FAQs
The ISOManager ISMS Assurance Solution offered in the ISO Manager platform is an all-in-one compliance command center, designed specifically to manage your ISMS Assurance requirements and all applicable GRC compliance requirements (legal / regulatory and contractual). It fully supports all of the requirements of ISO 27001, PCI-DSS, CPS234, NIST, COBIT and more. The platform is also extensible to enable additional compliance frameworks (and mappings) to be easily added.
The ISMS Assurance Solution is built upon ISO Manager which frames the ISO 27001:2015 framework and domain controls. The solution can be delivered as an on-premise or private cloud (SaaS) solution (dedicated servers in Australian DCs), covering the entire lifecycle of compliance within entities and services.
Additional modules for Australian government GRC requirements are being added all the time. Development on the product is extremely active.
The solution is highly scalable through a modular design to address capacity demands and any future needs of the organisation. It can be rapidly implemented, enabling growth and scalability.
# | Requirement | Yes/No | Comment |
1 | The solution must have the ability to assign information security | Yes | Please see Technical Requirements and FAQs for a detailed walkthrough of this requirement. |
2 | The solution must have the ability to allow a user to risk | Yes | As above |
3 | The solution must have the ability to allow a user to add | Yes | As above |
4 | The solution must have the ability to allow users to assign | Yes | As above |
5 | The solution must include the ability for a user to record | Yes | As above |
6 | The solution must include the ability for a user able to | Yes | As above |
7 | The solution should have a business | Yes | As above |
8 | The solution should contain a threat catalogue that can be | Yes | As above |
9 | The solution should include the ability for users to create | Yes | As above |
10 | The solution should have the ability for information asset | Yes | The ISO Manager Task module allows for the creation of and tracking of tasks. Tasks
|
11 | The solution should include an information security | Partial | A range of forms and workflows can be provided. However, embedding this option within ISO Manager implementation can be customized and developed during implementation according to a detailed requirement’s exercise.
|
12 | The solution should enable a user to undertake high-level | Yes | Risk assessments can be completed, recorded and actioned according to the ISO 27005 Framework As above
|
13 | The solution should have the ability for users to track the | Yes |
Users can track implementations against all mapped standards (ISO27001 and more). |
14 | The solution should have the ability for users to track the | Yes |
A range of dashboards and reporting options are available to show progress against the mapped standards. |
15 | The solution should have the ability for users to record | Yes |
While ISO Manager is not designed to replace a comprehensive CMDB (Such as ServiceNow / Cherwell Asset Manager), it does provide the required Asset Views to satisfy ISO27001 and similar standards. The Asset Views can also be linked to a |
16 | The solution should include a cyber supply chain management Background: Cyber supply chain risk management can be undertaken | Partial | ISO Manager can offer document upload and approval through DMS and SLA/OLA This option may be customized and developed during implementation according to detailed requirement, and it will be offered as optional customization as per ISO 27036 Information security
|
17 | The solution should have the ability for users to create an | Yes | The solution allows users to customise and send security questionnaires to suppliers. This option can be further customized and developed during implementation according to detailed requirements gathering
|
18 | The solution should have the ability for users to | Yes | Supplier assessments can be reported on and tracked to ensure supplier meet their contractual security obligations. This option can be customized and developed during implementation according to detailed requirement
|
19 | The solution should support the ability to create different | Yes |
An asset heirarchy can be established – However, ISOManager is an ISMS Management tool rather than a CMDB.
|
20 | The solution should enable a user to set a flag to identify | Yes |
PII / PCI flags can be established for all assets / systems as required. |
21 | The solution should enable a user to set a flag to identify | Yes | PII / PCI flags can be established for all assets / systems as required. |
22 | The solution should include workflow functionality that | Yes | This option can be further customized and developed during implementation according to detailed requirement
|
23 | The solution should include a document register that tracks | Yes | |
24 | The solution should include a generic risk bank that | Yes |
The solution includes a retailed risk library to assist with assessments. |
25 | The solution should include an Information Security Incident | Yes | A range of templates can also be provided / constructed to assist with IR plan |
26 | The solution should support the ability to email a person | Yes | ISO 1. 2. 3. 4. 5. 6. Further |
27 | The solution should include a workflow that enables | Yes |
Actual workflow will be customized during
|
28 | The solution should have the ability to create architectural | Partial | ISO Manager does not have an integrated network discovery tool – So cannot produce a network architecture or visual heirarchy. However, it does support the following architectural asset review /reporting options: 1.Assets 2.Assets 3.Assets 4.Assets 5.Assets 6. |
29 | The information | Yes |
ISOManager allows for extensive customisation to support a wide array of standards, including
|
30 | The solution should have the ability to assign ‘Low, Medium | Yes |
|
31 | The solution should have the ability to assign ownership and | Yes |
ISO Manager provides an easy to use, detailed RTP management solution. |
32 | The solution should dynamically update a centralised | Yes |
Unlike standard risk-management platforms, ISO Manager incorporates the end-to-end |
33 | The solution should have the ability for users to | Yes |
DLMs can be fully customised. Govt |
34 | The solution should require risks contained within | Yes | Please see Technical Requirements. |
35 | ISMS Dashboarding must have the ability to display:
· Corrective action due dates, including implementation | Yes | ISO Manager supports a range of customised dashboarding options. The required dashboard format will depend on the available data. Asset overview, compliance, risk, actions, implemention reporting can be customized and developed during the implementation phase. Data will be required to ensure that dashboards are aligned with expectations.
|
36 | The solution should have an Information Security Calendar | Yes | ISO Manager integrates with Calendar (Exchange, Google, etc). Calendar Dashboard is an available option.
|
37 | The solution should have a Corrective Actions Register that | Yes |
|
38 | The solution should include the ability for a user to upload | Yes |
|
39 | The solution should log user access, modification and | Yes | ISO Manager contains detailed logging and audit-trails. Every login to system is recorded with IP address. Every add/update/delete data
|
40 | The solution should have the ability to easily export all | Yes | Common file formats (including .xlsx, .docx, .pdf) are |