Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideMaintain Clauses 4–10, scope and interested parties, recurring compliance activity, internal assurance, management review and continual improvement.
PurpleWASP provides a structured workspace for operating an ISO/IEC 27001 management system, including Clauses 4–10, scope, interested parties, the Statement of Applicability, objectives, recurring compliance activity, internal audit, nonconformities, management review and supporting operational records.
Work through Clauses 4–10 and document the organisation's real context, leadership, planning, support, operation, performance evaluation and improvement arrangements.
Where organisation AI features are enabled, use AI-generated wording as a draft only. Review it against the real scope, stakeholders, obligations and operating practices before saving it as authoritative content.
Define in-scope and out-of-scope areas and maintain interested parties and their expectations. Keep related records current, including legal obligations, processes and dependencies, communications, training, suppliers, incidents, access reviews, business continuity/disaster recovery and retention records where they apply to the ISMS.
Use compliance activities for repeatable governance work such as management review, Policy review, Control review, Risk review, supplier review, training, certification, renewal and corrective action. Assign an accountable role, priority, due date and recurrence where the activity repeats.
Maintain meeting dates, attendees, required inputs, outputs, minutes and resulting actions. Track each action with an owner, due date and status so review decisions become accountable follow-up work.
The ISO readiness model brings together governance/ISMS foundation, planning and objectives, support/documented information, operational implementation, performance evaluation and improvement. Use View Drivers and Improve Score to see the records reducing the internal readiness position.
Any percentage or score shown is an operational indicator based on records maintained in PurpleWASP. It is not itself an ISO certification decision. Follow the metric back to the underlying SoA, Controls, evidence, audits, management reviews, nonconformities, BC/DR tests and other source records.
Confirm the organisation profile and then rewrite the output so it reflects actual scope, interested parties and practices.
Confirm the underlying record was saved in the correct status and that required evidence or relationships are linked. Refresh the dashboard after the authoritative record has changed.
Review both records. Reconcile the compliance decision in the SoA with the operational implementation and assurance facts in Control Management.