Skip to content

ISO 27001:2022 ISMS Integrated Management Toolkit All‑in‑One SoA, Risk, KPI, Audit & Dashboard

$289.95

This ISO 27001:2022 ISMS Integrated Management Tool v2 is a mid‑priced, feature‑rich Excel toolkit positioned well below most full documentation suites and ISMS software subscriptions, while offering more operational depth than typical “document-only” toolkits.

SKU: GS00088ISMS Category:

ISO 27001:2022 ISMS Integrated Management Toolkit

Turn ISO 27001 From Paper Exercise into a Live, Measurable ISMS

The ISO 27001:2022 ISMS Integrated Management Toolkit v2 is a single, formula‑driven Excel workbook that lets you design, operate, monitor and improve your ISMS in one place without buying expensive ISMS software or drowning in disconnected spreadsheets.

You get a complete Statement of Applicability for all 93 Annex A controls, a risk register with a 5×5 matrix, KPI/incident tracking with MTTD and MTTR, document control, context and interested‑party analysis, security awareness metrics, vulnerability and policy‑violation tracking, asset inventory, internal audit planning and GRC/financial KPIs all feeding a real‑time executive dashboard.

If you want to move beyond “template completion” and into genuine information security governance, this toolkit is built for you.

Who This Toolkit Is For

This toolkit is designed for organisations that:

  • Are implementing or upgrading to ISO/IEC 27001:2022, including Annex A re‑structure and climate‑change requirements from Amendment 1:2024.

  • Need an evidence‑rich, metrics‑driven ISMS without committing to a high‑cost SaaS ISMS platform.

  • Want to demonstrate performance, risk and control effectiveness to executives, boards, auditors and regulators via clear, defensible data.

  • Prefer Excel as a flexible, transparent environment where formulae, logic and data flows can be inspected and validated.

Typical users include:

  • CISOs and Information Security Managers who want one operating workbook to run their ISMS.

  • Risk and Compliance Managers who must link risk, controls, incidents, documents and audits coherently.

  • IT Directors responsible for showing cyber resilience and control coverage to boards and regulators.

  • ISO 27001 consultants seeking a ready‑to‑use, standards‑aligned operating tool that can be deployed repeatedly across clients.

What You Get: A Fully Integrated ISMS Operating Workbook

This is more than a bundle of templates.
You receive a structured, 15‑sheet Excel workbook where each major ISO 27001 process connects into a live, auto‑updating dashboard.

1. Statement of Applicability: All 93 Annex A Controls

  • Four SoA sheets covering:

      1. Organisational controls (37)

      1. People controls (8)

      1. Physical controls (14)

      1. Technological controls (34)

  • For each control, fields for:

    • Applicability decision (Applicable / Not Applicable / Not Assessed)

    • Justification and exclusion reasons

    • Control attributes and types (preventive, detective, corrective, directive)

    • Information security properties, cybersecurity concept and security domain

    • Approval details and communication method

  • A summary showing control counts, applicability and assessment status, which feeds directly into the dashboard’s SoA completion tiles.

Result: You can show auditors and executives, with a few clicks, which controls apply, why, and how they are governed with a numeric completion percentage.

2. Risk Register With 5×5 Matrix and Control Traceability

  • Structured risk register aligned to ISO 27001:2022 risk assessment and treatment.

  • Automated calculations:

    • Risk Score = Consequence × Likelihood on a 1–25 scale.

    • Initial Rating via a 5×5 risk matrix (L/M/S/H/E).

    • Residual Rating after treatment, showing improvement.

  • Treatment strategy options:

    • Treat (mitigate)

    • Tolerate (accept)

    • Transfer (insure/outsource)

    • Terminate (avoid)

  • Annex A control linkage:

    • Each risk can be mapped to one or more Annex A controls.

    • These mappings feed a risk‑to‑control traceability view on the dashboard.

Result: You move away from “static” risk lists and towards a living risk profile, explicitly mapped to controls exactly what auditors look for in a mature ISMS.

3. KPI & Incident Register (MTTD and MTTR in Hours)

  • Incident log for security events and incidents across the ISMS.

  • Automatic calculation in hours for:

    • Mean Time to Detect (MTTD)

    • Mean Time to Respond (MTTR)

  • Built‑in performance targets:

    • Critical systems: MTTD < 24 hours.

    • P1 incidents: MTTR < 4 hours; graduated targets for lower severities.

  • Domain tagging:

    • Incidents linked to Annex A controls via control reference (e.g. 5.7, 8.16).

    • Dashboard uses the leading digit to categorise by domain (Organisational, People, Physical, Technological).

Result: You can demonstrate not only that you handle incidents, but how quickly you detect and respond, and where issues originate in the control framework.

4. Document Control, Automated Status and Overdue Tracking

  • Document control sheet pre‑loaded with a core ISMS document set.

  • Key fields:

    • Document owner, version, review frequency (annual, 6‑monthly, quarterly).

    • Last revised date and automatically calculated next review due date.

  • Automation:

    • “Days Overdue” auto‑calculates based on today’s date.

    • Status is fully formula‑driven: Cancelled > Overdue > Due for Review (within 30 days) > Current > Not Set.

    • Cancelled flag overrides other conditions.

Result: You can instantly see which ISMS documents are current, which are coming due, and which are overdue and you can evidence document control to auditors with objective data.

5. Context, PESTLE, SWOT and Interested Parties (Clause 4.1 & 4.2)

  • Context register tailored to ISO 27001:2022 Clause 4 and Amendment 1:2024 (climate change).

  • PESTLE analysis for external issues:

    • Political, Economic, Social, Technological, Legal and Environmental factors.

    • Each factor rated as opportunity or threat with priority.

  • Internal issues analysis (culture, technology, resources, governance, capabilities).

  • SWOT strategic summary:

    • Strengths, weaknesses, opportunities and threats at ISMS level.

  • Interested‑party register:

    • Requirements, compliance obligations and climate‑change related requirements.

    • How the ISMS addresses each stakeholder’s needs.

Result: Your ISMS context is clearly documented, quantified and linked to obligations, enabling a robust foundation for risk assessment and governance.

6. Security Awareness and Phishing Metrics

  • Training register for security awareness activities:

    • Participants, completion dates, status and due dates.

  • Phishing simulation tracking:

    • Who clicked, who reported, and the overall click and report rates.

  • Dashboard metrics:

    • Training completion percentage.

    • Phishing click and report rates against defined targets.

Result: You can demonstrate competence and awareness (Clause 7) numerically, not just by showing a training slide deck.

7. Vulnerability Register and Patch Management KPIs

  • Vulnerability register capturing:

    • CVE/identifier, severity, dates (discovered, patch released, patch applied).

    • Affected assets and ownership.

  • Automatic KPIs:

    • Patch latency (time between patch release and application).

    • Remediation rate and backlog indicators (e.g. vulnerabilities > 30 days open).

  • Dashboard outputs:

    • Average patch latency.

    • Remediation percentage and critical open vulnerabilities.

Result: You can quantify your technical vulnerability management, an area often scrutinised by auditors, regulators and cyber insurers.

8. Policy Violations and Shadow IT

  • Policy violation log:

    • Type of violation, date, severity, recurrence, corrective actions.

  • Shadow IT tracking:

    • Records of unapproved tools and services discovered.

  • Dashboard summary:

    • Open violations, shadow IT instances, and recurrence indicators.

Result: You can evidence how you handle non‑compliance and informal practices, supporting both ISO 27001 and broader compliance programmes.

9. Asset Inventory and Coverage Metrics

  • Asset inventory for information and associated assets:

    • Business owner, classification, location, and type.

  • Coverage flags:

    • Endpoint protection/EDR, AV, vulnerability scanning, logging, backup, etc.

    • Internet‑facing and third‑party asset indicators.

  • Dashboard outputs:

    • Asset coverage percentage.

    • Count of uncovered high‑risk assets.

    • Number of internet‑facing assets and third‑party assets.

Result: You can demonstrate that assets are identified, classified and appropriately protected – a core requirement of Annex A.

10. Financial and Strategic GRC KPIs

  • Financial and strategic KPI sheet capturing:

    • Incident cost data (direct and indirect).

    • Budget allocation and spend.

    • Cyber insurance utilisation.

    • Board engagement metrics (e.g. frequency of cyber topics on agendas).

    • ISMS and cyber maturity scores, aligned to a 1–5 scale.

  • Derived KPIs:

    • Cost per incident.

    • Budget utilisation.

    • Return on Security Investment (ROSI).

    • Average maturity score and board engagement rate.

Result: You can speak the language of executives and boards: cost, benefit, maturity and governance – not just controls and policies.

11. Internal Audit Programme and Findings Management

  • Internal audit sheet structured to:

    • Define an ISO 27001 audit programme.

    • Plan individual audits by clause or control.

    • Record findings (major NC, minor NC, observation) and corrective actions.

  • Dashboard metrics:

    • Number of audits planned.

    • Findings by type.

    • Corrective‑action closure rate and overdue corrective actions.

Result: You can plan, execute and track internal audits systematically, with clear evidence for certification bodies and management reviews.

12. Real‑Time Executive Dashboard (No Manual Data Entry)

  • Single dashboard sheet pulling live data from all other sheets.

  • Nine sections presenting:

    • SoA coverage and audit readiness.

    • Risk profile and treatment strategies.

    • Incident metrics and domain breakdown.

    • Document status and overdue reviews.

    • Training and phishing performance.

    • Vulnerabilities, asset coverage and policy violations.

    • Internal audit performance.

    • GRC and strategic KPIs versus targets.

  • Status indicators and simple visual cues:

    • Completion percentages.

    • “On target” versus “below target” markers.

    • Audit‑readiness indicator for SoA.

Result: At any moment, you have a consolidated picture of ISMS health, ready for management review, board reporting or audit.

How It Aligns with ISO 27001:2022

The toolkit is explicitly mapped to:

  • Clause 4 Context of the organisation (context register, PESTLE, SWOT, interested parties).

  • Clause 5 Leadership (SoA with management approval, dashboard for leadership metrics).

  • Clause 6 Planning (risk register and SoA supporting risk treatment planning).

  • Clause 7 Support (document control, awareness and competence metrics).

  • Clause 8 Operation (SoA, risk, incidents, vulnerabilities, asset inventory).

  • Clause 9 Performance evaluation (KPI register, dashboard, internal audit).

  • Clause 10 Improvement (risk and incident trends, audit findings and corrective actions).

It also fully covers the 93 Annex A controls in their 2022 structure and incorporates climate‑change considerations introduced in Amendment 1:2024 through the context and interested‑parties register.

Why Choose This Toolkit Instead of Alternatives

Compared With Traditional Document‑Only Toolkits
  • Those toolkits:

    • Focus primarily on Word document templates.

    • Often provide basic registers with limited automation or dashboards.

  • This toolkit:

    • Focuses on operating the ISMS via metrics, automation and a unified dashboard.

    • Still supports documentation governance via document control and SoA approval fields.

    • Gives you an audit‑ready, data‑driven view rather than a stack of unconnected files.

Compared With ISMS SaaS Platforms

  • SaaS platforms:

    • Are powerful but often cost from tens of thousands per year.

    • Require integration projects, user onboarding and vendor management.

  • This toolkit:

    • Uses Excel, which your team already understands.

    • Has no subscription cost or lock‑in.

    • Provides transparency: every formula and linkage can be reviewed, validated and adapted.

Compared With Building Your Own Spreadsheets

  • Building in‑house:

    • Consumes significant time from security, risk and IT staff.

    • Often yields inconsistent structures across teams and projects.

  • This toolkit:

    • Gives you a pre‑engineered structure aligned with the latest standard.

    • Can be customised, but you start from a mature, integrated model.

What Happens After You Get It

Once you have the workbook, you can:

  1. Tailor the context.

    • Populate your PESTLE, SWOT, internal issues and interested parties.

  2. Refine the SoA.

    • Decide on applicability and justifications for all 93 controls.

  3. Load your current state.

    • Enter existing risks, incidents, documents, assets, vulnerabilities, audits and training records.

  4. Start monitoring.

    • Use the dashboard for management review, board packs and audit preparation.

  5. Iterate and improve.

    • Track KPIs, adjust controls, close risks and findings, and show continual improvement over time.

6. Use it with Power BI and receive live updated reporting.

 

Exclusive products