Eleven documents that make up a real Information Security Management System — gap assessment, risk register, all 93 Annex A controls, audit tracking, and more — as an interactive web app, plain Markdown, or downloadable Excel and Word files. Everything runs in your browser. Nothing is uploaded anywhere.
Plan, Do, Check, Act — the same structure ISO/IEC 27001 itself is built on. Work through them roughly in order the first time; every later document builds on the ones before it.
A quick maturity self-check across every clause and Annex A theme.
Scope, context, leadership commitment, roles, objectives.
4×4 likelihood × impact matrix, treatment decisions, residual risk.
The systems and data your risks and controls actually refer to.
All 93 Annex A controls — applicability, status, owner, evidence.
Audit-readiness checklist plus a corrective action log.
Security evaluation of vendors and third parties with data access.
Recovery objectives, continuity strategy, and a test log.
The annual top-management review record.
Version control plus a security awareness training log.
A simple cost-vs-benefit view for stakeholders.
A single self-contained HTML file. Fillable forms, live progress dashboard, search across all 93 controls, JSON export/import, print-to-PDF. No install, no build step.
Launch the app →The same eleven documents as plain text, for version control alongside your code or publishing via MkDocs/Docsify/GitHub Pages.
Browse the docs →One workbook with all eleven tabs (dropdowns, live formulas) plus a Word handbook — for anyone who'd rather just open a spreadsheet.
Download templates →