GRCDog

No signup · Real product content

This is what a control looks like inside GRCDog.

ISO 27001 has 93 Annex A controls. Here are two of them (access control and logging) exactly as the workbench presents them: the requirement in plain language, plus concrete examples of the evidence an auditor would actually accept. Not a mockup; this is the same content signed-in users work through.

Annex A 5.15Organizational controls

Access control

Decide who may reach what — written entitlement rules covering both buildings and systems, driven by business need.

What conforming evidence looks like

  • Access-control policy defining need-to-know/least-privilege rules, approved and versioned
  • Role-based access model or permission matrix mapping roles to systems and privileges
  • Access-request workflow record (ticket) showing approval before granting
Annex A 8.15Technological controls

Logging

Record security-relevant activity, guard the logs against tampering, and actually review them.

What conforming evidence looks like

  • Logging standard: what events are logged per system (auth, admin actions, errors)
  • Central log platform retention configuration matching policy — or, without a central platform: logging config export or screenshot from primary systems (e.g. CloudTrail, Google Workspace audit, GitHub audit log) with retention settings (e.g. 90 days in cloud)
  • Log-access restrictions and tamper protection evidence (append-only, restricted queries) — or, for smaller teams: evidence log access is restricted to admins (IdP permission or sharing setting)

Seed guidance drawn from ISO/IEC 27002:2022 practice — refine to match your organization. Not audit advice.

The other 91 controls work the same way.

Inside the workbench, every control gets this treatment, plus a status you can track, evidence you can attach, and readiness reports you can hand to leadership or an auditor. New to ISO 27001? A short setup wizard turns the standard into a simple readiness project for your team.

Already have an account? Log in