Digital platform by UESE ITALIA S.p.A.ISO governance and audit-ready documents
Trust CentreSupport
ISOPILOT ISO Management Workspace
ISO/IEC 27001:2022 · AMD 1:2024 · SGSI WORKSPACE

ISO/IEC 27001: a governed ISMS, not just a document package.

ISOPILOT provides ISO/IEC 27001 with a specialist workspace connecting organization, assets, risks, treatment, Annex A controls, Statement of Applicability, evidence, audits and improvement. Structured data drives document drafting and remains traceable throughout the ISMS lifecycle.

✓ Clauses 4–10✓ Annex A / SoA✓ ISO/IEC 27005:2022✓ ISO/IEC 27002:2022✓ Amd 1:2024 climate
01Structured ISMS data02Traceable SoA decisions03Documents generated from real context04Continuous audit readiness
THE SPECIALIST WORKSPACE

Everything needed to build and maintain the ISMS coherently.

ISO 27001 is treated as a living system: each register is linked to the decisions that generated it and can become verifiable context for policies, procedures, audits and reviews.

01

Organization and accountability

Business functions, people, ISMS roles, organizational matrix, general RACI and function-specific RACI.

02

Context and scope

Internal/external issues, interested parties, relevant requirements, ISMS scope and climate-change relevance assessment under Amd 1:2024.

03

Asset Register

Inventory of information and associated assets with owner, type, location, classification, confidentiality, integrity, availability, criticality and dependencies.

04

Risk assessment and treatment

Asset, threat, vulnerability, scenario, consequences, existing controls, likelihood, impact, inherent risk, treatment decision, owner and residual risk. Configurable 3×3 or 5×5 methodology, with risk acceptance and treatment-plan approval traceability.

05

Annex A & Statement of Applicability

Management of all 93 controls, applicability, rationale, implementation status, owner, linked risks, procedures and evidence. The SoA derives from recorded decisions, not an automatic AI choice.

06

Context-aware procedure suggestions

The ISMS core document set and procedures are suggested from management-system requirements and applicable controls; they can be created individually or as a complete non-duplicating set in the Document Centre.

CLAUSES 4–10

We go beyond assets and controls: the management system itself is governed too.

ISOPILOT includes a requirements matrix to track implementation, ownership, evidence and gaps across management-system clauses, keeping requirements distinct from Annex A controls.

Leadership and policyISMS risks and opportunitiesSecurity objectivesResources and competenceAwareness and communicationDocumented informationOperational planning and controlMonitoring and KPIsInternal auditManagement reviewNonconformity and corrective actionContinual improvement
REGISTERS AND EVIDENCE

The layer that makes the ISMS demonstrable during audits and reviews.

Objectives, KPIs and measurements

Indicators, owners, deadlines, results and evidence for performance evaluation.

Legal and contractual requirements

Register for applicable obligations, privacy, contracts, intellectual property and other relevant requirements.

Suppliers, supply chain and cloud

Third parties, responsibilities, security requirements, control evidence and links to applicable controls.

Incidents and evidence collection

Events, incidents, response, lessons learned and evidentiary material linkable to controls.

Competence and awareness

Training, required competence, awareness and records supporting implementation evidence.

Audit, review and improvement

Audit programmes and results, management review, nonconformities, corrective actions and improvement.

TRACEABILITY

From risk to implementation evidence.

The value of the ISMS Workspace lies in relationships between data: a risk can be linked to treatment, Annex A controls, the SoA, procedures and evidence. The document engine receives this structure as context, reducing inconsistencies and generic text.

AssetRiskTreatmentAnnex ASoAProcedureEvidence
TECHNICAL REFERENCES

A pathway aligned with the current ISMS family editions.

ISO/IEC 27001:2022 + Amd 1:2024 · ISMS requirements and integration of climate-change considerations.

ISO/IEC 27002:2022 · guidance for information security controls.

ISO/IEC 27005:2022 · guidance on managing information security risks.

Responsibility and certification

ISOPILOT supports design, documented implementation, register management, risk management, document control and audit readiness. The platform does not issue ISO certificates and does not automatically determine conformity: control applicability, risk acceptance, approvals, implementation and validation remain decisions of the organization and competent professionals; certification is the responsibility of the certification body.

Create the ISMS Workspace →
ISO/IEC 27001 · QUICK ANSWERS

What does the ISO/IEC 27001 ISMS Workspace add?

The specialist module links context, assets, risks, treatment, controls and evidence in a coherent pathway.

Which version of the standard does the ISMS Workspace support?

The workspace is designed for ISO/IEC 27001:2022 and considers Amd 1:2024, with dedicated coverage for clauses 4–10 and Annex A controls.

Which specialist registers does it manage?

It manages organisation and RACI, Asset Register, Risk Register, Risk Treatment Plan, requirements matrix, 93 Annex A controls, Statement of Applicability and ISMS registers linked to evidence.

Does AI decide control applicability or accept risks?

No. AI can assist analysis and preparation, but applicability, risk acceptance, approvals and governance decisions remain assigned to authorised human roles.

How is traceability maintained?

The model links Asset → Risk → Treatment → Annex A Control → SoA → Procedure → Evidence → Review, making the decision and documentation chain verifiable.