Standard
ISO 27001. An ISMS that reflects how your company actually works.
ISO 27001:2022 asks for a management system for information security and a reasoned choice from the 93 controls in Annex A. Trustbird helps you describe your organization in plain language, turns that into risks, controls and a Statement of Applicability, and keeps the evidence together for the audit.
- All 93 Annex A controls in four themes
- Statement of Applicability kept up to date
- The same core reused for NEN 7510 and ISO 9001
What Trustbird does for your ISMS
ISO 27001 has two parts: the management system in clauses 4 to 10, and the controls in Annex A. Trustbird covers both, working from one picture of your people, processes, systems, data and suppliers.
Context and scope
Record your stakeholders, their expectations and the boundaries of your ISMS. The scope stays visible next to every risk and control, so it matches what customers buy.
Risk assessment and treatment
Assess risks against the assets and processes they affect, choose a treatment and link the controls that carry it out. Accepted risks have a named owner and a date.
Annex A in four themes
The organizational, people, physical and technological controls are all there, described in our own words. For each one you decide whether it applies and how you meet it.
Statement of Applicability
Your choices and justifications per control form the Statement of Applicability. It updates as risks and controls change, instead of living in a separate spreadsheet.
Evidence with a home
Attach evidence to the control it supports. Trustbird shows which evidence is missing or out of date, and the AI checks whether a file fits the control before a person accepts it.
Internal audit and management review
Plan the internal audit cycle, record findings and follow up corrective actions. The management review draws on the risks, incidents and audit results already in the system.
From first question to audit
-
01
Describe your company
Answer questions about your teams, products, systems and suppliers. Trustbird translates the answers into context, scope and assets.
-
02
Assess the risks
Work through proposed risks, adjust them to your situation and decide how to treat each one.
-
03
Choose and implement controls
Approve policy, assign owners and attach evidence. The Statement of Applicability follows your decisions.
-
04
Prepare for the certification audit
Run the internal audit and management review, then export the Statement of Applicability, evidence and audit trail for the auditor.
Frequently asked questions
- Do I have to implement all 93 controls?
- No. You consider every control, but you apply what your risks call for. The Statement of Applicability records for each control whether it applies and why.
- Does Trustbird include the text of ISO 27001?
- No. The standard is copyrighted, so Trustbird describes each clause and control in its own words, linked to the official numbering. You buy the standard itself from ISO or NEN.
- Will using Trustbird get me certified?
- Not by itself. Certification is granted by a certification body after an audit, and Trustbird does not guarantee the outcome. Trustbird helps you build and maintain the management system and hand the auditor a complete, well-organized file.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.