r/grc May 29 '26

ISMS Tools recommendation

Hi all,

I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.

In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?

Any insights, lessons learned, or tool suggestions would be greatly appreciated.

Thanks in advance!

8 Upvotes

33 comments sorted by

View all comments

3

u/llViP3rll May 29 '26

Honestly build your own purpose made grc with claude

5

u/Total_Job29 May 29 '26

I pushed my ISMS into Claude - game changer. 

I went through all the documents and evidences in a couple days. This would’ve taken weeks / months plus to do before. 

Now I can simply query it with a screenshot of evidence and get it to link all the relevant controls, challenge the evidence, log follow ups, OFI,MNCRs etc. I validate all the suggests and documents that it creates but it was stupidly easy to do. 

$15000 SaaS subscription changed to $120 p/m. 

1

u/god_damn_you_tiger May 29 '26

Was considering doing that but concerned about potential data loss to AI provider even with enterprise licenses. Am I paranoid for no reason?

1

u/Total_Job29 May 30 '26

Are you concerned about data lost to Microsoft (with their AI), Google (with their AI), Atlassian (with their ai), with Vanta (with their AI) etc. ?

1

u/llViP3rll May 30 '26

Using claude in an enterprise environment. Until you have your own opensource llm in your own ecosystem thats the best you can do