Show which volume and transmission channels have encrypted settings status Get location | Storage & Snapshots → volume encryption status; Control Panel → network services |
| Supports logs | Log collection, time consistency, SIEM forwarding supported, periodic export Get location | QuLog Center → Event/Access log → Filter → Export CSV |
| Backup supported | Success/failure logs, failure alerts, and integrity check reports are available for review Get location | HBS 3 → Task log; Integrity check → Download report |
| Update supported | Refer to the current firmware version and security advisories to understand patch status and support period Get location | Control Panel → Firmware Update; qnap.com Security Announcements and Product Support Status Page |
QTS and QuTS hero Capability comparison of the two major operating systems for model planning reference
| Capability | QTS | QuTS hero | Note |
|---|---|---|---|
| WORM data folder/Immutable Snapshot | — | ✓ | Immutable storage is exclusive to QuTS hero (ZFS) models |
| QuObjects Object Lock | ✓ | ✓ | S3-compatible immutable object storage |
| volume encryption/2FA/QuFirewall/QuLog | ✓ | ✓ | — |
| Airgap+ Isolated Backup | ✓ | ✓ | Requires designated QNAP networking equipment |
Factory default settings meet the security baseline—compliance from day one
Initialization forces the creation of a custom administrator account and password, so there is no factory-shared account and password that could be vulnerable to dictionary attacks.
Services such as SSH and Telnet are not enabled by default, reducing the attack surface from day one.
Supports enforced HTTPS and TLS certificate management, ensuring management traffic is not transmitted in plain text.
Update file digital signature verification. Files that have not passed verification cannot be installed.
Security patches can be applied automatically (scope and time window configurable), reducing the exposure time of known vulnerabilities.
Security risk scanning and proactive alerts for weak passwords and externally exposed settings.
Most small and medium-sized enterprises aren't preparing for ISO 27001 certification, but are instead approached by major clients with supply chain security questionnaires or insurance audit questionnaires—three steps get your NAS ready to answer confidently
Follow QNAP's security hardening guide to complete the basic settings for accounts, services, and network—topics like “default password” and “service management” can be answered based on actual settings and attached as supporting evidence.
No SIEM required: QuLog Center provides built-in centralized storage, time-based filtering, and export, meeting basic log retention and review requirements.
Backups comply with the 3-2-1-1-0 rule (3 copies of data, 2 types of media, 1 offsite copy, 1 immutable copy, 0 restore errors). Enable integrity check—questions like “restore test” and “backup protection” can be answered with records.
When evaluating suppliers, look beyond the product and check the original manufacturer—products operated in an open and verifiable manner ensure security
QNAP, as a CVE Numbering Authority (CNA) and with a public PSIRT response system, ensures product security for hundreds of thousands of devices worldwide—this system was forged from the lessons learned during large-scale ransomware attacks. Each incident has led to structural reforms:
A product security incident response team, public security advisories, and full disclosure of CVE responses.
As a CNA, we collaborate with global security researchers to disclose vulnerabilities according to international standards and procedures.
Security Bounty Program—Let white hat researchers find problems before attackers do.
Non-essential services are disabled by default, enforced custom account passwords, and firmware signature verification, making security the starting point right out of the box.
Automatic security patch updates, public product support periods, and information security not ending with warranty expiration.
myQNAPcloud One cloud service operations have obtained ISO/IEC 27001 and 27017 certification (service scope)
Learn More →Product Security Incident Response Team; Security advisories are publicly released, QNAP is a CVE Numbering Authority (CNA)
Security Advisory →Security Bounty Program and global security researchers jointly disclose
Program Description →Product support and security update period can be checked publicly, unit replacement can be planned in advance
Support status inquiry →ISO 27 Customer Assurance Pack—reference for IT, explanation for auditors, a one-page document for the boss
Correct Understanding of NAS and ISO 27001
First, take the checklist for self-assessment, or discuss your company’s implementation scenario with QNAP