Solutions

ISMS platform

An information security management system needs one place for the risk assessment, the controls, the evidence, and the people who keep them current. SecBoard is that workspace.

What the ISMS workspace already contains

Risk assessment covers threats, vulnerabilities, assets, a calculated risk level, response measures, and reports. Compliance holds frameworks such as PCI DSS, ISO 27001, SOC 2, HIPAA, and GDPR, plus internal policies, with templates, reminders, and confirmation that a mandatory process was done. Assets, documents, incidents, and the access matrix sit next to that, not in a separate toolkit.

How a control stays alive

The standards catalog stores PCI DSS requirements and ISO/IEC 27002 controls. Framework compliance maps those controls, attaches evidence, and tracks status. Security awareness and phishing campaigns cover the people side. None of this issues a certificate: it keeps the records an ISMS needs between audits.

Questions

It is one platform. Risk, compliance, assets, documents, incidents, access, and awareness are modules of the same product.

No. It stores the assessment, the control status, and the evidence the team shows an auditor.

In framework compliance for the ISO 27001 instance, in risk assessment for treatment, and in the ISO/IEC 27002 catalog for the control text.

Yes. Community Edition is self-hosted under AGPL v3, with a community key for up to 100 users.

Related