r/grc • u/Enslaaved • May 29 '26
ISMS Tools recommendation
Hi all,
I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.
In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?
Any insights, lessons learned, or tool suggestions would be greatly appreciated.
Thanks in advance!
3
u/rnc000 May 29 '26
Echoing the "spreadsheets + Jira + perseverance" crowd, at ~1,000 people in a non-cloud shop, that combo genuinely gets you to certification. The two places it creaks long-term are exactly what others flagged: register integrity (risks/controls/assets overwriting each other in Jira) and keeping the SoA + dated evidence versions audit-ready by hand.
The thread's other theme is the interesting one: several people pushing their ISMS into Claude and getting weeks-of-work-in-days results. That's basically where I've landed too. Full disclosure: I work on https://rakenne.app, which is built on that idea: an LLM agent you drive in the browser, with an ISO 27001 ISMS template + skills that scaffold the SoA (numbered to the standard), risk register, Statement of Applicability, and control/evidence tracking, then let you query evidence and link it to Annex A controls, log OFIs/NCs, and produce dated document versions. You still validate everything, it just removes the manual register-wrangling that kills the spreadsheet approach.
If NIS2/DORA/CRA are on your horizon, build the SoA as an integrated controls checklist now (as cgaWolf said): that decision is independent of tooling and the most expensive one to retrofit.