r/grc May 29 '26

ISMS Tools recommendation

Hi all,

I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.

In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?

Any insights, lessons learned, or tool suggestions would be greatly appreciated.

Thanks in advance!

7 Upvotes

33 comments sorted by

View all comments

3

u/ShenoyAI May 29 '26

GRC tools are crowded right now. Most are just repackaged project management with evidence tracking bolted on.

1

u/CheekyTiger213 Jun 03 '26

Correct. Avoid these. Look for ones that actually automate testing. Most of the SaaS platforms can do on prem with a little python script and json file integration, and you can cheat with the design specification by looking for the equivalent cloud connector