Lead & govern
Approve the information-security policy, commitments, authority and management direction.

Move from leadership intent and a defensible scope to assessed risk, justified controls, controlled evidence and management evaluation—without breaking the audit trail between each decision.

Each stage produces a controlled output used by the next. Customers can adopt the complete route or use the workspaces that match their present maturity.
Approve the information-security policy, commitments, authority and management direction.
Define organisational context, boundaries, interfaces, governance and accountable ownership.
Identify interested parties, obligations and information-security requirements, then monitor change.
Assess inherent and residual risk, evaluate controls, plan treatment and authorise acceptance.
Set measurable ISMS objectives, establish measures and evaluate performance against targets.
Determine competence, deliver awareness and control internal and external communication.
Control documented information, risk-treatment delivery, suppliers, operations and change.
Validate data, analyse trends, evaluate effectiveness and escalate evidence-led action.
The structured risk record preserves the cause–event–consequence scenario, inherent exposure, existing-control evaluation, residual decision, treatment plan and accountable acceptance. The live heat map makes priority visible without replacing the evidence beneath it.

The Statement of Applicability connects each control to its justification, implementation position, risk treatment, accountable owner and objective evidence.
Operational records remain available to the people doing the work, while dashboards surface incomplete decisions, control coverage and residual exposure for review.



The supplied policy, procedures and records form a practical implementation system. Every document has a defined purpose and a place in the customer journey.
Direction, principles, responsibilities, minimum controls and continual improvement.
Organisational context, interested parties, approved scope, authority and review.
Applicable obligations, control links, gaps, changes and approval evidence.
5×5 scoring, control evaluation, residual risk, treatment and acceptance.
Objective plans, measure definitions, results, escalation and evaluation.
Role competence, evidence, awareness effectiveness and authorised communication.
Creation, approval, publication, protection, retention, withdrawal and disposal.
Treatment delivery, suppliers, change assessment, exceptions and review.
Measurement design, validation, trends, conclusions, reporting and action.
Leaders can see the approved scope, applicable obligations, priority risk, control position, objective performance and unresolved action. Practitioners retain the detail needed to demonstrate how each conclusion was reached.
Start your connected ISMS workspace with RPG Excellence.