This is a live, read-only demo. You’re exploring a fictional company, “Tailwind Systems.” Nothing here can be edited, and the data resets nightly. Create a free workspace to build your own program.
Controls
Control register
Every safeguard, its status, and the framework clauses it satisfies.
Total
31
Implemented
24
In progress
3
Gaps
2
| Control | Mapped clauses | Evidence | Status |
|---|---|---|---|
Access control | A.5.15, A.8.3, PR.AA-01, PR.AA-05 | 0 | Implemented |
Access control policy Rules for granting, reviewing, and revoking access to systems and data based on business need and least privilege. | A.5.15, CC6.1, CC6.3 | 0 | Implemented |
Asset inventory An inventory of hardware, software, and information assets with assigned owners. | A.5.9, CC6.1 | 0 | Implemented |
Backups | A.8.13, PR.DS-11 | 1 | Implemented |
Backups Regular, tested backups of critical data and systems with defined retention. | A.8.13, A1.2 | 0 | Implemented |
Business continuity & disaster recovery BC/DR plans with defined RTO/RPO, tested periodically, to restore service after disruption. | A.5.30, A1.2, A1.3 | 0 | Implemented |
Change management Changes to systems and software are requested, reviewed, tested, approved, and tracked. | A.8.32, CC8.1 | 0 | Implemented |
Data classification & handling Information is classified and handled per its sensitivity, with rules for labeling and protection. | A.5.12, C1.1 | 0 | Implemented |
Data retention & secure disposal Data is retained per policy and securely destroyed when no longer needed. | A.8.10, C1.2 | 0 | Implemented |
Document & records control Documented information is created, approved, versioned, and controlled; records are retained and protected. | A.5.37, CC5.3 | 0 | Implemented |
Encryption in transit & at rest Strong cryptography protects sensitive data in transit over public networks and at rest in storage. | A.8.24, CC6.7 | 0 | Implemented |
Personnel security (HR) Background screening, confidentiality agreements, and onboarding/offboarding security steps. | A.6.1, A.6.5, CC1.4 | 0 | Implemented |
Incident response A documented, tested plan to detect, triage, contain, remediate, and communicate security incidents. | A.5.24, A.5.26, CC7.3, CC7.4 | 0 | Implemented |
Personal data privacy Personal data of employees and customers is protected with clear, honored privacy practices. | A.5.34 | 0 | In progress |
Information security policy A board-approved information security policy set, reviewed at least annually and communicated to the workforce. | A.5.1, CC5.3 | 0 | In progress |
Internal audit program A risk-based internal audit program evaluates conformity and effectiveness at planned intervals. | A.5.35, CC4.1 | 0 | In progress |
ISMS policy set | A.5.1, GV.PO-01 | 0 | Gap |
Logging & monitoring | A.8.15, A.8.16, DE.CM-09, PR.PS-04 | 0 | Gap |
Logging & monitoring Security-relevant events are logged, protected, retained, and reviewed for anomalies. | A.8.15, A.8.16, CC7.2 | 0 | Not started |
Malware protection Anti-malware controls prevent, detect, and respond to malicious software on endpoints and servers. | A.8.7, CC6.8 | 0 | Not started |
Management review Leadership reviews management-system performance at planned intervals and drives improvement decisions. | CC4.1 | 0 | Implemented |
Multi-factor authentication MFA enforced for remote access, administrative access, and access to sensitive systems and data. | A.8.5, PR.AA-03, CC6.1 | 0 | Implemented |
Network security controls Firewalls/segmentation and network controls restrict traffic to and from sensitive environments. | A.8.20, A.8.22, CC6.6 | 0 | Implemented |
Physical security Physical access to facilities and equipment holding sensitive data is restricted and monitored. | A.7.1, A.7.2, CC6.4 | 0 | Implemented |
Risk assessment & treatment A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence. | A.5.7, CC3.1, CC3.2 | 0 | Implemented |
Secure software development Secure coding, review, and testing practices across the development lifecycle. | A.8.25, CC8.1 | 0 | Implemented |
Security awareness training Ongoing security awareness training for all personnel, with completion tracking. | A.6.3, CC1.4 | 0 | Implemented |
User provisioning & deprovisioning Joiner/mover/leaver process to grant, change, and promptly remove access across systems. | A.8.3, CC6.2, CC6.3 | 0 | Implemented |
Third-party / vendor risk management Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data. | A.5.19, CC9.2 | 1 | Implemented |
Vulnerability management | A.8.8, ID.RA-01 | 0 | Implemented |
Vulnerability management Regular scanning, prioritization, and remediation of vulnerabilities across systems and applications. | A.8.8, CC7.1 | 0 | Implemented |