CapGRC
CapGRC
All solutions
ISO 27001

ISO 27001 — Achieve and maintain your certification with CapGRC

From gap analysis to certification, CapGRC structures your ISMS and automates Annex A control tracking.

What ISO 27001 requires

ISO 27001 defines requirements for an Information Security Management System (ISMS). CapGRC supports you in obtaining and maintaining your certification.

01

Management system (ISMS)

Establish a documented and structured ISMS.

02

Risk analysis

Conduct a methodical and documented risk analysis.

03

Annex A controls

Implement and track the 93 Annex A controls (2022 version).

04

Statement of Applicability (SoA)

Produce and maintain an up-to-date SoA.

05

Internal audits

Conduct regular internal ISMS audits.

06

Management review

Conduct periodic management reviews.

How CapGRC responds

RequirementCapGRC feature
ISMSGRC Programs module — Policy and ISMS management
Risk analysisRisk module — Register and ISO 27005 methodology
Annex A controlsCompliance module — Pre-loaded ISO 27001 framework
SoACompliance module — Automatic SoA generation
Internal auditsAudit module — Guided ISO 27001 audits

Recommended modules

Ready to ensure your ISO 27001 compliance?

Request a free consultation and discover how CapGRC can structure your compliance program.