Write, review, approve and publish policies through a portal, with attestation via the Awareness Portal.
ISO 27001, clause by clause, in eramba
Where each requirement lives, what you actually have to produce, and what the auditor will look at. Written by a practitioner who has certified a dozen organisations, not by a sales team.
- Flat annual fee
- Unlimited users
- Every framework included
- Community edition free
Where each clause lives
Seven clauses of the standard, the eramba modules that carry them, and what a practitioner would tell you before the audit. Open a clause for the detail.
4Context of the organisation
Internal and external issues, interested parties and the scope of the ISMS.OrganisationPolicies
Most teams write one short document for 4.1 to 4.3. Keep it where its reviews and approvals are recorded: Program Issues and Scope in the Organisation module, or a policy in the Policy module. A file on a shared drive proves nothing to an auditor.
5Leadership
An approved Information Security Policy, ISMS roles, and security objectives management can measure.PoliciesOrganisation
5.1 asks you to prove that senior management is behind the ISMS. The cheapest proof is the ISMS policy itself (5.2) carrying its review and approval history. Roles (5.3) and objectives, "Goals" in eramba lingo, live in the Organisation module, where Goals can be tested at intervals.
6Planning
Risk classification and matrix, risks with owners, four treatment options, and the Statement of Applicability.RiskOnline AssessmentsCompliance AnalysisExceptionsProjects
ISO does not care how you classify risks, as long as it is consistent, valid and comparable. The standard has not used the words "threat" or "vulnerability" for risk identification since 2005, and it never mentions "asset" at all, so a list of risks with no relation to those attributes is perfectly certifiable. Risks are found by talking to people, in the coffee corner or with an Online Assessment. eramba records what you decided and who owns it.
7Support
Competence records, one short awareness course per department, and documented information behind a Policy Portal.OrganisationAwarenessPolicies
7.2 is 5.3 with attachments: certificates and training records on the roles you already documented. For 7.3 a few slides per department are enough, what to be aware of and which controls they operate. 7.5 wants documents approved, reviewed and available, and the Policy module and its portal do all three.
8Operation
Every process you run documented as an Internal Control with a test method and evidence, and risk reviews on fixed dates.Internal ControlsRisk
"Plan, implement and control the processes" means laptop encryption, account provisioning, change management, log reviews. Each is an Internal Control that explains what you do and gets tested at intervals. 8.2 and 8.3 send you back to risk: the module forces review dates, so the reassessment cannot quietly not happen.
9Performance evaluation
Systematic control testing with dates, testers and results, internal audit findings, and management review minutes.Internal ControlsCompliance AnalysisPolicies
9.1 is the expensive clause, alongside 8.2 and 8.3: monitoring must be systematic, with who, when and results. Test your own controls through the year the way an auditor would, because when the auditor comes they will lean on your testing. That is the key piece of ISO, testing beforehand. 9.3 is a meeting with slides, and its minutes go into the Policy module.
10Improvement
Non-conformities from audits, incidents and findings tracked as Projects with owners, deadlines and tasks.Projects
An auditor favourite. When something is not met, a failed control audit, an incident, an external finding, there has to be a plan to fix it. Projects carry the owner, the deadline and the tasks, and link back to the requirement, risk or control they repair.
Nine modules, one flat fee
Every module is included in every edition. Nothing on this page is an add-on.
Issues, scope, roles and goals. The ISMS context, measurable at intervals.
Identify, classify, review and treat risks. Owners and review dates are mandatory.
The activities you run, tested at regular intervals with collected evidence.
Requirements linked to controls, policies, projects and risks. The SoA comes out of here.
Documented decisions that a requirement or risk is not treated, with owners and expiry.
What you will do in the future about a gap, with tasks and deadlines.
Videos, disclaimers and questionnaires that audiences complete on a schedule.
Spreadsheet-defined questionnaires sent to anyone. Answers land in a portal for your review.
What eramba does not do for ISO 27001
It does not collect evidence from your cloud accounts, and it will not find your risks. People do, in interviews. eramba records what you decided, tests the controls you run, and keeps the proof where an auditor expects to find it. GRC tools facilitate the work, they do not do it.
We also do not publish a percentage of ISO 27001 you "already cover" by doing another framework. Requirements that look alike rarely say the same thing.
Read why in "The disjointed world of mappings"From download to first audit
Import the ISO 27001:2022 package
All requirements as a CSV, ready to assign, track and report on. Annex A ships as the ISO 27002:2022 package.
Download the packageFollow the clause map
Work through the seven clauses above. The 22-minute Compliance Management course covers the mechanics.
Start the course
Before you ask sales
Does eramba make us ISO 27001 compliant?
No tool does. eramba organises the requirements, the risks, the controls and the evidence, and shows you what is expired or failed before the auditor does. The work is still yours.
Is Annex A included?
Yes. Annex A controls are the ISO 27002:2022 package. Link risks to each control and generate the Statement of Applicability from Compliance Analysis. Exclusions are recorded as Compliance Exceptions with an owner and a reason.
Do we pay per framework?
No. Enterprise is a flat annual fee with unlimited users and every module. The 70+ compliance packages are included and you can upload any framework as a CSV.
Can our auditor log in?
Yes. Give auditors a read-only account scoped to what they need to see. There is a guide on the forum for exactly that setup.
Same method, different clauses
ISO 27002, Annex A
The 93 controls, and how the SoA is produced.
Open the guideGuide and packageNIS2, Article 21
Ten measures most companies already do and cannot prove.
Open the guideGuide and packageDORA
ICT risk, incidents, testing and third parties for financial entities.
Open the guideGuideGDPR
Records of processing, data flows and the controls around them.
Open the guideTry it before you talk to anyone
Import the ISO 27001 package into the free Community edition and see how it works with your own requirements. No sales sequence.
- 39,030 downloads last year
- 641 enterprise users
- 11 releases last year
- Used for ISO, PCI and SOC 2 since 2015
Pricing
Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.
Community
Free
Self-hosted. No user limit, no time limit.
DownloadEnterprise on-premises
from 2500€/year
Runs on your infrastructure, with support and updates.
See pricingEnterprise SaaS
from 5000€/year
Hosted and operated by eramba, in the EU.
See pricingContact us
A practitioner answers, not a sales sequence.