Information security
Where Check HenQ originally came from. Controls, statement of applicability and evidence, in one place.
Where you are
Information security is what this system was originally built for, and it shows. The controls are in there, you build the statement of applicability inside the system instead of in a spreadsheet, and per control you see what hangs off it.
Useful detail for those who ask: the platform Check HenQ runs on is itself ISO 27001 certified.
Item by item
| What the standard asks for | Where you handle it in Check HenQ |
|---|---|
| Risk assessment | Threats, vulnerabilities and controls, with threat models built in. |
| Statement of applicability | Record per control whether it applies, with rationale and outsourcing. |
| Controls | The controls as requirements, with documents, tasks and evidence linked underneath. |
| Policies and procedures | Version control, approval and publication, so there is always one valid version. |
| Suppliers | Reviews, agreements and processor contracts, with the re-assessment already scheduled. |
| Incidents | From report to resolution, including privacy incidents and notification duties. |
| Awareness | Who received which instruction, and when it is due again. |
| Internal audit and management review | Plan, carry out, and have the input sitting together already. |
The difference
The requirements are already there. From day one you have a structure to hang your existing material on.
Every action, audit and inspection you attach to a requirement counts. You do not collect just before the audit.
Continuously, with a score that explains itself. In March you know what you will meet in November.
Combining
That is the rule rather than the exception. ISO 27001 is often mentioned in the same breath as the GDPR and sector baselines. In Check HenQ they hang off the same documents and the same processes, so you do the work once and demonstrate it several times.
Multiple standards means unlimited here. See pricing, or the overview of all standards.
Volgende stap
In a demo we take a requirement from ISO 27001 and build it up live. Within ten minutes you see how it would work for you.