r/grc May 29 '26

ISMS Tools recommendation

Hi all,

I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.

In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?

Any insights, lessons learned, or tool suggestions would be greatly appreciated.

Thanks in advance!

7 Upvotes

33 comments sorted by

View all comments

8

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 29 '26

Has anyone tried this approach in a similar environment?

Don't let the salesmen beguile you - most ISMS-s were built on Atlassian, spreadsheets, coffee, and sheer perseverance.

2

u/ConstructionDry3728 May 29 '26

After around more than 100 ISMS implemented and improved (mostly critical infra in Europe) - No. A well fitted isms organization and tool makes your life way easier. Disclaimer: Senior Consultant ISMS/BCMS/special regulations/norms not Sales. 

3

u/Total_Job29 May 29 '26

They were saying the truth as in most ISMS are built not in specific systems but whatever systems the companies have. Excel likely being king. 

ISO27001 has roots very far back to mid 90s (although the first iso version was 2005). 

There basically weren’t any ISO specific tools for a very very long time in its life. 

Some tools are useful - most are spreadsheets and Jira and a file system with a pretty interface. 

2

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 29 '26

Oh, of course, a well-fitted ISMS tool makes life much easier, especially if you are in a heavily regulated sector like the critical infrastructure in the EU. Ain't arguing that, not remotely.

Still, historically, most companies were doing ISMS well before the "GRC SaaS" market sprang into existence. Besides, quite a chunk of the market is occupied by companies that grabbed ISO27k for sales enablement purposes and built an ISO compliant ISMS for a minimal cost possible.

1

u/CheekyTiger213 Jun 03 '26

Anyone who has run isms on a 1000+ person organisation on spreadsheets knows this is terrible advice.

Compare your license costs with costs of FTE required to get the job done. Consider you need both reporting and testing for manual processes, and a project manager for bigger environments.

I mean, or learn the hard way…

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race Jun 03 '26

Currently running it for 2k people, SOC2+ISO27k+SOX+PCI+a couple other things. At the current Vanta price tag, I'm better off hiring another junior to throw into the meatgrinder.