ISO 27001 compliance automation.
Automation removes the bookkeeping: collecting evidence from the systems you already run, keeping the risk register connected to it, and having the audit package ready. It does not remove the decisions. Your scope, your risk acceptance, your internal audit and the certificate itself stay human, and any tool that implies otherwise is selling you an audit finding.
What a tool can genuinely automate
All of it is collection, correlation and keeping a record current — work a machine does better than a person with a spreadsheet and a calendar reminder.
- Collecting evidence from the systems you already run
- Access reviews, logging, backup and vulnerability status exist as facts in your cloud, identity provider and code host. Reading them directly is strictly better than asking someone to screenshot them quarterly, because the screenshot is stale the moment it is taken and nobody re-takes it until the next audit.
- Keeping the documented information current7.5 Documented information
- Versions, approvals, owners and review dates are bookkeeping. A tool that tracks which policy is current, who approved it and when it is next due removes an entire category of audit finding that has nothing to do with your actual security.
- Maintaining the risk register and treatment plan6.1 Actions to address risks and opportunities
- The register itself — risks, owners, treatment decisions, linked controls and the evidence behind each one — is a data structure. Keeping it connected so a treatment decision still points at live evidence a year later is exactly the kind of upkeep that decays by hand.
- Tracking control status and what is still missing
- Which controls are in place, which are partially in place, who owns the rest and what order to do them in. This is the part most teams try to run in a spreadsheet, and the spreadsheet is why the work stalls.
- Assembling the audit package
- An auditor asks for the evidence behind a control and the trail that connects it. Producing that on request, rather than reconstructing it over three weeks, is a packaging problem and a solved one.
What stays yours
Each of these is either a judgement the standard requires your management to make, or an activity that has to actually happen. Software can hold the record. It cannot be the decision.
- Deciding the scope4.3 Determining the scope of the information security management system
- Which parts of the business, which systems, which locations. Get this wrong and everything downstream is wrong, and no tool can make the call for you because it depends on what you sell and to whom. It is the first thing a Stage 1 audit examines.
- Setting risk criteria and accepting risk6.1 Actions to address risks and opportunities
- What counts as acceptable risk is a management decision with consequences, and the standard requires it to be a management decision. A tool can present the risk and record who accepted it. Somebody still has to accept it.
- The internal audit
- It has to be performed, by someone objective about the area under review. Software can schedule it, hold the findings and track the corrective actions. It cannot be the auditor.
- The management review
- Leadership has to look at the ISMS and decide things about it, on a record. A generated report is an input to that meeting, not a substitute for it.
- The certificate
- ISO/IEC 27001 certification is issued by an accredited certification body after a two-stage audit, and it is bought separately from any software. Any platform describing itself as getting you certified is describing the preparation, not the certificate.
How Kaamos handles the automatable half.
Connect your cloud, identity provider and code host, and Kaamos reads the state of those systems into an inventory and attaches it to the controls it evidences. The risk register, the treatment decisions and the roadmap sit on top of the same data, so a decision you made in March still points at evidence that is true in September rather than at a screenshot of March.
The other half stays yours, and we would rather say so here than in a footnote after you have bought it. Kaamos will hold your scope statement, record who accepted which risk, schedule the internal audit and keep its findings — but the scope is your decision, the acceptance is your management's, and the audit needs a person. The certificate comes from an accredited certification body and is paid for separately.
Sources
- ISO/IEC 27001:2022, catalogue entry
- ISO/IEC 27001:2022 clause structure, ISO Online Browsing Platform
- ISO/IEC 27001:2022 at the IEC Webstore, the joint publisher
- ISO/IEC JTC 1/SC 27, the committee that maintains the standard
- How ISO management system standards and certification work
The standard itself is paywalled, so clause titles here were read from ISO’s own Online Browsing Platform preview and nothing is quoted from the body of the text. Last reviewed .