Noru

ISO 27001 software: what to look for

Why tools that focus on Annex A miss the part of the standard auditors actually test.

ISO 27001 software should support the management system, not just the control checklist. The mandatory clauses are 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement — and the Annex A controls exist only because a risk assessment called for them. That ordering is what auditors test, and it is where tooling most often disappoints: a product that presents Annex A as a checklist without connecting each control to the risk it treats produces a Statement of Applicability nobody can defend. Evaluate on risk assessment, the Statement of Applicability, internal audit and management review before you look at control libraries.

What to look for

Does it support clauses 4 to 10, or only Annex A?

Leadership involvement, planning, competence, performance evaluation and improvement are all audited. A tool that models only the control set leaves you assembling the mandatory management system records by hand, which is the part most first-time certifications stumble on.

Does risk drive control selection?

Ask whether each selected control links back to the assessed risk that motivated it. If the tool starts from a pre-ticked Annex A list, the resulting Statement of Applicability will not survive an auditor asking why a control is there.

How is the Statement of Applicability produced?

It is a mandatory output and one of the first documents an auditor reads. It should be generated from the risk assessment and control decisions rather than maintained as a separate spreadsheet that drifts from both.

Does it carry internal audit and management review?

Both are mandatory, both are recurring, and both need records. Check the tool schedules them, captures findings and nonconformities, tracks corrective action to closure, and retains the evidence for surveillance audits.

Does evidence accumulate on its own?

The expensive part of ISO 27001 is not the first certificate but proving each year that controls kept operating. Look for evidence collected automatically from connected systems, timestamped and retained, rather than gathered in a scramble before each audit.

The kinds of tool on the market

Four shapes of vendor, described by category rather than by name. Which one fits depends on how fast your systems change and how much judgement you need to buy in.

Broad enterprise suites

Large, modular GRC platforms that cover most regimes through separately licensed modules, usually with a long implementation and a dedicated administrator.

Best fit: Large organisations with a compliance team big enough to own configuration, and budget that tolerates a multi-module licence.

Point tools

Focused products that do one job well — consent, DSAR intake, cookie scanning, vendor questionnaires — and integrate loosely with whatever else you run.

Best fit: Teams with one acute, well-bounded problem, who accept that the register tying everything together lives somewhere else.

Consultancies and managed services

People rather than software: an external DPO or advisory retainer that produces the documentation on your behalf, often in documents you then own.

Best fit: Organisations without in-house expertise who need judgement more than tooling, and who can accept that the output is a snapshot.

Compliance operations platforms

Systems that connect to what you already run, derive the records from live signals, and keep them current between audits rather than regenerating them before one.

Best fit: Teams whose systems change faster than documents can be maintained by hand, and who need to evidence a current state on demand.

Where Noru fits

Noru models the ISMS clauses alongside the controls, so risk assessment, Statement of Applicability, internal audit and management review are part of the same system rather than documents kept beside it.

Controls map once across ISO 27001, SOC 2, NIS2 and the rest, so evidence collected for one standard counts toward every other framework that asks the same question.

Evidence accumulates continuously from connected cloud, identity, code and device systems, which is what turns surveillance audits into a review rather than a project.

FAQ

Common questions

Talk to us

What should ISO 27001 software cover?

The mandatory management system clauses 4 to 10, the risk assessment and treatment process, control selection and the Statement of Applicability, policy and competence records, internal audit, management review, corrective action, and the evidence that controls operate.

Is a Statement of Applicability mandatory?

Yes. It records which Annex A controls you have applied, which you have excluded and the justification for each, linked to your risk assessment. It is one of the first documents an auditor examines.

Do we have to implement every Annex A control?

No. Annex A is a reference set. You select controls that treat the risks your assessment identified and justify exclusions. Implementing controls that address no identified risk adds cost without adding assurance.

How long is an ISO 27001 certificate valid?

Three years, subject to annual surveillance audits, with a full recertification audit at the end of the cycle. Certification can be suspended or withdrawn if surveillance finds the management system is not being maintained.

Can software get us certified?

No. Certification comes from an accredited certification body after a two-stage audit. Software reduces the cost of building the ISMS and of proving, year after year, that it is still running — but the audit is performed by people independent of anyone who built it.

See Noru against your own systems

A 45-minute walkthrough against your frameworks, your integrations and your evidence.