Hi there,
I'm looking for some help to direct me to folks that have created an ISMS using confluence, or something that is 'pre canned' that we can customise.
Any assistance is appreciated.
cheers
Rob
Have you had any luck @Robert McAdam? My online search lead me to your post and the website https://instant27001.com/.
Thanks Kat, I have looked in depth at instant27001.com and seeing if there were any others that were available. So far, they look like the only ones.
Hi Robert,
My company bought an ISO 27001 package, which consisted of roughly 100+ Word and Excel templates, some tens of pages long, while others a few paragraphs long.
Last year along with a colleague we were responsible for editing everything, changing the file owners, tags and labels, sharing them with people within the organisation over email and ensuring processes were place. It was an extremely tiring, a messy process, with a lot of files in various folders, multiple versions of documents, a lot of hard work. I wouldn't recommend it on anyone.
This year I moved everything into Confluence, which was relatively easy to do with the Import Word document function and copy and paste, which sometimes is a lot easier because Word has a lot of unnecessary formatting. The big job really is:
If you are going to do it yourself consider this 'must have' plugin, which will make your life a lot easier with all of the above. Sadly I only discovered this plugin in the last month, thus wasted a lot of time updating audit report pages manually.
I am happy to share a few tips and tricks on how to do the pages, how to build the reports, etc.
In fact I did a post not so long ago titled How to automate a page (report) that summaries changes on other pages? on this very topic and one can see where I have used the QC plugin to maximise the potential of automation.
Here is example ISO Audit report page I created that is entirely automated, linked to every ISO page and it pulls in information as pages are updated.
The other plugin I mentioned is 'SubSpace Navigation for Confluence', this is a menu system, which I am using to show important documentation. I've found folk remember stuff a lot more if they:
Here is an example of the menu in action for ISO 27001.
- Mike
I am already in contact with @Robert McAdam but for all other people that stumble upon this question: I am the owner of Instant 27001 :-).
My solution is designed and sold as ready-to-run, as it contains not only the templates, but also all canned examples, written with small business in mind. So no need to sift through hundreds of lengthy Word and Excel files.
No plugins required, plain vanilla Confluence will do!
We are interested in implementation . Requested a demo
That might be a stupid question but I am thinking about versioning documents in Confluence. ISO requires version control. Sometimes, however, typos or other minor changes are corrected in the document which do not affect the substantive content. Confluence makes a new version of document after every little change. When changing the version, you must authorize the change and notify stakeholders. How did you handle it?
I wonder if we should introduce manual version control (manual mark) so that I only change version when there is a significant document change.
Hi @Iz P ,
Our Scroll Documents app can help you here if you're looking for manual version control. (Just to be open, I work for the vendor of this app).
With Scroll Documents, you can save versions / snapshots of a page (or even multiple pages) whenever your team needs to. This feature isn't tied to Confluence's page versioning, so you can still make those minor changes between versions and they won't affect the major versions that you control.
If you have any questions, we'd be happy to help or show you a demo of the app. Just get in touch with us: hello@k15t.com.
Cheers,
Shannon (K15t)
The version controls system in Confluence suffices for ISO.
Yes, if you correct a typo a new version number will be assigned, but you can show the differences between the versions to the auditor, as proof that it did not have to be re-approved.
So while external version control or workflow apps may prove additional value to an organization, they are not required for ISO compliance.
(Source: I am an ISO auditor myself, and Instant 27001 has been certified hundreds of times so far without issues :-)
@Maurice Pasman Thank you! So, I'll manually mark the revision on the document and use a Confluence version control only to proof compliance (show that change didn't have to be reapproved).
Hi @Robert McAdam, a partner of ours just released a plugin to help getting ISO 27001 certified.
Probably you already found your solution but maybe others may find this to be a useful alternative.
Here is the link to ISMS for Confluence on the Atlassian Marketplace: https://marketplace.atlassian.com/apps/1223742/isms-for-confluence?hosting=server&tab=overview
Feel free to contact them if you have further questions.
@Maurice Pasman does it also have an operational planning? So that you can generate (recurring) tasks?
It comes with an operational planning, but that is still a static page.
The most pragmatic approach is to take that planning an automate using recurring appointments in your team calendar.
Or, look at the Instant 27001 Jira Companion if you want to automate things from within the Atlassian stack :-).
@Mike Bowen appreciate its been a while, I noted the work you done on the ISO docs was something I was looking at - only just thinking of building something. But wanted to touch base if your open to it for any guidance ?
Hello @Robert McAdam
I hope everything is well!
Maybe you already found the solution that you were looking for, but if not maybe you would be interested in our ready-to-use ISO/IEC 27001:2022 Template for Confluence Cloud which you can find on our store.
Last year we got certified with ISO 27001 by using this exact template (with some customizations according to our needs of course) and we decided to help other companies ensure their compliance with the standard's requirements as well.
You can also have a look at this article I wrote in the community regarding our ready-to-use space templates, or contact us for any additional help you may need.
I hope this helps you or any other readers that stumble upon your question 🙂
Kind regards,
Sofia
Getting ISO 27001 to actually hold up in Confluence is less about the templates and more about enforcing the controls around your pages.So things like classification, access restriction, documented review and approval, and an audit trail of who changed what and when. These types of ISMS packs are amazing at getting you the document set quickly, but auditors will also want evidence those controls are operating, not just that the policies exist.
Two things that close that gap if you're staying inside Confluence: Compliance for Confluence for classifying pages and flagging/restricting sensitive content, and Workflows for Confluence for a proper draft → review → approved lifecycle with page owners, expiry/review dates and periodic re-approval - something that the Annex A documented-information control really asks for.
We wrote up the full approach here: How to achieve ISO 27001 in Confluence. Happy to share specifics if useful
It looks like you're new here. Sign in or register to get started.