Skip to content

Repository files navigation

ISO 27001:2022 GRC Assessment Tool

A browser-based gap analysis tool that maps an organisation's security posture against all 93 ISO/IEC 27001:2022 Annex A controls — no backend, no dependencies, deployable as a single HTML file.

Live Demo: https://<your-username>.github.io/iso27001-grc-tool


Screenshots

Dashboard Controls Register Gap Analysis
Coverage stats, domain breakdown, top risk controls All 93 controls with search, filter, detail panel Risk-prioritised gap list with remediation hints

Features

  • Full Annex A coverage — all 93 controls across Organizational (5.x), People (6.x), Physical (7.x), and Technological (8.x) domains
  • Structured gap analysis — Implemented / Partially Implemented / Missing / Not Applicable
  • Risk rating — Critical / High / Medium / Low, computed from domain defaults + questionnaire context
  • Company background questionnaire — 10-question intake form that drives rule-based control mapping
  • Detail panel — per-control objective, evidence requirements, remediation actions, and owner
  • Three export formats — JSON, Markdown report, CSV spreadsheet
  • Demo dataset — fictional Australian SaaS company (NovaBridge Pty Ltd) with 10 pre-loaded known issues
  • Zero dependencies — pure HTML/CSS/JS, works offline, deployable on GitHub Pages

Repository Structure

iso27001-grc-tool/
├── index.html                      # Main assessment dashboard (Gap Analysis Tool)
├── questionnaire.html              # Company background questionnaire (intake form)
├── iso27001_annex_a_controls.json  # Knowledge base: all 93 Annex A controls
├── company_questionnaire.json      # Questionnaire schema + control mapping rules
├── novabridge_demo_dataset.json    # Demo dataset: fictional SaaS company
└── README.md

How It Works

1. Questionnaire → Risk Context

The 10-question intake form collects company context across six dimensions:

Question Dimension GRC Purpose
Q01 Organisation size Governance complexity
Q02 Industry sector Regulatory obligations (APRA CPS 234, Privacy Act, ISM)
Q03 PII handling Data breach impact severity
Q04 Infrastructure Attack surface (cloud vs on-premise)
Q05 Remote work / BYOD Perimeter definition
Q06 Software development Supply chain / SDLC risk
Q07 Third-party suppliers Indirect exposure
Q08 Security operations Current detection capability
Q09 Identity & access Current IAM maturity
Q10 Governance documents Baseline governance maturity

2. Rule-based Mapping Engine

Each answer triggers one of three rule types:

  • mandatory — control is a regulatory requirement for this sector (e.g. APRA CPS 234 → 8.15, 8.16)
  • elevate_risk — control's default risk tier is increased (e.g. sensitive PII → 8.11 escalates to Critical)
  • increase_applicability — control confirmed as in-scope (e.g. public cloud → 5.23 applicable)

Answers accumulate — multiple rules from different questions apply to the same control, producing a context-weighted final risk rating.

3. Structured Output

Every control produces four GRC-relevant outputs:

{
  "control_id": "8.11",
  "status":     "Missing",
  "risk_level": "Critical",
  "gaps":       ["Production PII (TFN, bank details) present in staging without masking"],
  "remediation_hints": [
    "Mask PII in test/dev environments",
    "Implement tokenisation for payment or health data",
    "Document masking procedures aligned to Privacy Act obligations"
  ]
}

Demo: NovaBridge Pty Ltd

The tool ships with a pre-loaded fictional dataset representing a realistic Australian SaaS assessment scenario.

Company profile: 85-person cloud HR & payroll platform, Melbourne. Processes TFNs, salary records, and superannuation details for ~45,000 employees across 1,200 client organisations. AWS-hosted, hybrid workforce, ISO 27001 certification in progress.

Assessment results:

Status Count
Implemented 6
Partially Implemented 7
Missing 80
Total 93
Risk Level Count
Critical 4
High 34
Medium 42
Low 13

10 pre-loaded known issues including:

  • KI-002 — Production TFN/bank data in staging without masking → Critical (8.11, 8.31, 5.34)
  • KI-005 — No SIEM; CloudTrail logs unmonitored → High (8.15, 8.16, 5.25)
  • KI-009 — No SAST/DAST in CI/CD pipeline → High (8.28, 8.29, 8.8)

Methodology

Control Status Definitions

Status Definition
Implemented Control fully in place with verifiable evidence
Partially Implemented Control exists but gaps remain in scope, documentation, or testing
Missing No evidence of control implementation
Not Applicable Control is not relevant to this organisation's context

Risk Rating Logic

Base risk = domain default
            (Technological: High, Organizational: Medium, People: Medium, Physical: Low)

+ Questionnaire elevation rules (mandatory / elevate_risk)
+ Known issue severity overlay
= Final risk level (Critical / High / Medium / Low)

Australian Regulatory Alignment

Framework Applicable Controls
Privacy Act 1988 — APP 1–13 5.34, 8.11, 8.12, 5.12, 8.3
Notifiable Data Breaches (NDB) Scheme 5.5, 5.24, 5.26
APRA CPS 234 8.15, 8.16, 5.35, 8.2, 8.5
Essential Eight (ACSC) 8.5 (MFA), 8.8 (patching), 8.2 (admin privileges), 8.7 (malware), 8.13 (backups)
Security of Critical Infrastructure Act 2018 5.5, 5.7, 5.29, 5.30

Deploy to GitHub Pages

# Clone or fork this repo
git clone https://github.com/<your-username>/iso27001-grc-tool.git
cd iso27001-grc-tool

# No build step needed — static files only
# Enable GitHub Pages: Settings → Pages → Branch: main / root

# Your tool will be live at:
# https://<your-username>.github.io/iso27001-grc-tool

Use Your Own Data

To run the questionnaire against your own organisation:

  1. Open questionnaire.html in a browser
  2. Answer all 10 questions
  3. Click Generate ISO 27001 Assessment → export JSON
  4. (Coming in v2) Import responses into index.html to override the demo dataset

Roadmap

  • Questionnaire → assessment integration (import responses into main tool)
  • Statement of Applicability (SoA) draft generation
  • Remediation tracking (mark gaps as in-progress / resolved)
  • Multi-framework mapping (ISO 27001 ↔ NIST CSF ↔ Essential Eight)
  • AI-assisted remediation suggestions (Claude API integration)
  • Evidence upload and re-scoring

Knowledge Base

The iso27001_annex_a_controls.json knowledge base covers all 93 Annex A controls with:

  • Control objective
  • Evidence examples (what an auditor looks for)
  • Risk if missing (business impact)
  • Remediation hints (actionable steps)
  • Typical owner (CISO, IT, Legal, HR, Facilities)
  • Essential Eight mapping
  • NIST CSF mapping

About

Built as a GRC portfolio project demonstrating:

  • ISO 27001:2022 Annex A domain knowledge (all 93 controls)
  • Gap analysis methodology and control status reasoning
  • Risk rating logic (context-weighted, not static)
  • Australian regulatory context (Privacy Act, NDB, APRA CPS 234, Essential Eight)
  • Structured output design suitable for audit reporting

Author: Jack Chen Target roles: GRC Analyst · Security Consultant · Technology Risk Analyst · AppSec Analyst Location: Melbourne, VIC, Australia


All company data in this tool is fictional and created for demonstration purposes only.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages