Our company is in the process of formalizing an ISMS to later apply for ISO 27001 certification.
While searching for suitable ISMS tool, I have stumbled onto the below youtube video and articles by atlassian's (former?) security Guy:
https://community.atlassian.com/t5/Agile-articles/How-Atlassian-uses-Jira-to-manage-risks-and-compliance/ba-p/896891
https://community.atlassian.com/t5/Agile-articles/How-Atlassian-uses-Jira-to-manage-risks-and-compliance/ba-p/896891
https://youtu.be/FvjhskeEg_M
The presentation on youtube convinced me that Jira+Confluence would be the best choice for our company. However Guy stopped responding to questions a while back and there are some open questions - the provided data on community forum isn't really exhausting. Just a rough cut to setup main things in Jira.
I would like to know if anyone is operating ISMS based on setup from Guy or own setup and if they can share their view of pros / cons for Jira as an ISMS and/or GRC tool and how to best get started.
Ideally, more support from atlassian would be welcome - if they document this better or even package a solution, it could be a very good selling proposition.
I am aware of some companies that sell confluence addons in atlassian market - I may ultimately use some of these, but my question is mainly about Jira as ISMS and GRC tool/platform.