Information Security Management
ISO/IEC 27001
InternationalThe management-system standard most groups use as their anchor, and the one most other frameworks map cleanly onto. A sensible choice for the primary standard on a shared control.
Frameworks
Jurisdictions, authorities, domains, and controls are records in the library rather than logic in the code. The five below are what we hold today. Whichever framework governs you is loaded the same way, and mapped to the controls you already test.
Information Security Management
The management-system standard most groups use as their anchor, and the one most other frameworks map cleanly onto. A sensible choice for the primary standard on a shared control.
Cybersecurity Framework
Five functions that summarise posture for a board without cutting the thread back to the controls and evidence that produced the number.
Essential Cybersecurity Controls
An example of a national baseline: five domains, full coverage expected rather than selective adoption, including a dedicated industrial control systems domain.
Cyber Security Framework
An example of a sector regulator, with a third-party chapter heavy enough that it usually forces a second tool. Here it reads the same vendor register as everything else.
Personal Data Protection
An example of a privacy regime, held as controls in the same library and mapped to the security controls that already satisfy them rather than run as a separate programme.
Your own authority
That is the normal case, and it is a loading exercise rather than a development one. Controls import from a header-based workbook, publish as a versioned release, and map to what you already hold. Requirements of your own become company-scoped custom controls with their own identifiers and authorship trail.
Talk to our teamBook a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.