Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideBuild the Clauses 4–10 management system, maintain supporting registers and use the dashboard to prioritise improvement.
PurpleWASP provides an end-to-end workspace for the ISO/IEC 27001 management system, including the ISMS manual for Clauses 4–10, scope records, the Statement of Applicability, management reviews, audit activity, nonconformities and supporting registers.
Open the ISO 27001 compliance workspace and work through Clauses 4–10. Complete the required organisational context, leadership, planning, support, operation, performance evaluation and improvement information.
Where AI is enabled, it can draft supporting text using organisation details such as location and sector. Review and approve generated content before treating it as final.
Define what is in scope, what is out of scope and the relevant interfaces and dependencies. Maintain supporting registers such as assets, risks, objectives, incidents, legal obligations, suppliers, training and access reviews.
The score is an operational indicator, not a certification decision. Use its underlying drivers to identify incomplete requirements, missing evidence and control work.
Provide accurate organisation profile information and rewrite the output to reflect real scope, stakeholders and operating practices.
Review the improvement drivers and confirm that completed records have been saved, evidence linked and status updated.