Scrydon
Examples

ISO yearly review

Annual ISMS / AIMS review template — pentest SOW, IRP tabletop, management review, audit pack.

The ISO yearly review process template models the annual review and assurance cycle expected by ISO 27001 and ISO 42001.

What it provides

ArtefactPurpose
Pentest SOWScope of work for the annual penetration test.
IRP tabletop scenarioIncident-response plan tabletop exercise script.
Management review packThe materials for the annual management review.
Audit pack manifestA manifest of evidence assembled for the external audit.

Setup

  1. Install the ISO yearly review process template from the marketplace.
  2. Create a workflow instance for the current year.
  3. Assign reviewers and approvers.
  4. Set the milestone dates (pentest, tabletop, management review, audit).

The flow

Year start


[Issue pentest SOW] → [Pentest report] → [Remediation tracking]


[Schedule IRP tabletop] → [Tabletop execution] → [Lessons learned]


[Assemble management review pack] → [Management review] → [Decisions]


[Build audit pack] → [External audit] → [Audit response]

Sample data

Ships with:

  • 01-pentest-sow.md — example pentest scope of work.
  • 02-irp-tabletop-scenario.md — example tabletop script.
  • 03-management-review-pack.md — example review pack.
  • 04-audit-pack-manifest.md — example audit pack manifest.

Compliance mapping

  • ISO 27001 clause 9.3 (management review), clause 9.2 (internal audit).
  • ISO 42001 clause 9.3 (management review), clause 9.2 (internal audit).
  • SOC 2 CC9 (risk mitigation), CC7 (system operations).
  • EU AI Act Article 15 (cybersecurity).
On this page

On this page