Roadmap

What's live, what's next, and what we're exploring.

ISO 360 Plus is built to grow one register at a time, each one mapped to a specific ISO/IEC 27001 clause or Annex control.

Live now

Live

Asset Register

Full asset catalogue with ownership, CIA ratings, and scheduled reviews.

Annex A.5.9 - Inventory of information and other associated assets
Live

Risk Register

Risk scoring, treatment tracking, and residual risk comparison.

Clause 6.1.2 / 8.2 - Information security risk assessment

Next in line

Planned

Incident Register

Capture, triage, and close out information security incidents with a full audit trail.

Annex A.5.24–A.5.28
Planned

Supplier Register

Track supplier risk, due diligence, and contractual security requirements.

Annex A.5.19–A.5.22
Planned

Policy Register

Centralise policy documents, versions, approvals, and review cycles.

Clause 5.2 / Annex A.5.1

Further candidates

Statement of Applicability

Track applicable controls and justification in one living document.

Clause 6.1.3(d)

Non-Conformity & CAPA

Log non-conformities and manage corrective actions to closure.

Clause 10.1

Internal Audit

Plan, schedule, and record internal audit findings.

Clause 9.2

Access Review

Periodic reviews of user access rights across systems.

Annex A.5.18

Training & Awareness

Track security awareness training completion by role.

Annex A.6.3

Legal & Regulatory

Maintain a register of applicable legal and contractual requirements.

Annex A.5.31 / A.5.34

Business Continuity

Track continuity plans, tests, and readiness status.

Annex A.5.29–A.5.30

Vulnerability & Patch Mgmt

Track known vulnerabilities and patch status across assets.

Annex A.8.8

Want a register prioritised?

Tell us which part of your ISMS is the biggest gap today, and we'll factor it into the roadmap.