ISO 27001 coverage that survives the certification audit
Every requirement and information security control mapped to an owner, the risk assessment linked to treatment decisions, and the evidence an auditor will ask for already in place.
Compliance at a glance
What ISO 27001 requires
Statement of Applicability from live data
Every information security control carries its applicability decision, justification and implementation status. Dimeri generates the SoA as a report rather than a separate spreadsheet.
Risk to control to evidence in one chain
Each selected control traces back to the risk that justified it, with test results showing it operates. The auditor sees the full chain on screen.
Shared credit across frameworks
A control satisfying both ISO 27001 and POPIA is written once and counted in each. Dimeri eliminates duplicate work for organisations running multiple certifications.
Surveillance audits without the scramble
Scheduled control tests, internal audits and management reviews keep the system visibly running. Evidence exists with its dates, not assembled the week before.
ISO 27001 compliance, covered by default
The foundational parts of ISO 27001 are built in, from policies and people processes to continuous monitoring, so you don't spend time assembling the basics.
Policy templates
Ready-to-use, auditor-approved policies that match your environment automatically. No writing required.
Employee and device compliance
Automated onboarding, training, access checks, and device validation, all handled without manual follow-up.
Continuous monitoring
Always-on checks that flag issues instantly so you stay ISO-aligned without extra effort.
One-click trust centre
A clean, customer-ready Trust Center pre-populated with your certifications, policies, controls, and security status.
Vendor security oversight
Track vendors, their security details, and breach alerts in one place. Clean, ready evidence for vendor monitoring.
What Dimeri tracks
Dimeri holds the management system requirements and the full control set in one structure, so the Statement of Applicability is generated rather than maintained by hand.
Context, scope and leadership
The organisation and its interested parties understood, the ISMS scope defined and defensible, and top management demonstrably accountable for it.
- Scope statement held with its boundaries and exclusions
- Interested parties and their requirements recorded
- Information security policy with approval and review dates
- Roles and responsibilities assigned to named individuals
Risk assessment and treatment
A defined and repeatable risk assessment method, applied consistently, with a treatment decision recorded for every risk.
- Assessment criteria and acceptance thresholds configured once
- Risks to confidentiality, integrity and availability scored
- Treatment option and owner recorded per risk
- Residual risk accepted by an accountable person
Statement of Applicability
Every information security control listed with its applicability, the justification for inclusion or exclusion, and its implementation status.
- All 93 information security controls held as a single register
- Justification recorded against each decision
- Implementation status derived from control evidence
- SoA exported for the auditor from live data
The control set
Organisational, people, physical and technological controls, each with an owner and evidence that it operates rather than that it exists.
- Controls mapped to the risks they treat
- Test schedule and results per control
- Evidence attached at the point the control runs
- Shared controls credited to POPIA and other frameworks
Support and operation
Competence, awareness, communication and documented information, plus the operational planning and control that keeps the system running.
- Awareness training tracked to the individual
- Document control with versions and review dates
- Change and supplier processes held as controls
- Operational records retained against their requirement
Evaluation and improvement
Monitoring and measurement, internal audit, management review, and nonconformity and corrective action.
- Internal audit programme covering the whole ISMS
- Management review inputs assembled through the year
- Nonconformities tracked to closure with root cause
- Effectiveness measures reported rather than asserted
Getting ISO 27001 coverage in place
4 steps from where you are today to a ISO 27001 position your auditor can rely on.
Book a demoScope is the decision that shapes everything after it. Too narrow and the certificate is worth little commercially; too broad and the first certification becomes unmanageable. It is recorded with its boundaries and its exclusions so the auditor sees the reasoning.
How Dimeri covers ISO 27001
The Statement of Applicability writes itself
Because every information security control carries its applicability decision, justification and implementation evidence in one place, the SoA is a report. Maintaining it as a separate spreadsheet is how it drifts out of step with reality between audits.
Risk to control to evidence, in one chain
The standard expects the controls you selected to trace back to the risks that justified them. Dimeri holds that link directly, so the auditor's question about why a control exists has an answer on screen.
Shared credit with POPIA
A control satisfying ISO 27001 and POPIA is written once and counted in both. For South African organisations doing ISO 27001 and POPIA together, that overlap is most of the work.
ISO 27001 questions
How many controls are in ISO 27001?
The current edition contains 93 controls grouped into four themes: organisational, people, physical and technological. The previous edition had 114 controls across a different structure. Organisations transitioning need to map their existing controls onto the new structure, which Dimeri holds as a single register either way.
What is the Statement of Applicability?
It is the document listing every information security control, whether it applies to your ISMS, the justification for including or excluding it, and whether it is implemented. It is usually the first document an auditor asks for, and the one most likely to have drifted out of date when it lives in a separate spreadsheet.
Can Dimeri get us certified?
No platform can. Certification is granted by an accredited certification body after a two stage audit. What Dimeri does is hold the management system so the evidence the auditor asks for already exists, which is where most first attempts lose time.
How does ISO 27001 relate to POPIA?
POPIA requires appropriate, reasonable technical and organisational measures and refers to generally accepted information security practices. ISO 27001 is the most commonly cited expression of those practices in South Africa. Dimeri maps a control once and credits it to both, which is why organisations running the two together do far less duplicate work.
Is this a substitute for the standard itself?
No. ISO 27001 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to certify against it. This page describes how Dimeri holds the management system.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.