ISO/IEC 27001:2022

Intelligent Information Security Management.

ISO 27001 is the initial framework supported by PRATIMUS. The platform is designed to support the full management-system lifecycle, not only the documentation produced for an audit.

01

ISMS scope and organisational context

Define what the management system covers: business units, systems, locations and interested parties, together with the internal and external issues that shape security objectives.

AI-assisted drafting of scope statements from structured organisational information.

02

Asset inventory

Maintain a living register of information assets, systems, suppliers and processes, each with an accountable owner.

Ownership gaps and stale records are surfaced automatically for review.

03

Risk assessment and treatment

Identify risks in their organisational context, evaluate likelihood and impact, and record treatment decisions with clear accountability.

Draft risk analyses and treatment options prepared for human review and approval.

04

Statement of Applicability

Determine which Annex A controls apply, document justification for inclusion and exclusion, and keep the SoA aligned with the risk register.

Inconsistencies between risks, controls and the SoA are flagged continuously.

05

Policies and procedures

Author, approve, version and distribute the policy set that governs security behaviour across the organisation.

Drafting support and review reminders aligned to the approval workflow.

06

Control implementation

Track implementation status, responsible owners and operating effectiveness for each applicable control.

Control status monitored continuously rather than reviewed only before an audit.

07

Evidence management

Collect, store and refresh the evidence that demonstrates controls are operating, with clear provenance and review dates.

Expiring evidence is identified and assigned before it becomes an audit finding.

08

Internal audit

Plan audits, record findings, agree corrective actions and follow them through to closure.

Audit preparation packs assembled from existing ISMS records.

09

Management review

Give leadership a structured, understandable view of security posture, risks, incidents and improvement progress.

Management reporting drafted from live ISMS data.

10

Continuous improvement

Treat nonconformities, incidents and observations as inputs to an ongoing improvement cycle rather than annual remediation.

Improvement actions tracked with outcomes and evidence of effectiveness.

In the product

From implementation to continuous operation.

The ISMS workspace connects scope, assets, risks, controls, evidence and audits in one place, so the management system reflects the organisation as it is today.

Pratimus ISMS — demonstration data

Security posture

ISMS scope: corporate IT and cloud services

AI CSO active

Controls implemented

78 / 93

Statement of Applicability

Open risks

14

3 above tolerance

Evidence current

86%

Reviewed this quarter

Open actions

9

2 overdue

Risk heatmap

Low impactHigh impact

Open actions

  • Review supplier access rights

    A-114 · IT Operations

    12 Oct
  • Update backup restoration evidence

    A-121 · Infrastructure

    18 Oct
  • Close finding from internal audit

    A-127 · ISMS Manager

    24 Oct

Audit trail

  • Risk R-042 treatment plan recommended by AI CSO — awaiting approval
  • Control A.8.12 evidence uploaded by Infrastructure
  • Access review completed for finance systems

Interface preview of the PRATIMUS ISMS. Demonstration data only.

Zero Trust alignment

Annex A access-control requirements map naturally to Zero Trust: identity-based access, least privilege and logged activity. PRATIMUS applies these principles to the ISMS itself, so the records that prove your security are protected the same way.

Other frameworks

Support for NIS2 and additional frameworks is a developing capability. It is not presented as currently verified functionality.

Certification

PRATIMUS does not issue certification and does not replace an independent auditor. ISO 27001 certification is assessed and awarded by an appropriate certification body.

The future of cybersecurity management starts here.

Discover how PRATIMUS can help your organisation implement and operate an intelligent Information Security Management System.