82ISMS · Health
Controls
78
Risks
88
Policies
91
Evidence
74
Audits
80
Actions
79
A directional blend of control implementation, risk exposure, overdue items and policy governance — not an audit metric.
Needs your attention
5 ITEMSOVERDUE
→A.8.24 Use of cryptography — evidence expired
FRAMEWORK · Owner: Priya · 3 days overdue
OVERDUE
→RSK-018 Third-party data leak — treatment plan missing
RISK · Owner: Sofia · 1 day overdue
DUE SOON
→Password Policy v2 acknowledgment closes tomorrow
POLICY · 48/62 acknowledged · 14 pending
DUE SOON
→Q4 Internal Audit — cryptographic controls
AUDIT · Scheduled Feb 03 · 2 sessions
FLAGGED
→New CAPA opened — CAPA-042 phishing simulation gap
CAPA · Awaiting root-cause analysis
Risk heatmap
5×5Low
Med
High
High
1
3
2
Med
4
5
2
Low
3
2
1
← ImpactLikelihood ↑
Annex A by theme
VIEW ALL →A.5Organizational30/36 · 1 EX
A.6People6/8
A.7Physical10/13 · 1 EX
A.8Technological22/32 · 2 EX
Modules
12 · TOTAL01→
142
Assets
02→
38
Vendors
03→
87
Personnel
04→
6
Incidents
05→
12
Internal Audit
06→
9
CAPA
07→
4
Mgmt Review
08→
5
Continuity
09→
11
Training
10→
22
Legal
11→
8
Objectives
12→
341
Evidence
— ACTION REQUIRED
3 policies to acknowledge
Published and awaiting your confirmation.
Cryptography Policy v3.0
Password Policy v2
Data Retention Policy
Upcoming
90 · DAYSFeb
3
Internal audit · A.8
AUDIT
Feb
15
Access review · Production
OPS
Feb
28
Management review Q1
REVIEW
Mar
11
Vendor risk refresh
VENDORS
Recent activity
Priya Menon published a policy Cryptography Policy v3.0
2h ago
Sofia Reyes created a risk RSK-021 Cloud misconfig
5h ago
James Ochieng approved a policy version Access Control v2.1
Yesterday
Aditi Rao acknowledged a policy Password Policy v2
Yesterday
System seeded sample data 20 sample risks
2 days ago