Compliance guide

Configure and maintain the ISO 27001 ISMS

Maintain Clauses 4–10, scope and interested parties, recurring compliance activity, internal assurance, management review and continual improvement.

Compliance Manager, ISMS Manager or authorised contributor Ongoing programme activity Updated 18 September 2026

What the ISO 27001 workspace covers

PurpleWASP provides a structured workspace for operating an ISO/IEC 27001 management system, including Clauses 4–10, scope, interested parties, the Statement of Applicability, objectives, recurring compliance activity, internal audit, nonconformities, management review and supporting operational records.

Audit and evidence are capabilities inside the current Compliance/ISMS workflow. PurpleWASP does not present them as separate standalone modules.

1. Build and maintain the ISMS manual

Work through Clauses 4–10 and document the organisation's real context, leadership, planning, support, operation, performance evaluation and improvement arrangements.

The ISMS workspace structures the clauses and related records so the management system can be maintained in one place.

Where organisation AI features are enabled, use AI-generated wording as a draft only. Review it against the real scope, stakeholders, obligations and operating practices before saving it as authoritative content.

2. Maintain context and supporting records

Define in-scope and out-of-scope areas and maintain interested parties and their expectations. Keep related records current, including legal obligations, processes and dependencies, communications, training, suppliers, incidents, access reviews, business continuity/disaster recovery and retention records where they apply to the ISMS.

3. Schedule recurring compliance activity

Use compliance activities for repeatable governance work such as management review, Policy review, Control review, Risk review, supplier review, training, certification, renewal and corrective action. Assign an accountable role, priority, due date and recurrence where the activity repeats.

4. Record internal assurance and improvement

  • Plan and perform internal audits against defined scope, objective and criteria.
  • Record findings and link supporting evidence.
  • Raise nonconformities or improvement items and document root cause and corrective action.
  • Track effectiveness review and closure rather than treating implementation as the end of the process.
  • Use the Statement of Applicability and Control Management for the appropriate compliance versus operational-Control decisions.

5. Record management review

Maintain meeting dates, attendees, required inputs, outputs, minutes and resulting actions. Track each action with an owner, due date and status so review decisions become accountable follow-up work.

6. Use the Compliance dashboard

The dashboard surfaces the current compliance position and the work that needs attention.

The ISO readiness model brings together governance/ISMS foundation, planning and objectives, support/documented information, operational implementation, performance evaluation and improvement. Use View Drivers and Improve Score to see the records reducing the internal readiness position.

Any percentage or score shown is an operational indicator based on records maintained in PurpleWASP. It is not itself an ISO certification decision. Follow the metric back to the underlying SoA, Controls, evidence, audits, management reviews, nonconformities, BC/DR tests and other source records.

Common problems

AI-generated content is too generic

Confirm the organisation profile and then rewrite the output so it reflects actual scope, interested parties and practices.

A dashboard metric does not change after work is completed

Confirm the underlying record was saved in the correct status and that required evidence or relationships are linked. Refresh the dashboard after the authoritative record has changed.

Control assurance and SoA status disagree

Review both records. Reconcile the compliance decision in the SoA with the operational implementation and assurance facts in Control Management.