CyberGrape – cyber security certification and GRC platform for small business

ISO 27001:2022 · ISMS programme

Build an ISMS that runs from first scope to continuous improvement.

CyberGrape brings risk, policies, evidence, incident readiness, audit activity and executive reporting into one programme. Establish the system, prove it operates, prepare for independent certification and keep improving after the audit.

Explore the journey

One operating system

ISO 27001 is a management programme, not a control checklist.

Certification depends on more than having policies or configuring security tools. You need a defined scope, risk-based decisions, accountable owners, evidence that controls operate, management oversight and a repeatable improvement cycle.

CyberGrape connects those activities. A vulnerability can update control effectiveness and residual risk. An exercise can create corrective actions. A policy approval can become evidence. The executive report reflects the same live programme your auditor reviews.

Clauses 4–10

Management-system requirements organised into one programme

93 controls

Annex A applicability, implementation and evidence tracked

One evidence base

Technical, documentary and human assurance connected

Continual

Risk, audit and improvement continue beyond certification

app.cybergrape.io/compliance/iso27001
Dashboard
SoA
Risk Treatment
Audit
Reports
61%
ISMS Readiness
79
Controls decided
47
Days to Stage 1
Management System Clauses
4
Context
Complete
5
Leadership
Complete
6
Planning
In progress
7
Support
In progress
8
Operation
In progress
9
Performance
Not started
10
Improvement
Not started
Scope checklist
Organisational context defined
Interested parties documented
ISMS scope approved
Information security objectives
Recent programme activity
Risk assessment completed — 24 risks recordedToday
SoA v0.3 exported for internal review2 days ago
Information Security Policy approved1 week ago
Stage 1 readiness
3 of 7 management system clauses complete

Start to finish

A complete ISO 27001 programme in ten connected stages.

Each stage produces the inputs for the next. Control assessment, technical validation and supplier assessment can run in parallel once scope and inherent risk are understood.

01Establish

Set context and scope

Define the organisation, interested parties, business objectives, legal obligations, locations, systems, data and exclusions that belong inside the ISMS. Record owners and approval so the programme starts with an agreed boundary.

Programme output

ISMS scope, context, stakeholders and objectives

02Establish

Discover what is really there

Build the baseline from your asset register, identity estate, endpoints, cloud services, suppliers and information flows. Connected tools expose the environment as it operates, not as an old spreadsheet describes it.

Programme output

Current asset, identity, supplier and data baseline

03Establish

Assess and prioritise risk

Identify business-critical assets and realistic threat scenarios, score inherent risk, assign owners and map the controls that will treat each risk. Priorities reflect business impact instead of a generic checklist.

Programme output

Inherent risk register and control priorities

04Design

Select controls and treatment

Decide whether every Annex A control is applicable, justify exclusions and build the Statement of Applicability. Convert gaps into owned risk treatment actions with target dates and acceptance criteria.

Programme output

Statement of Applicability and risk treatment plan

05Implement

Build policies and procedures

Start from policy templates, tailor them to the organisation, obtain approval and manage versions, acknowledgements and review dates. Policies remain connected to the controls and risks they are intended to address.

Programme output

Controlled ISMS policy and procedure set

06Implement

Operate controls and collect evidence

Use integrations to collect recurring technical evidence and combine it with interviews, documents and samples for controls automation cannot observe. Assess intent, implementation and operating effectiveness separately.

Programme output

Live evidence library and control assessments

07Operate

Exercise and respond

Create incident response plans, assign roles and run structured tabletop exercises. Real incidents and exercises produce time-stamped records, lessons learned, new risks and remediation actions.

Programme output

Tested response plans, exercise records and actions

08Review

Audit, review and report

Plan internal audits, track findings and bring performance, risks, incidents, objectives and improvement decisions into management review. Generate separate board, management and auditor-ready views from the same live programme.

Programme output

Internal audit, management review and executive reporting

09Certify

Prepare for independent audit

Package the approved SoA, policies, risk treatment records and control evidence for Stage 1 and Stage 2 review. CyberGrape supports readiness and evidence coordination; certification decisions remain with an independent certification body.

Programme output

Controlled, traceable certification evidence pack

10Improve

Improve continuously

Track corrective actions to verified closure, reassess residual risk and trigger reviews when technology, suppliers, incidents or business priorities change. The ISMS stays operational after the audit instead of becoming a yearly scramble.

Programme output

Corrective actions, monitoring cadence and measurable improvement

Automated assurance

Integrations turn live operations into control evidence.

Connected tools do not replace assessment. They remove repetitive evidence chasing and give assessors current data to test whether controls are actually operating.

Identity and access

Microsoft Entra ID and Microsoft 365

Users, privileged roles, MFA, account hygiene and access configuration become evidence for identity and access controls.

Endpoints and vulnerability

Intune, NinjaOne and CrowdStrike

Device inventory, patch status, endpoint protection and vulnerability findings support implementation and effectiveness assessments.

Network and external exposure

Meraki, Cloudflare and attack-surface monitoring

Network configuration and observable external risk help validate that documented controls are operating in the real environment.

Email and awareness

Email security and uSecure

Mail protection, training completion and phishing results provide recurring evidence for people and communications controls.

Cloud, SaaS and suppliers

Cloud services and third-party monitoring

Connected services populate the technology and supplier picture while critical vendors retain proportionate questionnaires and reviews.

Human and documentary evidence

Policies, interviews, samples and approvals

Not every requirement is technical. Manual evidence sits beside integration data with owners, dates, mappings and review history.

Evidence is assessed in three layers: whether the control intent is documented, whether it is implemented, and whether it is demonstrably effective. Interviews, review and sampling remain essential where integrations cannot answer the question.

Risk-led priorities

Start with what matters to the business.

The platform keeps risk assessment connected to the controls, findings and work that reduce it. That gives leaders a defensible basis for sequencing investment instead of treating every gap as equally urgent.

1

Inherent risk

Score realistic scenarios before relying on controls, using business criticality, threats, obligations and prior incidents.

2

Control treatment

Map risks to applicable controls, define actions, owners, dates and the target level the organisation is prepared to accept.

3

Effectiveness

Use evidence, testing, incidents and supplier findings to determine whether controls exist, operate and produce the intended result.

4

Residual risk

Re-score with real control effectiveness applied, expose the remaining decision and report the risk reduction achieved.

Explore risk management
app.cybergrape.io/compliance/iso27001/risk-treatment
Risk Treatment PlanISO 27001
24
Risks
6
Extreme/High
18
Treating
Unauthorised access to cloud storage
ExtremeHigh· IT Lead
Ransomware via compromised vendor access
ExtremeModerate· IT Lead
Staff phishing — finance accounts
HighLow· HR
Unpatched public-facing systems
HighModerate· IT Lead
Inadequate supplier security review
ModerateLow· Ops Mgr
Unauthorised access to cloud storage
Inherent: ExtremeResidual: High
Add action
Treatment progress40%
Enable private access controls on all storage buckets
Enforce MFA for all administrative accounts
Review and revoke excess permissions quarterly
Enable audit logging for data access events
Annex A controls treating this risk
8.25.158.3
Risk owner
IT Lead
Target closure
31 Mar 2026

Operate the ISMS

Templates get you moving. Governance keeps the programme real.

Establish the documented system, put it into operation, test it and retain the records that show decisions were made and actions were completed.

Templates that become controlled documents

Start with practical policy and procedure templates, tailor them to the organisation, route them for approval and retain versions, owners, acknowledgements and scheduled reviews.

Incident plans that are exercised

Draft response plans with roles, escalation paths and communications requirements, then run tabletop exercises that create evidence, findings and improvement actions.

Governance that runs on schedule

Track objectives, obligations, competence, change, internal audits, management reviews and corrective actions as one operating programme rather than disconnected documents.

Reporting for each audience

Give boards the risk and decision view, management an owned remediation roadmap, and auditors the control, evidence and document trail behind each conclusion.

Statement of Applicability

The decision record at the centre of your control programme.

Manage all 93 Annex A controls in one structured view. Every applicability decision, implementation statement and exclusion rationale stays linked to risks, owners, treatment actions and the evidence used to support it.

Applicability and exclusion rationale
Implementation status and notes
Linked risks and treatment actions
Control owner and review date
Mapped technical and manual evidence
Approval and document control history
app.cybergrape.io/compliance/iso27001/soa
Statement of Applicability — Annex A (ISO 27001:2022)
Export SoA
Submit for review
93
Total controls
87
Applicable
34
Implemented
28
Partial / Planned
25
Not yet assessed
🔍 Search controls…
All
Applicable
Implemented
Gaps
Chapter 5Organisational controls· 37 controls
5.1Policies for information securityImplemented
3
5.2Information security roles & responsibilitiesImplemented
2
5.9Inventory of information and other assetsPartially impl.
1
5.19Information security in supplier relationshipsAssessed
5.23Information security for use of cloud servicesAssessed
5.31Legal, statutory, regulatory, contractual req.Planned
Chapter 6People controls· 8 controls
6.1ScreeningImplemented
2
6.3Information security awareness, educationImplemented
4
6.8Information security event reportingPlanned
Chapter 7Physical controls· 14 controls
7.1Physical security perimetersImplemented
1
7.9Security of assets off-premisesN/A
Chapter 8Technological controls· 34 controls
8.2Privileged access rightsImplemented
5
8.7Protection against malwareImplemented
6
8.8Management of technical vulnerabilitiesPartially impl.
3
8.20Networks securityAssessed
8.28Secure codingN/A

Executive oversight

One programme. Different views for the board, management and auditor.

Board reports focus on material risk, trends, objectives and decisions. Management reports carry the remediation roadmap, owners, dates and progress. Auditor exports preserve the SoA, policy, risk and evidence trail behind each conclusion.

See executive reporting
app.cybergrape.io/reporting/iso27001/executive
ISO 27001 Executive Report
Acme Financial Pty Ltd · Q3 2026 · Board Confidential
Board view
Management view
Auditor view
ISMS health summary
ISMS Readiness
61%
↑ 8pp this quarter
Controls implemented
34 / 87
39% of applicable
Open high risks
4
2 treatment plans active
Policies published
9 / 14
5 pending approval
Annex A implementation by chapter
Org controls (Ch.5)52%
People (Ch.6)75%
Physical (Ch.7)86%
Tech controls (Ch.8)44%
Certification timeline
Stage 1 (Doc review)May 2026
Stage 2 (On-site audit)Aug 2026
Certification issuedSep 2026
Board decisions required
High

Approve risk treatment budget: $48,000 for cloud access remediation

Medium

Accept residual risk: data residency gap — legal review attached

Low

Approve ISMS scope extension to include New Zealand operations

AI-generated summary

ISMS readiness improved 8pp this quarter. Technological controls remain the largest gap (44%). Three board decisions are required to unblock the Stage 1 audit timeline.

Common questions about building an ISO 27001 ISMS.

Start with your scope, context and risk.

We will help you understand where the organisation stands, what the ISMS needs to cover and how to build a practical programme towards independent ISO 27001 certification.

See compliance frameworks