Skip to main content

Overview

CaseBender provides comprehensive ISO 27001:2022 Information Security Management System (ISMS) support. The platform maps its security controls to the ISO 27001 Annex A control set and provides tools for risk management, internal audit, and continuous improvement.

Annex A Control Coverage

Organizational Controls (A.5)

People Controls (A.6)

Technological Controls (A.8)

Risk Management

CaseBender includes a dedicated ISO 27001 risk management module:

Risk Register

  • Risk Identification: Catalog information security risks with threat and vulnerability mapping
  • Risk Assessment: Likelihood and impact scoring using configurable risk matrices
  • Risk Treatment: Define treatment plans with milestones, owners, and deadlines
  • Risk Acceptance: Formal risk acceptance workflow with management approval and documentation
  • Risk Monitoring: Track risk levels over time with trend analysis

Risk Matrix

Risks are evaluated on a 5x5 matrix:

Treatment Plans

Each risk treatment plan includes:
  • Treatment strategy (mitigate, transfer, accept, avoid)
  • Specific actions with owners and deadlines
  • Milestones for tracking progress
  • Residual risk assessment after treatment
  • Review schedule for ongoing monitoring

Statement of Applicability (SoA)

The SoA documents which Annex A controls are applicable to your deployment:
  • Applicable Controls: Controls that are relevant and implemented
  • Not Applicable Controls: Controls excluded with documented justification
  • Implementation Status: Current implementation level per control
  • Evidence Links: Direct links to evidence artifacts for each control
  • Approval Workflow: SoA changes require management approval

Internal Audit

Audit Cycle Management

  • Audit Planning: Define audit scope, schedule, and team assignments
  • Audit Execution: Guided audit procedures with evidence collection
  • Finding Management: Track findings by severity (major nonconformity, minor nonconformity, observation, opportunity for improvement)
  • Corrective Actions: Assign and track corrective actions with deadlines
  • Verification: Verify corrective action effectiveness before closure
  • Management Review: Aggregate audit results for management review meetings

Evidence Collection

Automated collectors gather ISO 27001-specific evidence:
  • Access control configurations and reviews
  • Security event logs and incident records
  • Change management records
  • Training and awareness records
  • Risk assessment documentation
  • Business continuity test results

Reporting

  • Compliance Dashboard: Real-time view of ISO 27001 control implementation status
  • Gap Analysis Report: Identify unimplemented or partially implemented controls
  • Risk Report: Current risk landscape with treatment status
  • Audit Report: Internal audit findings and corrective action status
  • Management Review Package: Aggregated data for management review meetings