Information security

Software for
ISO 27001

Where Check HenQ originally came from. Controls, statement of applicability and evidence, in one place.

Where you are

A standard is a list of requirements. That is how we treat it.

Information security is what this system was originally built for, and it shows. The controls are in there, you build the statement of applicability inside the system instead of in a spreadsheet, and per control you see what hangs off it.

Useful detail for those who ask: the platform Check HenQ runs on is itself ISO 27001 certified.

Item by item

What the system does for you

What the standard asks forWhere you handle it in Check HenQ
Risk assessmentThreats, vulnerabilities and controls, with threat models built in.
Statement of applicabilityRecord per control whether it applies, with rationale and outsourcing.
ControlsThe controls as requirements, with documents, tasks and evidence linked underneath.
Policies and proceduresVersion control, approval and publication, so there is always one valid version.
SuppliersReviews, agreements and processor contracts, with the re-assessment already scheduled.
IncidentsFrom report to resolution, including privacy incidents and notification duties.
AwarenessWho received which instruction, and when it is due again.
Internal audit and management reviewPlan, carry out, and have the input sitting together already.

The difference

Why this goes faster

You do not start empty

The requirements are already there. From day one you have a structure to hang your existing material on.

Evidence grows along

Every action, audit and inspection you attach to a requirement counts. You do not collect just before the audit.

The Monitor watches

Continuously, with a score that explains itself. In March you know what you will meet in November.

Combining

Several standards on your plate?

That is the rule rather than the exception. ISO 27001 is often mentioned in the same breath as the GDPR and sector baselines. In Check HenQ they hang off the same documents and the same processes, so you do the work once and demonstrate it several times.

ISO 9001ISO 14001ISO 45001ISO 27001VCAVCUISO 17025ISO 17020Legal requirementsClient requirementsOwn requirements

Multiple standards means unlimited here. See pricing, or the overview of all standards.

Volgende stap

See it on your own requirements

In a demo we take a requirement from ISO 27001 and build it up live. Within ten minutes you see how it would work for you.