ISO/IEC 27001 operations

Make your ISMS work every day, not only before the audit

Turn security procedures into repeatable checks, clear ownership and traceable evidence across your operations.

From policy to practice

The hard part is keeping the system alive

ISO/IEC 27001 is not a one-off set of documents. It is a management system that must be operated, monitored, reviewed and improved. SentyHub connects recurring security work to the people who perform it and records what happened.

01

One operational view

Bring scheduled checks, open actions, alerts and supporting records into a consistent workflow.

02

Evidence at the source

Capture forms, signatures, timestamps, photos and, where appropriate, video clips linked through Event Video Trace when the work is done.

03

Follow-up that moves

Notify the right owner when a check is missed or a deviation needs action, and preserve the response trail.

How it works

Turn the controls you choose into repeatable operations

Your organisation defines the scope, risks and controls. SentyHub helps put the operational parts of that treatment plan into motion.

  1. 01

    Model the routine

    Translate procedures into forms, checks, frequencies, owners and escalation rules.

  2. 02

    Run it where work happens

    Let teams complete assigned controls from the site, floor or mobile device they already use.

  3. 03

    Respond to exceptions

    Route deviations to the right people and document the actions taken to resolve them.

  4. 04

    Review the evidence

    See what is complete, identify gaps and retrieve records for reviews and audits.

The operational layer

Support the parts of your ISMS that have to happen in the real world

Use the same platform to run routine controls, capture evidence and act on exceptions across people, facilities and day-to-day operations.

Digital controls

Run inspections, checklists and recurring security tasks with the context and evidence attached.

Explore digital forms

People and physical access

Keep traceable records for employees, visitors, contractors and access to controlled areas.

Explore access control

Events, alerts and follow-up

Send relevant deviations to the people who can act and retain the history of the response.

Explore alerts

Connected evidence

Use the public API and webhooks to connect operational records with the rest of your security stack.

Explore the platform

A clear boundary

A platform for execution, not a shortcut around the standard

SentyHub supports the operation and evidence of your ISMS. It does not decide what risks your organisation should accept or certify that your management system conforms to the standard.

SentyHub can support

  • Recurring operational controls
  • Evidence capture and traceable records
  • Alerts, escalation and follow-up
  • Operational status and audit retrieval

Your organisation remains responsible for

  • Defining the ISMS scope and objectives
  • Assessing and treating information security risks
  • Selecting applicable controls and maintaining the Statement of Applicability
  • Leadership review, continual improvement and the certification process

Certification is assessed and issued by an independent certification body. Using SentyHub does not by itself demonstrate conformity or guarantee certification.

Questions

Before you bring ISO/IEC 27001 into the platform

What is an ISMS?

An information security management system is the way an organisation governs information security through policies, responsibilities, risk management, operational controls, monitoring and continual improvement. It covers people and physical operations as well as technology.

Does SentyHub replace the risk assessment or Statement of Applicability?

No. Your organisation must define its risk method, assess and treat its risks, and justify which controls apply. SentyHub can help teams operate selected controls and retain the evidence they produce.

Can SentyHub certify our organisation?

No. SentyHub is software, not a certification body. An independent certification body performs the certification audit and decides whether to issue a certificate.

Which edition does this page refer to?

This page refers to ISO/IEC 27001:2022 together with Amendment 1:2024. The amendment adds climate-change considerations to the context of the organisation and interested-party requirements; it does not add a separate Annex A control.

See how SentyHub could fit your ISMS

Bring one real security workflow to the demo. We will show you how to turn it into an assigned, traceable operation without pretending the software replaces your management system.