RPG Excellence
Sign inBook
NEW STANDARDISO 9001:2026 is now publishedSee what changed and prepare your quality management system.
Read full update
INFORMATION SECURITY · ISO/IEC 27001

Your ISMS journey, connected end to end.

Move from leadership intent and a defensible scope to assessed risk, justified controls, controlled evidence and management evaluation—without breaking the audit trail between each decision.

✓ Nine controlled templates✓ Connected risk and SoA✓ Management-ready evidence
RPG Excellence Information Security Hub customer journey
One controlled route from scope and risk to controls, evidence and improvement
THE CUSTOMER JOURNEY

Eight stages. One defensible management system.

Each stage produces a controlled output used by the next. Customers can adopt the complete route or use the workspaces that match their present maturity.

01POL-001

Lead & govern

Approve the information-security policy, commitments, authority and management direction.

02PRO-001

Context & scope

Define organisational context, boundaries, interfaces, governance and accountable ownership.

03FRM-001

Requirements

Identify interested parties, obligations and information-security requirements, then monitor change.

04FRM-002

Risk & treatment

Assess inherent and residual risk, evaluate controls, plan treatment and authorise acceptance.

05FRM-003

Objectives

Set measurable ISMS objectives, establish measures and evaluate performance against targets.

06FRM-004

People & communication

Determine competence, deliver awareness and control internal and external communication.

07PRO-002 · PRO-003

Operate & control

Control documented information, risk-treatment delivery, suppliers, operations and change.

08PRO-004

Evaluate & improve

Validate data, analyse trends, evaluate effectiveness and escalate evidence-led action.

CONNECTED RISK DECISIONS

Assess exposure, then prove what changed.

The structured risk record preserves the cause–event–consequence scenario, inherent exposure, existing-control evaluation, residual decision, treatment plan and accountable acceptance. The live heat map makes priority visible without replacing the evidence beneath it.

  • Consistent 5×5 likelihood and consequence method
  • Risk-to-control and treatment traceability
  • High and critical risk escalation
  • Review dates, ownership and acceptance controls
Open ISMS Risk Management →
Information Security Risk Management dashboard and heat map
Risk portfolio, exposure distribution and treatment priorities
RISK → CONTROL → EVIDENCE

Turn Annex A selection into an accountable decision.

The Statement of Applicability connects each control to its justification, implementation position, risk treatment, accountable owner and objective evidence.

01Requirement
02Risk
03Treatment
04Annex A control
05Evidence
06Evaluation
LIVE ASSURANCE VIEWS

Detail for practitioners. Clarity for management.

Operational records remain available to the people doing the work, while dashboards surface incomplete decisions, control coverage and residual exposure for review.

Controlled Statement of Applicability register
Controlled SoA register across all Annex A controls
Statement of Applicability interactive risk heat map
Interactive risk-to-control exposure view
Statement of Applicability management board
Portfolio coverage, treatment position and management attention
CONTROLLED IMPLEMENTATION PACK

Documents that drive work—not shelfware.

The supplied policy, procedures and records form a practical implementation system. Every document has a defined purpose and a place in the customer journey.

01
Policy

Information Security Policy

Direction, principles, responsibilities, minimum controls and continual improvement.

02
Procedure

Context, Scope & Governance

Organisational context, interested parties, approved scope, authority and review.

03
Register

Interested Parties & Requirements

Applicable obligations, control links, gaps, changes and approval evidence.

04
Record

Risk Assessment & Treatment

5×5 scoring, control evaluation, residual risk, treatment and acceptance.

05
Record

Objectives & Performance Measures

Objective plans, measure definitions, results, escalation and evaluation.

06
Record

Competence, Awareness & Communication

Role competence, evidence, awareness effectiveness and authorised communication.

07
Procedure

Control of Documented Information

Creation, approval, publication, protection, retention, withdrawal and disposal.

08
Procedure

Operational Planning & Change Control

Treatment delivery, suppliers, change assessment, exceptions and review.

09
Procedure

Monitoring, Measurement & Evaluation

Measurement design, validation, trends, conclusions, reporting and action.

WHAT THE CUSTOMER LEAVES WITH

A visible, reviewable and improvable ISMS.

Leaders can see the approved scope, applicable obligations, priority risk, control position, objective performance and unresolved action. Practitioners retain the detail needed to demonstrate how each conclusion was reached.

Definedscope, governance and obligations
Assessedrisk and treatment decisions
Controlleddocuments, change and evidence
Evaluatedperformance and effectiveness
BUILD THE CUSTOMER JOURNEY

Know the risk. Justify the control. Prove the outcome.

Start your connected ISMS workspace with RPG Excellence.

Create your free account →
ISMS Hub at a Glance | RPG Excellence | RPG Excellence