Free online trainings
24
Sep
Eramba Detailed Risk & Compliance Advanced
ISO/IEC 27001:2022 - framework guide

ISO 27001, clause by clause, in eramba

Where each requirement lives, what you actually have to produce, and what the auditor will look at. Written by a practitioner who has certified a dozen organisations, not by a sales team.

  • Flat annual fee
  • Unlimited users
  • Every framework included
  • Community edition free
ISO 27001 clauseseramba modules4Context5Leadership6Planning7Support8Operation9Performance10ImprovementOrganisationPoliciesRiskOnline AssessmentsInternal ControlsCompliance AnalysisExceptionsProjectsAwareness

Where each clause lives

Seven clauses of the standard, the eramba modules that carry them, and what a practitioner would tell you before the audit. Open a clause for the detail.

4

Context of the organisation

Internal and external issues, interested parties and the scope of the ISMS.OrganisationPolicies
Most teams write one short document for 4.1 to 4.3. Keep it where its reviews and approvals are recorded: Program Issues and Scope in the Organisation module, or a policy in the Policy module. A file on a shared drive proves nothing to an auditor.
From the guide "eramba & ISO 27001 (2022)"
5

Leadership

An approved Information Security Policy, ISMS roles, and security objectives management can measure.PoliciesOrganisation
5.1 asks you to prove that senior management is behind the ISMS. The cheapest proof is the ISMS policy itself (5.2) carrying its review and approval history. Roles (5.3) and objectives, "Goals" in eramba lingo, live in the Organisation module, where Goals can be tested at intervals.
From the guide "eramba & ISO 27001 (2022)"
6

Planning

Risk classification and matrix, risks with owners, four treatment options, and the Statement of Applicability.RiskOnline AssessmentsCompliance AnalysisExceptionsProjects
ISO does not care how you classify risks, as long as it is consistent, valid and comparable. The standard has not used the words "threat" or "vulnerability" for risk identification since 2005, and it never mentions "asset" at all, so a list of risks with no relation to those attributes is perfectly certifiable. Risks are found by talking to people, in the coffee corner or with an Online Assessment. eramba records what you decided and who owns it.
From the guide "eramba & ISO 27001 (2022)"
eramba risk register showing classification, score and treatment for each risk
6.1.2 - Risk module: likelihood, impact, score and treatment.
eramba Compliance Analysis with ISO 27001:2022 items linked to internal controls and policies
6.1.3 - Statement of Applicability from Compliance Analysis. Exclusions are Compliance Exceptions.
7

Support

Competence records, one short awareness course per department, and documented information behind a Policy Portal.OrganisationAwarenessPolicies
7.2 is 5.3 with attachments: certificates and training records on the roles you already documented. For 7.3 a few slides per department are enough, what to be aware of and which controls they operate. 7.5 wants documents approved, reviewed and available, and the Policy module and its portal do all three.
From the guide "eramba & ISO 27001 (2022)"
8

Operation

Every process you run documented as an Internal Control with a test method and evidence, and risk reviews on fixed dates.Internal ControlsRisk
"Plan, implement and control the processes" means laptop encryption, account provisioning, change management, log reviews. Each is an Internal Control that explains what you do and gets tested at intervals. 8.2 and 8.3 send you back to risk: the module forces review dates, so the reassessment cannot quietly not happen.
From the guide "eramba & ISO 27001 (2022)"
9

Performance evaluation

Systematic control testing with dates, testers and results, internal audit findings, and management review minutes.Internal ControlsCompliance AnalysisPolicies
9.1 is the expensive clause, alongside 8.2 and 8.3: monitoring must be systematic, with who, when and results. Test your own controls through the year the way an auditor would, because when the auditor comes they will lean on your testing. That is the key piece of ISO, testing beforehand. 9.3 is a meeting with slides, and its minutes go into the Policy module.
From the guide "eramba & ISO 27001 (2022)"
eramba report showing the percentage of compliance items with issues over time
9.1 - Dynamic status over time: expired reviews and failed audits per requirement, before the auditor asks.
10

Improvement

Non-conformities from audits, incidents and findings tracked as Projects with owners, deadlines and tasks.Projects
An auditor favourite. When something is not met, a failed control audit, an incident, an external finding, there has to be a plan to fix it. Projects carry the owner, the deadline and the tasks, and link back to the requirement, risk or control they repair.
From the guide "eramba & ISO 27001 (2022)"

Nine modules, one flat fee

Every module is included in every edition. Nothing on this page is an add-on.

Policies

Write, review, approve and publish policies through a portal, with attestation via the Awareness Portal.

Organisation

Issues, scope, roles and goals. The ISMS context, measurable at intervals.

Risk

Identify, classify, review and treat risks. Owners and review dates are mandatory.

Internal Controls

The activities you run, tested at regular intervals with collected evidence.

Compliance Analysis

Requirements linked to controls, policies, projects and risks. The SoA comes out of here.

Exceptions

Documented decisions that a requirement or risk is not treated, with owners and expiry.

Projects

What you will do in the future about a gap, with tasks and deadlines.

Awareness

Videos, disclaimers and questionnaires that audiences complete on a schedule.

Online Assessments

Spreadsheet-defined questionnaires sent to anyone. Answers land in a portal for your review.

What eramba does not do for ISO 27001

It does not collect evidence from your cloud accounts, and it will not find your risks. People do, in interviews. eramba records what you decided, tests the controls you run, and keeps the proof where an auditor expects to find it. GRC tools facilitate the work, they do not do it.

We also do not publish a percentage of ISO 27001 you "already cover" by doing another framework. Requirements that look alike rarely say the same thing.

Read why in "The disjointed world of mappings"

From download to first audit

  1. Download the Community edition

    Free, self-hosted, no user limit and no time limit.

    Get Community
  2. Import the ISO 27001:2022 package

    All requirements as a CSV, ready to assign, track and report on. Annex A ships as the ISO 27002:2022 package.

    Download the package
  3. Follow the clause map

    Work through the seven clauses above. The 22-minute Compliance Management course covers the mechanics.

    Start the course

Before you ask sales

Does eramba make us ISO 27001 compliant?

No tool does. eramba organises the requirements, the risks, the controls and the evidence, and shows you what is expired or failed before the auditor does. The work is still yours.

Is Annex A included?

Yes. Annex A controls are the ISO 27002:2022 package. Link risks to each control and generate the Statement of Applicability from Compliance Analysis. Exclusions are recorded as Compliance Exceptions with an owner and a reason.

Do we pay per framework?

No. Enterprise is a flat annual fee with unlimited users and every module. The 70+ compliance packages are included and you can upload any framework as a CSV.

Can our auditor log in?

Yes. Give auditors a read-only account scoped to what they need to see. There is a guide on the forum for exactly that setup.

Try it before you talk to anyone

Import the ISO 27001 package into the free Community edition and see how it works with your own requirements. No sales sequence.

  • 39,030 downloads last year
  • 641 enterprise users
  • 11 releases last year
  • Used for ISO, PCI and SOC 2 since 2015

Pricing

Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.

Community

Free

Self-hosted. No user limit, no time limit.

Download

Enterprise on-premises

from 2500€/year

Runs on your infrastructure, with support and updates.

See pricing

Enterprise SaaS

from 5000€/year

Hosted and operated by eramba, in the EU.

See pricing

Contact us

A practitioner answers, not a sales sequence.