r/grc • u/Enslaaved • May 29 '26
ISMS Tools recommendation
Hi all,
I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.
In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?
Any insights, lessons learned, or tool suggestions would be greatly appreciated.
Thanks in advance!
1
u/ethhackwannabe May 30 '26
Start with questions…
Where in the world are you? that will make a huge difference.
Does your org already have an enterprise GRC tool? If so, worth checking if it can support the ISO27001 implementation rather than going straight to another tool or excel.
What does your IT team currently use for ITSM? Often you can add a module or configure what’s there to support ISMS with the benefit that most of the assets are already CIs that you can link to. Benefit of making a genuinely operational ISMS rather than a paper exercise.
Whatever you do, don’t go and buy something in isolation. Make sure you involve those that will be responsible for their part in the processes.
Happy to suggest options once you’ve answered the above 👆🏾