Two standards are modelled in the product, not attached as a template pack:
- ISO/IEC 27001:2022 — clauses 4 to 10 and all 93 Annex A controls, with the eleven that are new in the 2022 revision flagged as such.
- The ACSC Essential Eight, with maturity levels 0 to 3.
What is actually here
A Statement of Applicability. A risk register. An information-asset inventory. Control ownership, with a named owner per control and a visible gap where there is not one. An internal audit programme with findings. Management reviews. Certificate and surveillance-audit tracking. A readiness score that is a calculation over those, not a self-assessment.
Evidence has an expiry date
This is the difference between a compliance product and a folder. Every evidence item carries a freshness window. A screenshot of MFA coverage taken fourteen months ago is not evidence, and the system says so before the auditor does.
Two scheduled jobs run against that: one collects, one checks for expiry.
Four collectors gather evidence on their own
- Microsoft 365 MFA coverage
- Application access reviews
- Supplier certificates
- Third-party grants of access
Each runs on a schedule and files what it finds against the control it evidences, with a record of the run. That is four fewer recurring calendar reminders and four fewer screenshots taken the week before an audit.
Incidents, and the notifiable-breach clock
Security incidents are tickets — the same ticket system, so an incident has a queue, a participant list, a history and an SLA rather than a separate tool nobody opens.
On top of that sits the Notifiable Data Breaches clock. Australian privacy law gives you thirty days to assess. The system warns at day twenty-one and escalates at day twenty-eight. It is a countdown that runs whether or not anyone remembered to start it.
Roles are per certification
Control ownership is assigned within a certification rather than by global role, because the person who owns access reviews for ISO 27001 is not necessarily an administrator of the system.