ISO 27001:2022 · ISMS programme
Build an ISMS that runs from first scope to continuous improvement.
CyberGrape brings risk, policies, evidence, incident readiness, audit activity and executive reporting into one programme. Establish the system, prove it operates, prepare for independent certification and keep improving after the audit.
One operating system
ISO 27001 is a management programme, not a control checklist.
Certification depends on more than having policies or configuring security tools. You need a defined scope, risk-based decisions, accountable owners, evidence that controls operate, management oversight and a repeatable improvement cycle.
CyberGrape connects those activities. A vulnerability can update control effectiveness and residual risk. An exercise can create corrective actions. A policy approval can become evidence. The executive report reflects the same live programme your auditor reviews.
Management-system requirements organised into one programme
Annex A applicability, implementation and evidence tracked
Technical, documentary and human assurance connected
Risk, audit and improvement continue beyond certification
Start to finish
A complete ISO 27001 programme in ten connected stages.
Each stage produces the inputs for the next. Control assessment, technical validation and supplier assessment can run in parallel once scope and inherent risk are understood.
Set context and scope
Define the organisation, interested parties, business objectives, legal obligations, locations, systems, data and exclusions that belong inside the ISMS. Record owners and approval so the programme starts with an agreed boundary.
ISMS scope, context, stakeholders and objectives
Discover what is really there
Build the baseline from your asset register, identity estate, endpoints, cloud services, suppliers and information flows. Connected tools expose the environment as it operates, not as an old spreadsheet describes it.
Current asset, identity, supplier and data baseline
Assess and prioritise risk
Identify business-critical assets and realistic threat scenarios, score inherent risk, assign owners and map the controls that will treat each risk. Priorities reflect business impact instead of a generic checklist.
Inherent risk register and control priorities
Select controls and treatment
Decide whether every Annex A control is applicable, justify exclusions and build the Statement of Applicability. Convert gaps into owned risk treatment actions with target dates and acceptance criteria.
Statement of Applicability and risk treatment plan
Build policies and procedures
Start from policy templates, tailor them to the organisation, obtain approval and manage versions, acknowledgements and review dates. Policies remain connected to the controls and risks they are intended to address.
Controlled ISMS policy and procedure set
Operate controls and collect evidence
Use integrations to collect recurring technical evidence and combine it with interviews, documents and samples for controls automation cannot observe. Assess intent, implementation and operating effectiveness separately.
Live evidence library and control assessments
Exercise and respond
Create incident response plans, assign roles and run structured tabletop exercises. Real incidents and exercises produce time-stamped records, lessons learned, new risks and remediation actions.
Tested response plans, exercise records and actions
Audit, review and report
Plan internal audits, track findings and bring performance, risks, incidents, objectives and improvement decisions into management review. Generate separate board, management and auditor-ready views from the same live programme.
Internal audit, management review and executive reporting
Prepare for independent audit
Package the approved SoA, policies, risk treatment records and control evidence for Stage 1 and Stage 2 review. CyberGrape supports readiness and evidence coordination; certification decisions remain with an independent certification body.
Controlled, traceable certification evidence pack
Improve continuously
Track corrective actions to verified closure, reassess residual risk and trigger reviews when technology, suppliers, incidents or business priorities change. The ISMS stays operational after the audit instead of becoming a yearly scramble.
Corrective actions, monitoring cadence and measurable improvement
Automated assurance
Integrations turn live operations into control evidence.
Connected tools do not replace assessment. They remove repetitive evidence chasing and give assessors current data to test whether controls are actually operating.
Identity and access
Microsoft Entra ID and Microsoft 365
Users, privileged roles, MFA, account hygiene and access configuration become evidence for identity and access controls.
Endpoints and vulnerability
Intune, NinjaOne and CrowdStrike
Device inventory, patch status, endpoint protection and vulnerability findings support implementation and effectiveness assessments.
Network and external exposure
Meraki, Cloudflare and attack-surface monitoring
Network configuration and observable external risk help validate that documented controls are operating in the real environment.
Email and awareness
Email security and uSecure
Mail protection, training completion and phishing results provide recurring evidence for people and communications controls.
Cloud, SaaS and suppliers
Cloud services and third-party monitoring
Connected services populate the technology and supplier picture while critical vendors retain proportionate questionnaires and reviews.
Human and documentary evidence
Policies, interviews, samples and approvals
Not every requirement is technical. Manual evidence sits beside integration data with owners, dates, mappings and review history.
Evidence is assessed in three layers: whether the control intent is documented, whether it is implemented, and whether it is demonstrably effective. Interviews, review and sampling remain essential where integrations cannot answer the question.
Risk-led priorities
Start with what matters to the business.
The platform keeps risk assessment connected to the controls, findings and work that reduce it. That gives leaders a defensible basis for sequencing investment instead of treating every gap as equally urgent.
Inherent risk
Score realistic scenarios before relying on controls, using business criticality, threats, obligations and prior incidents.
Control treatment
Map risks to applicable controls, define actions, owners, dates and the target level the organisation is prepared to accept.
Effectiveness
Use evidence, testing, incidents and supplier findings to determine whether controls exist, operate and produce the intended result.
Residual risk
Re-score with real control effectiveness applied, expose the remaining decision and report the risk reduction achieved.
Operate the ISMS
Templates get you moving. Governance keeps the programme real.
Establish the documented system, put it into operation, test it and retain the records that show decisions were made and actions were completed.
Templates that become controlled documents
Start with practical policy and procedure templates, tailor them to the organisation, route them for approval and retain versions, owners, acknowledgements and scheduled reviews.
Incident plans that are exercised
Draft response plans with roles, escalation paths and communications requirements, then run tabletop exercises that create evidence, findings and improvement actions.
Governance that runs on schedule
Track objectives, obligations, competence, change, internal audits, management reviews and corrective actions as one operating programme rather than disconnected documents.
Reporting for each audience
Give boards the risk and decision view, management an owned remediation roadmap, and auditors the control, evidence and document trail behind each conclusion.
Statement of Applicability
The decision record at the centre of your control programme.
Manage all 93 Annex A controls in one structured view. Every applicability decision, implementation statement and exclusion rationale stays linked to risks, owners, treatment actions and the evidence used to support it.
Executive oversight
One programme. Different views for the board, management and auditor.
Board reports focus on material risk, trends, objectives and decisions. Management reports carry the remediation roadmap, owners, dates and progress. Auditor exports preserve the SoA, policy, risk and evidence trail behind each conclusion.
See executive reportingApprove risk treatment budget: $48,000 for cloud access remediation
Accept residual risk: data residency gap — legal review attached
Approve ISMS scope extension to include New Zealand operations
ISMS readiness improved 8pp this quarter. Technological controls remain the largest gap (44%). Three board decisions are required to unblock the Stage 1 audit timeline.
Common questions about building an ISO 27001 ISMS.
Yes. The platform supports the complete programme from scope, context and risk assessment through the Statement of Applicability, policies, treatment actions, evidence, internal audit, management review and certification readiness. Your team and advisers remain responsible for decisions and operation of the ISMS, while the independent certification body makes the certification decision.
Integrations bring current information from identity, endpoint, network, cloud, email, awareness and security tools into a shared evidence library. The platform maps that evidence to relevant Annex A controls so assessors can verify implementation and operating effectiveness. Interviews, documents and sampling remain available for requirements that tools cannot observe.
Work begins with business context and inherent risk rather than a flat list of controls. Risks are mapped to treatments and applicable controls, then findings are prioritised by impact, effort, ownership and target residual risk. That creates a remediation roadmap leadership can fund and track.
Yes. CyberGrape provides templates to help establish the ISMS policy set and incident response plans. Documents can be tailored, approved, versioned, acknowledged and reviewed in the platform. Incident plans can also be exercised through structured tabletop activities, with findings retained as evidence and actions tracked to closure.
Executive reporting draws from the live risk register, control coverage, treatment actions, incidents, audit findings and certification progress. Boards receive a plain-language view of material risks, trends and decisions, while management receives the detailed roadmap and owners behind the summary.
No. CyberGrape helps organisations establish and operate an ISO 27001:2022-based ISMS and prepare evidence for audit. Certification is awarded only by an independent accredited certification body after its own assessment.
Start with your scope, context and risk.
We will help you understand where the organisation stands, what the ISMS needs to cover and how to build a practical programme towards independent ISO 27001 certification.

