Organization and accountability
Business functions, people, ISMS roles, organizational matrix, general RACI and function-specific RACI.
ISOPILOT provides ISO/IEC 27001 with a specialist workspace connecting organization, assets, risks, treatment, Annex A controls, Statement of Applicability, evidence, audits and improvement. Structured data drives document drafting and remains traceable throughout the ISMS lifecycle.
ISO 27001 is treated as a living system: each register is linked to the decisions that generated it and can become verifiable context for policies, procedures, audits and reviews.
Business functions, people, ISMS roles, organizational matrix, general RACI and function-specific RACI.
Internal/external issues, interested parties, relevant requirements, ISMS scope and climate-change relevance assessment under Amd 1:2024.
Inventory of information and associated assets with owner, type, location, classification, confidentiality, integrity, availability, criticality and dependencies.
Asset, threat, vulnerability, scenario, consequences, existing controls, likelihood, impact, inherent risk, treatment decision, owner and residual risk. Configurable 3×3 or 5×5 methodology, with risk acceptance and treatment-plan approval traceability.
Management of all 93 controls, applicability, rationale, implementation status, owner, linked risks, procedures and evidence. The SoA derives from recorded decisions, not an automatic AI choice.
The ISMS core document set and procedures are suggested from management-system requirements and applicable controls; they can be created individually or as a complete non-duplicating set in the Document Centre.
ISOPILOT includes a requirements matrix to track implementation, ownership, evidence and gaps across management-system clauses, keeping requirements distinct from Annex A controls.
Indicators, owners, deadlines, results and evidence for performance evaluation.
Register for applicable obligations, privacy, contracts, intellectual property and other relevant requirements.
Third parties, responsibilities, security requirements, control evidence and links to applicable controls.
Events, incidents, response, lessons learned and evidentiary material linkable to controls.
Training, required competence, awareness and records supporting implementation evidence.
Audit programmes and results, management review, nonconformities, corrective actions and improvement.
The value of the ISMS Workspace lies in relationships between data: a risk can be linked to treatment, Annex A controls, the SoA, procedures and evidence. The document engine receives this structure as context, reducing inconsistencies and generic text.
ISO/IEC 27001:2022 + Amd 1:2024 · ISMS requirements and integration of climate-change considerations.
ISO/IEC 27002:2022 · guidance for information security controls.
ISO/IEC 27005:2022 · guidance on managing information security risks.
ISOPILOT supports design, documented implementation, register management, risk management, document control and audit readiness. The platform does not issue ISO certificates and does not automatically determine conformity: control applicability, risk acceptance, approvals, implementation and validation remain decisions of the organization and competent professionals; certification is the responsibility of the certification body.
The specialist module links context, assets, risks, treatment, controls and evidence in a coherent pathway.
The workspace is designed for ISO/IEC 27001:2022 and considers Amd 1:2024, with dedicated coverage for clauses 4–10 and Annex A controls.
It manages organisation and RACI, Asset Register, Risk Register, Risk Treatment Plan, requirements matrix, 93 Annex A controls, Statement of Applicability and ISMS registers linked to evidence.
No. AI can assist analysis and preparation, but applicability, risk acceptance, approvals and governance decisions remain assigned to authorised human roles.
The model links Asset → Risk → Treatment → Annex A Control → SoA → Procedure → Evidence → Review, making the decision and documentation chain verifiable.