Keel
Live demo · read-onlyStart free →
This is a live, read-only demo. You’re exploring a fictional company, “Tailwind Systems.” Nothing here can be edited, and the data resets nightly. Create a free workspace to build your own program.
Start freeLearn more
Total
31
Implemented
24
In progress
3
Gaps
2
ControlMapped clausesEvidenceStatus
Access control
A.5.15, A.8.3, PR.AA-01, PR.AA-050Implemented
Access control policy
Rules for granting, reviewing, and revoking access to systems and data based on business need and least privilege.
A.5.15, CC6.1, CC6.30Implemented
Asset inventory
An inventory of hardware, software, and information assets with assigned owners.
A.5.9, CC6.10Implemented
Backups
A.8.13, PR.DS-111Implemented
Backups
Regular, tested backups of critical data and systems with defined retention.
A.8.13, A1.20Implemented
Business continuity & disaster recovery
BC/DR plans with defined RTO/RPO, tested periodically, to restore service after disruption.
A.5.30, A1.2, A1.30Implemented
Change management
Changes to systems and software are requested, reviewed, tested, approved, and tracked.
A.8.32, CC8.10Implemented
Data classification & handling
Information is classified and handled per its sensitivity, with rules for labeling and protection.
A.5.12, C1.10Implemented
Data retention & secure disposal
Data is retained per policy and securely destroyed when no longer needed.
A.8.10, C1.20Implemented
Document & records control
Documented information is created, approved, versioned, and controlled; records are retained and protected.
A.5.37, CC5.30Implemented
Encryption in transit & at rest
Strong cryptography protects sensitive data in transit over public networks and at rest in storage.
A.8.24, CC6.70Implemented
Personnel security (HR)
Background screening, confidentiality agreements, and onboarding/offboarding security steps.
A.6.1, A.6.5, CC1.40Implemented
Incident response
A documented, tested plan to detect, triage, contain, remediate, and communicate security incidents.
A.5.24, A.5.26, CC7.3, CC7.40Implemented
Personal data privacy
Personal data of employees and customers is protected with clear, honored privacy practices.
A.5.340In progress
Information security policy
A board-approved information security policy set, reviewed at least annually and communicated to the workforce.
A.5.1, CC5.30In progress
Internal audit program
A risk-based internal audit program evaluates conformity and effectiveness at planned intervals.
A.5.35, CC4.10In progress
ISMS policy set
A.5.1, GV.PO-010Gap
Logging & monitoring
A.8.15, A.8.16, DE.CM-09, PR.PS-040Gap
Logging & monitoring
Security-relevant events are logged, protected, retained, and reviewed for anomalies.
A.8.15, A.8.16, CC7.20Not started
Malware protection
Anti-malware controls prevent, detect, and respond to malicious software on endpoints and servers.
A.8.7, CC6.80Not started
Management review
Leadership reviews management-system performance at planned intervals and drives improvement decisions.
CC4.10Implemented
Multi-factor authentication
MFA enforced for remote access, administrative access, and access to sensitive systems and data.
A.8.5, PR.AA-03, CC6.10Implemented
Network security controls
Firewalls/segmentation and network controls restrict traffic to and from sensitive environments.
A.8.20, A.8.22, CC6.60Implemented
Physical security
Physical access to facilities and equipment holding sensitive data is restricted and monitored.
A.7.1, A.7.2, CC6.40Implemented
Risk assessment & treatment
A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence.
A.5.7, CC3.1, CC3.20Implemented
Secure software development
Secure coding, review, and testing practices across the development lifecycle.
A.8.25, CC8.10Implemented
Security awareness training
Ongoing security awareness training for all personnel, with completion tracking.
A.6.3, CC1.40Implemented
User provisioning & deprovisioning
Joiner/mover/leaver process to grant, change, and promptly remove access across systems.
A.8.3, CC6.2, CC6.30Implemented
Third-party / vendor risk management
Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data.
A.5.19, CC9.21Implemented
Vulnerability management
A.8.8, ID.RA-010Implemented
Vulnerability management
Regular scanning, prioritization, and remediation of vulnerabilities across systems and applications.
A.8.8, CC7.10Implemented