Overview
CaseBender provides comprehensive ISO 27001:2022 Information Security Management System (ISMS) support. The platform maps its security controls to the ISO 27001 Annex A control set and provides tools for risk management, internal audit, and continuous improvement.Annex A Control Coverage
Organizational Controls (A.5)
People Controls (A.6)
Technological Controls (A.8)
Risk Management
CaseBender includes a dedicated ISO 27001 risk management module:Risk Register
- Risk Identification: Catalog information security risks with threat and vulnerability mapping
- Risk Assessment: Likelihood and impact scoring using configurable risk matrices
- Risk Treatment: Define treatment plans with milestones, owners, and deadlines
- Risk Acceptance: Formal risk acceptance workflow with management approval and documentation
- Risk Monitoring: Track risk levels over time with trend analysis
Risk Matrix
Risks are evaluated on a 5x5 matrix:Treatment Plans
Each risk treatment plan includes:- Treatment strategy (mitigate, transfer, accept, avoid)
- Specific actions with owners and deadlines
- Milestones for tracking progress
- Residual risk assessment after treatment
- Review schedule for ongoing monitoring
Statement of Applicability (SoA)
The SoA documents which Annex A controls are applicable to your deployment:- Applicable Controls: Controls that are relevant and implemented
- Not Applicable Controls: Controls excluded with documented justification
- Implementation Status: Current implementation level per control
- Evidence Links: Direct links to evidence artifacts for each control
- Approval Workflow: SoA changes require management approval
Internal Audit
Audit Cycle Management
- Audit Planning: Define audit scope, schedule, and team assignments
- Audit Execution: Guided audit procedures with evidence collection
- Finding Management: Track findings by severity (major nonconformity, minor nonconformity, observation, opportunity for improvement)
- Corrective Actions: Assign and track corrective actions with deadlines
- Verification: Verify corrective action effectiveness before closure
- Management Review: Aggregate audit results for management review meetings
Evidence Collection
Automated collectors gather ISO 27001-specific evidence:- Access control configurations and reviews
- Security event logs and incident records
- Change management records
- Training and awareness records
- Risk assessment documentation
- Business continuity test results
Reporting
- Compliance Dashboard: Real-time view of ISO 27001 control implementation status
- Gap Analysis Report: Identify unimplemented or partially implemented controls
- Risk Report: Current risk landscape with treatment status
- Audit Report: Internal audit findings and corrective action status
- Management Review Package: Aggregated data for management review meetings
Related Documentation
- Compliance Overview — All supported frameworks
- Data Protection — Encryption and data handling controls
- Threat Detection — Monitoring and detection capabilities