iso/iec 27001:2022 · popia

An ISMS you can
actually keep current

Track every Annex A control, run your risk register, build your Statement of Applicability, and generate the reports leadership and auditors ask for — without the spreadsheet sprawl.

annex a

All 93 controls, one register

The 2022 revision of ISO/IEC 27001, tracked control by control. Set applicability, record implementation status, attach evidence, and assign owners — the Statement of Applicability writes itself as you go.

  • Implementation status per control
  • Evidence attached where auditors expect it
  • Owners and review dates
  • Statement of Applicability, always up to date
control register93 controls
A.5.1Policies for information securityimplemented
A.5.7Threat intelligenceimplemented
A.8.8Technical vulnerabilitiesimplemented
A.8.9Configuration managementin progress
A.8.23Web filteringgap
risk

A risk register that drives action

Log risks, score them on a 5×5 heatmap, choose a treatment — treat, tolerate, transfer or terminate — and track inherent score down to residual. Risks connect to the controls that mitigate them and the findings that prove they're real.

  • Likelihood × impact scoring, inherent and residual
  • Treatment plans with owners and dates
  • Linked to controls and test findings both ways
  • Board-ready risk posture at a glance
risk registerresidual
R-02Credential stuffing on customer loginhigh
R-05Unpatched edge servicesmedium
R-08Supplier access review overduemedium
R-11Backup restore untestedlow
the registers nobody mentions in the demo

Seeded, not blank

A new workspace isn't an empty page. Your policies, assets and suppliers arrive scaffolded from the standard, so day one is editing rather than staring.

Policy library

Ten policies drafted against Annex A — information security, acceptable use, access control, classification, cryptography, supplier security, incident management, continuity, POPIA and secure development — each with an owner, a version, an approval status and a review date.

A.5.1

Asset register

Your inventory of information and associated assets, classified public through restricted, rated for criticality, with an owner and custodian and a link to the controls that protect each one.

A.5.9

Supplier register

Third parties tracked by the data they touch, their risk rating, whether a DPA is in place and when the next review falls due — the questions an auditor asks about outsourcing.

A.5.19–A.5.23

Awareness training

Induction, phishing, POPIA, acceptable use and incident reporting — who has completed what, when, and when it renews.

A.6.3

Compliance calendar

Everything with a date on it in one place: control reviews, policy reviews, supplier reviews, training renewals, internal audits and management reviews.

cadence

Findings & corrective actions

Nonconformities and improvement opportunities with severity, owner, root cause, corrective action and closure — the clause 10 machinery, tracked.

clause 10

Audits & management reviews

The internal audit programme and the management review record, kept where the evidence already lives.

clause 9.2 / 9.3

Getting started checklist

A guided path from empty workspace to audit-ready that ticks itself off as you go, so you always know the next useful thing to do.

onboarding

Audit trail

An immutable log of who changed what and when, across every register — including everything the AI operator did during a test.

A.8.15

See every module

Reports and trust, on demand

reporting

Written for the room they're read in

The same data, told six ways — board, IT, engineering, implementer, auditor and investigator.

  • Board report — posture, risk and progress, no jargon
  • IT & software reports — controls, gaps and owners, split by who fixes them
  • Implementer queue — what to do next, in priority order
  • Auditor pack & forensics — evidence with integrity hashes, assembled

Compare the six lenses →

trust center

Show customers you're serious

A shareable, read-only view of your security posture — so answering a customer's security questionnaire stops being a fire drill.

  • Public Trust Center page, white-labelled on Scale
  • Security questionnaires auto-answered from your ISMS
  • POPIA alignment tracked alongside ISO 27001
  • Framework crosswalk to SOC 2, NIST CSF 2.0, CIS v8.1 and GDPR

Inside the Trust Center →

evidence

Verified beats self-attested

Connect Microsoft 365, Google Workspace or Entra ID and evidence arrives from the system that enforces the control, marked verified and carrying a 90-day expiry so it can't quietly rot. Everything uploaded is SHA-256 hashed on capture.

  • Verified and self-attested evidence never blur together
  • Integrity hash on every artefact, visible in the auditor view
  • Expiring evidence surfaces as a gap, not a silent pass
  • Findings from your pen tests land as evidence automatically

How evidence gets in

evidence registersha-256
A.5.17MFA enrolment exportverified
A.8.13Backup job historyverified
A.5.18Quarterly access reviewexpires in 11d
A.8.7Endpoint protection reportself-attested

Set up your ISMS in an afternoon