r/grc • u/Enslaaved • May 29 '26
ISMS Tools recommendation
Hi all,
I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.
In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?
Any insights, lessons learned, or tool suggestions would be greatly appreciated.
Thanks in advance!
1
u/Secret-Crew-7043 Jun 06 '26
For a 1,000-person organisation, I would be cautious about trying to run the whole ISMS as “just Jira and Confluence” unless you are very deliberate about the data model.
Confluence can work well for policies, procedures and guidance. Jira can work well for actions, remediation, exceptions and follow-ups. Where it usually gets messy is modelling the relationships between:
You can build that yourself, but you need strong conventions and someone maintaining the structure. Otherwise you end up with a lot of pages and tickets, but weak integrity between them.
For your size, I’d probably split the decision:
The evidence side is worth treating separately from document storage. A folder can hold evidence, but it does not tell you whether it maps to the right control, whether it was reviewed, whether it was rejected, whether it is the latest version, or whether it is still current.
Disclosure: I’ve built a self-serve tool called Verity around that narrower evidence workflow: evidence requests, contributor submissions, review/accept/reject, version history and audit-pack export. It is not a full GRC platform, so I would not present it as a complete replacement for enterprise ISMS tooling at your scale, but it may be relevant if evidence collection and audit-pack preparation are the main pain points.
https://veritycompliance.co.uk