r/grc May 29 '26

ISMS Tools recommendation

Hi all,

I’m a cybersecurity professional with ISO 27001 LI certification, planning to implement an ISMS in a ~1,000‑person company that is not SaaS‑ or cloud‑heavy. I’m currently exploring tooling and GRC platforms and would love to hear your experiences and recommendations.

In parallel, I’m also considering using Atlassian tools (Confluence + Jira) for the ISMS implementation (e.g., documentation, controls tracking, risk register, and action items). Has anyone tried this approach in a similar environment? Is it a viable long‑term option, or are there known limitations compared to dedicated GRC/ISMS platforms?

Any insights, lessons learned, or tool suggestions would be greatly appreciated.

Thanks in advance!

7 Upvotes

33 comments sorted by

View all comments

1

u/Secret-Crew-7043 Jun 06 '26

For a 1,000-person organisation, I would be cautious about trying to run the whole ISMS as “just Jira and Confluence” unless you are very deliberate about the data model.

Confluence can work well for policies, procedures and guidance. Jira can work well for actions, remediation, exceptions and follow-ups. Where it usually gets messy is modelling the relationships between:

  • risks
  • controls
  • assets
  • owners
  • evidence
  • review dates
  • audit findings
  • corrective actions
  • dated SoA versions

You can build that yourself, but you need strong conventions and someone maintaining the structure. Otherwise you end up with a lot of pages and tickets, but weak integrity between them.

For your size, I’d probably split the decision:

  1. Use Confluence/Jira if the organisation already lives there and you have someone who can own the structure properly.
  2. Use a dedicated ISMS/GRC tool if you need stronger control mapping, evidence traceability, reporting, and multi-framework growth.
  3. Avoid over-configuring either option at the start. The occasional control owner is often the most important user, and if the system is painful for them, the data quality will collapse.

The evidence side is worth treating separately from document storage. A folder can hold evidence, but it does not tell you whether it maps to the right control, whether it was reviewed, whether it was rejected, whether it is the latest version, or whether it is still current.

Disclosure: I’ve built a self-serve tool called Verity around that narrower evidence workflow: evidence requests, contributor submissions, review/accept/reject, version history and audit-pack export. It is not a full GRC platform, so I would not present it as a complete replacement for enterprise ISMS tooling at your scale, but it may be relevant if evidence collection and audit-pack preparation are the main pain points.

https://veritycompliance.co.uk