Skip to main content

ISO/IEC 27001 · ISO/IEC 42001 readiness

Know exactly where you stand on ISO 27001 and ISO 42001.

Choose your certification, connect your own Microsoft 365 in a click, and Security Flare lines your Conditional Access, Intune, and audit data up against the standard — control by control — so you can see how far you are from compliant and what's left to do. Built for Australian businesses, data kept onshore.

ISO 27001 · Annex A controls
93
ISO 42001 · Annex A controls
38
  • ISO 27001 · ISO 42001 · Essential 8 crosswalk
  • Sydney (ap-southeast-2) data residency

From sign-up to where-you-stand in three steps.

No consultants, no spreadsheets. Connect your own Microsoft 365 once; for ISO 27001 the evidence flows in automatically, and for both frameworks a guided readiness view shows you exactly where you sit.

Step 1 of 3

Choose your certification

Pick ISO 27001 for information security, ISO 42001 for AI management, or both. Your control catalogue, policies, and readiness view all follow your choice — switch any time.

Step 2 of 3

Connect your Microsoft 365

One admin consent connects your own tenant, read-only. Security Flare pulls Conditional Access, Intune device posture, sign-in and audit logs, and Secure Score — no agents to install.

Step 3 of 3

See where you sit

Every signal maps to the control it satisfies, scored in a live readiness heat map. Generate branded, auditor-ready policies and export your Statement of Applicability when it's time.

Everything the audit asks for, in one place.

Two frameworks, one platform

ISO 27001 for information security and ISO 42001 for AI management. Hold one or both, and switch between them in a click — the whole app follows your active framework.

Australian data residency

Hosted in Sydney (ap-southeast-2). Mindful of the Privacy Act 1988 and the OAIC Notifiable Data Breaches scheme so the 30-day clock isn't a surprise.

Essential 8 crosswalk built in

Every Annex A control carries the Essential 8 strategy it overlaps with — so the same evidence work satisfies two frameworks at once. No retro-mapping later.

Branded, auditor-ready policies

Generate your full policy set as branded, tailored .docx documents — each a controlled document with document control, defined scales, and version history, in your own colours.

Tamper-evident evidence

Every evidence file is hashed and the hash is in the audit log. Object Lock prevents in-place rewrites for the seven-year retention window an audit expects.

Evidence runs on schedule, not on prayer

For ISO 27001, evidence is pulled from your tenant automatically every night, hashed, and stored — a clean run log for the auditor, with no manual collection.

Ready to see where you stand?

Sign in with your Microsoft work account to connect your own tenant, or browse the full control catalogue first to see what Security Flare measures.