From the first question to a system that runs
Hisland Comply puts the work of ISO 27001 in an order that makes sense for a small company, and keeps it running after the first audit.
-
Answer the starting questions
Five screens, one question at a time. You describe your company, why you are doing this now, what is in scope, where you stand today and the rhythm you want to keep. Each screen has one action, and you can change any answer later.
What the answers set up
- Only the modules you need, for example privacy only when personal data is in scope
- The Hisland ISO 27001 journey, with your scope and objectives filled in
- Recurring dates for management review, internal audit, risk review and access review
- Your readiness page as the home screen
-
Follow the journey
The journey walks through the standard in the order an auditor reads it. Each step explains what it is, why the auditor asks and roughly how long it takes, then opens the screen where the work happens.
A few of the steps
- Context and interested parties 4.1, 4.2
- Risk assessment and treatment 6.1.2, 6.1.3
- Statement of Applicability 6.1.3 d
- Evidence for controls in operation 7.5
- Internal audit and management review 9.2, 9.3
- Findings and corrective actions 10.2
-
See where you stand
The readiness page lists what would block a Stage 1 audit and what could go wrong at Stage 2, shows whether the internal audit and management review are done, and compares documented controls with the ones that are operating.
It shows counts, dates and trends. It does not reduce your work to a single percentage.
On the readiness page
- Stage 1 blockers: required documents without evidence
- Stage 2 risks: controls past their date, risks without treatment
- The two hard gates: internal audit, management review
- Documented and operating, per Annex A theme
- Open nonconformities and the next big dates
-
Keep a weekly rhythm
A fifteen-minute weekly review starts with what you closed, then sweeps what needs sorting, risks nobody has looked at, and corrective actions whose follow-up date has passed.
Planned after v1
Weekly review, in order
ClosedSince last weekTo sortNew itemsStale risksNot reviewedFollow-upsDid it work?NextBig dates -
Ask when you are unsure
The help corner explains the screen you are on in plain words, takes feedback, and lets you ask a Hisland consultant. If your organisation has switched on the AI assistant, you can ask follow-up questions about what a requirement means.
In the help corner
- Explain this screen
- Send feedback, with an optional screenshot
- Ask Hisland, with your current step attached
- What's new
What sits underneath
Hisland Comply is CISO Assistant Community, the open-source GRC platform by intuitem, with a Hisland layer on top. Everything the platform can do is still there when you need it.
| Record | What you keep in it |
|---|---|
| Assets and scope | Systems, sites and information in scope |
| Risk register | Risks, treatment and acceptance |
| Statement of Applicability | Which Annex A controls apply, and why |
| Controls and evidence | What you do and proof that it runs |
| Audits and findings | Internal audits, nonconformities, corrective actions |
| Exports | Statement of Applicability and audit packages for your auditor |
What it is not
Not a certificate
Only an accredited certification body can certify you. Hisland Comply helps you prepare and keep the records.
Not a policy generator
You write your own policies, with help and examples. The AI assistant explains, it does not write them for you.
Not an integration hub
It does not connect to your cloud accounts to collect evidence automatically. [confirm for v1]
Want to try the starting questions?
We go through them together on a call, using your company.