Notifications
Clear all
Topic starter
16/07/2026 1:32 pm
Looking at ISO 27001 automation tools. Tugboat Logic keeps coming up, but most reviews are generic GRC. Need specifics for the ISMS build-out.
Has anyone here actually used it to:
* Map controls directly to Annex A, especially for a cloud-native stack?
* Handle evidence collection for things like Terraform state or K8s configs?
* Generate the SoA and other mandatory docs without endless tweaking?
Mainly want to know if it saves real time over a wiki+spreadsheet approach, or if it's just another layer to manage. Pricing feedback for a mid-sized engineering org would also be useful.