one ISMS · six lenses

The same truth,
told six ways

A board member, a sysadmin, a developer, an implementer, an auditor and an investigator all need different things from the same management system. Writing six documents by hand is how they drift apart. Xee generates all six from one dataset.

for the board

Board report

Plain language, no acronyms, one page. The question it answers is "are we exposed, and is it getting better?"

  • Readiness and trend
  • Top business risks in English
  • Framework coverage
  • Assurance status
  • Prints into the board pack
for IT

IT report

The A.8 technical control surface, grouped the way an infrastructure team actually thinks about it.

  • Identity, logging, backup
  • Vulnerability and malware
  • Network and segregation
  • Verified evidence per domain
  • Open technical actions
for engineering

Software report

Only the secure-SDLC controls development owns — so nobody hands a developer a 93-row spreadsheet again.

  • A.8.25–A.8.29 secure development
  • Dev-facing questionnaire answers
  • Engineering findings
  • Fixes tied to controls
for the implementer

Implementer queue

Not a report — a work list. What to do next, in the order that moves readiness furthest.

  • Not-started and in-progress controls
  • Reviews falling due
  • Open findings by due date
  • Risks still needing treatment
for the auditor

Auditor pack

A read-only assessor view, shareable with an external auditor who gets this and nothing else.

  • Scope and readiness
  • Evidence sample with SHA-256 hashes
  • Audit programme
  • Nonconformities and corrective actions
  • Management reviews · prints as a pack
for the investigator

Forensics

The view you'll want on the worst day — built before you need it, not during the incident.

  • Searchable activity timeline
  • Chain-of-custody evidence register
  • Integrity hash per artefact
  • Incident-response and logging controls

Why this matters more than it sounds. Six hand-written documents means six versions of the truth, five of them out of date. Because every lens reads the same registers, closing a finding updates the board report, the IT report and the auditor pack at the same moment — and the audit trail shows exactly when it happened.

what's underneath

Generated, not maintained

Nothing here is a template you fill in. Each view is a query over the control register, the risk register, findings, evidence, audits and the activity log — rendered server-side, on demand, for whoever opened it.

  • No export-to-spreadsheet step in the middle
  • Evidence integrity hashes carried into the auditor and forensics views
  • Read-only external auditor role — the pack, nothing else
  • Print-to-PDF for the artefacts that leave the building
  • Score history behind the trend line, month by month
board report · Q3readiness 64%
Controls implemented59 of 93
High residual risk3 open
Nonconformities1 major
Reviews overdue4
Internal auditcomplete
Management reviewminuted

Stop writing the board pack by hand