ISO 27001

ISO 27001 compliance software

Compliancy supports an ISO/IEC 27001 information security management system by holding scope, risk assessment and treatment, Annex A control decisions, policies and evidence in one connected structure.

What ISO 27001 is

  • ISO/IEC 27001 is an international standard for an information security management system (ISMS).
  • Certification is granted by an accredited certification body after a stage 1 and stage 2 audit, followed by surveillance audits.
  • ISO/IEC 27001:2022 Annex A contains 93 controls grouped into organisational, people, physical and technological themes.

What organisations need to manage

  • Defined ISMS scope and context
  • A repeatable risk assessment and risk treatment process
  • Statement of Applicability decisions with justification
  • Documented policies and procedures
  • Internal audit and management review records
  • Corrective actions and continual improvement

How Compliancy helps

Risk register

Record risks with owners, treatment decisions and the controls that reduce them.

Annex A coverage

See which Annex A controls are applied, which are excluded and where justification is missing.

Evidence and records

Keep ISMS records connected to the controls and processes they belong to.

Audit preparation

Produce the control, risk and policy information a certification body asks for.

Reporting

Readiness you can show, not assemble.

How it connects to other frameworks

ISO 27001 and SOC 2 share substantial ground in access control, change management, supplier management and incident response. Compliancy maps one control to both so the same evidence counts once.

ISO 27001 questions

Does Compliancy certify our ISMS?

No. Certification is issued by an accredited certification body. Compliancy manages the ISMS information used during the audit.

Can we manage ISO 27001 and SOC 2 together?

Yes. Controls can be mapped to multiple frameworks in the same workspace.

Does Compliancy include a Statement of Applicability?

Compliancy holds the applicability decisions and justifications for Annex A controls that feed the Statement of Applicability.

Run ISO 27001 in one place.

Compliancy does not issue reports, certificates or legal advice. It manages the program behind them.