ISO 27001 and Essential Eight

An evidence-freshness problem, not a document exercise. Four collectors gather it on a schedule — and it is in the price, where the specialists charge per seat for it.

Two standards are modelled in the product, not attached as a template pack:

  • ISO/IEC 27001:2022 — clauses 4 to 10 and all 93 Annex A controls, with the eleven that are new in the 2022 revision flagged as such.
  • The ACSC Essential Eight, with maturity levels 0 to 3.

What is actually here

A Statement of Applicability. A risk register. An information-asset inventory. Control ownership, with a named owner per control and a visible gap where there is not one. An internal audit programme with findings. Management reviews. Certificate and surveillance-audit tracking. A readiness score that is a calculation over those, not a self-assessment.

Evidence has an expiry date

This is the difference between a compliance product and a folder. Every evidence item carries a freshness window. A screenshot of MFA coverage taken fourteen months ago is not evidence, and the system says so before the auditor does.

Two scheduled jobs run against that: one collects, one checks for expiry.

Four collectors gather evidence on their own

  • Microsoft 365 MFA coverage
  • Application access reviews
  • Supplier certificates
  • Third-party grants of access

Each runs on a schedule and files what it finds against the control it evidences, with a record of the run. That is four fewer recurring calendar reminders and four fewer screenshots taken the week before an audit.

Incidents, and the notifiable-breach clock

Security incidents are tickets — the same ticket system, so an incident has a queue, a participant list, a history and an SLA rather than a separate tool nobody opens.

On top of that sits the Notifiable Data Breaches clock. Australian privacy law gives you thirty days to assess. The system warns at day twenty-one and escalates at day twenty-eight. It is a countdown that runs whether or not anyone remembered to start it.

Roles are per certification

Control ownership is assigned within a certification rather than by global role, because the person who owns access reviews for ISO 27001 is not necessarily an administrator of the system.