Work toward ISO 27001 one clear step at a time

A guided workspace for Swedish and European companies building their information security management system. It shows what to do next, explains why the auditor asks, and runs in your own instance in the EU.

  1. Set direction

    • Context and scope4.1–4.3
    • Objectives and roles5.3, 6.2
    • Risk assessment6.1.2
  2. Put it to work

    • Statement of Applicability6.1.3
    • Policies and controlsAnnex A
    • Evidence that it runs7.5, 8
  3. Check and prepare

    • Internal audit9.2
    • Management review9.3
    • Ready for Stage 1 and Stage 2 with your certification body

What you work with every week

Built on CISO Assistant, the open-source GRC platform, with a Hisland layer that decides the order and keeps the language plain.

Start from your company, not a blank framework

Five short questions about who you are, why now, your scope, where you stand and your yearly rhythm. Your answers switch on the modules you need, apply the Hisland ISO 27001 journey and put the big dates in the calendar.

How the starting point works
  1. Your companySize, sector, who runs IT, where data lives
  2. Why nowCustomer demand, a tender, NIS2, insurance
  3. ScopeSites, systems and people, in one sentence
  4. Where you arePick the sentence that sounds like you
  5. Your rhythmReviews, internal audit, target quarter

Then one action: set up my workspace.

Every step says why the auditor asks

The Hisland ISO 27001 journey follows the standard from context to improvement. Each step opens the screen where the work happens, tells you roughly how long it takes, and what good looks like. You mark a step done when the record it points to exists.

A journey in Hisland Comply with the Explain panel open, describing what the step is and why the auditor asks. The same screen in dark mode.
Journey with the Explain panel open. Reshoot with the ISO 27001 demo tenant

Readiness you can act on, without a score

One page shows what would stop a Stage 1 audit, what could go wrong at Stage 2, whether the two hard gates are done, and how much is documented compared with what is actually operating. Counts and dates, never a single percentage.

A person to ask when the standard gets vague

The help corner sits on every screen. Read a plain explanation of the page, send feedback, or ask a Hisland consultant. Your question arrives with the step you were on, so nobody has to start from the beginning.

Working with a Hisland consultant

Your own instance, in the EU

No shared database with other customers. The code underneath is open source, so you can see what runs and take your data with you.

One instance per customer

Your workspace runs on its own, with its own database and backups.

Hosted in the EU

Application and data stay in [provider, region].

Open source base

CISO Assistant Community by intuitem, AGPL. The Hisland layer is public too.

AI is optional

When switched on, it runs on an EU endpoint in Paris and only explains and summarises.

Security and data residency

For companies doing this for the first time

Small and mid-sized companies without a full-time security team, where someone has been asked to get ISO 27001 in place and wants a clear path rather than a blank register.

  • A customer asks for itSecurity questionnaires and contract clauses
  • A tender requires itPublic and private procurement
  • NIS2 applies to youDirectly, or through your customers
  • Insurance wants evidenceCyber insurance renewals
Placeholder for a customer quote or case. Use only with the customer's written permission and their real name, role and company. Leave this section out at launch if none exists.

Questions people ask first

Does Hisland Comply certify us?
No. Certification is done by an accredited certification body. Hisland Comply helps you build and run the management system and keep the records the auditor will ask for.
How is this different from Vanta or Drata?
It is built for companies that want guidance in plain language and a consultant within reach, rather than automated integrations first. It runs as your own EU-hosted instance on open-source software.
Which frameworks are covered?
The guided journey is ISO 27001:2022. The platform underneath supports many other frameworks, such as NIS2 and ISO 27701, without the Hisland guidance. [confirm which to name]
Is it available in Swedish?
The product and this site are in English today. The ISO 27001 content has Swedish text, and a Swedish interface is planned if customers ask for it.

Want to see it with your own scope?

A short call where we walk through the starting point using your company as the example.

Book a demo