Skip to content

Supporting registers

An ISMS rests on a handful of maintained lists: what you’re protecting, what you must comply with, which documents are controlled, and what you’re aiming for. Keel gives each its own register.

In Information assets, inventory your information and associated assets, each with a type (information, software, hardware, service, people, facility), a classification (public, internal, confidential, restricted), an owner, a location/hosting note, and a CIA rating (confidentiality, integrity, availability — low / moderate / high). This is Annex A 5.9 (inventory) and 5.12 (classification), and it’s the foundation your risks, controls, and Statement of Applicability trace back to. Assets can be retired.

In Legal & regulatory, track the obligations that apply to you — legal, statutory, regulatory, or contractual — each with a jurisdiction, a citation/reference, an accountable owner, and a compliance status (not assessed, met, partially met, not met). This is the Annex A 5.31 register: identify each obligation and show how you meet it.

In Documented information, keep the controlled master list of every document the ISMS depends on. Register each item with a document code, type (policy, procedure, work instruction, form, record, and more), classification, version, lifecycle status (draft through published to obsolete/withdrawn), owner, approver, where the controlled copy lives, a review cadence with a next-review date (flagged overdue / due soon), a retention rule, and a distribution note.

It also carries a document-awareness loop: add required readers who must acknowledge a document, and publishing a new version resets every reader to pending so they re-acknowledge the change. This register is the master index; the Policies module holds the authored policy bodies.

In Objectives & KPIs, set measurable information-security objectives, each with a metric, a baseline, a target, a current value, an owner, and a target date, then track it to On track / At risk / Achieved / Missed. This is the measurable, monitored objective Clause 6.2 asks for — a target to steer the program by, not just controls to maintain.

Keel keeps a few more registers that support the ISMS from adjacent parts of the app:

  • Risk scenario library (under Controls & risk): starter information-security risk scenarios with suggested inherent likelihood × impact and the Annex A control areas that typically treat each — add the ones that apply to your risk register.
  • AI services register (AI governance): an inventory of vetted AI systems with purpose, data categories, an EU AI Act risk tier, and an approval status — the record ISO 42001 and the EU AI Act expect.
  • KEV catalog: CISA’s Known Exploited Vulnerabilities feed, backing vulnerability-management and continuous-monitoring controls.
  • Automated checks: credential-free monitors for TLS, security headers, SPF, and DMARC that run on a schedule and record pass/fail as living evidence for a linked control.