# XGRC® MSXCyber®

_Information Security Governance_

**ISO 27001 compliance without the spreadsheet chaos.**

MSXCyber® delivers a complete Information Security Management System aligned to ISO 27001:2022 — with governance, risk management, and audit-ready evidence built in from day one. Data breaches now carry material financial, regulatory and operational consequences — structured ISMS governance is no longer optional.

## What it is

ISMS software helps organisations manage information security governance, risk assessment, controls, incidents, internal audits and evidence required to support an ISO 27001-aligned Information Security Management System.

## Overview

MSXCyber® implements the full plan-do-check-act cycle for information security — from asset registration and risk assessment through control implementation, incident management, internal audit, and management review — on a single governed platform.

## When organisations use it

Organisations typically adopt MSXCyber® when ISO 27001 evidence, asset inventories and incident response plans are still managed through spreadsheets and email — and they need continuous, audit-ready ISMS governance rather than a scramble before each certification review.

## What it is not

MSXCyber® supports information security governance and ISO 27001-aligned management processes. It does not replace technical security tools such as firewalls, endpoint protection, vulnerability scanners or SIEM platforms — for offensive security testing and vulnerability scanning, XGRC® partners with Hakware.

## Challenges it addresses

- **ISO 27001 gaps only found at audit** — Without continuous monitoring, control weaknesses accumulate quietly between certification reviews.
- **Asset inventories in spreadsheets** — Assets undocumented, risks unassessed. One security incident reveals just how fragile the inventory actually is.
- **No structured incident response** — When a breach occurs, the response is improvised. Regulatory disclosure obligations are missed. Costs escalate.
- **GDPR and POPIA obligations untracked** — Data protection compliance managed through email threads — no evidence trail, no audit readiness.

## Modules

- **Security Operations:** Asset Register, Monitoring, Inspections, Broadcasting, Event Management
- **Risk & Controls:** Risk Assessments, Non-Conformances, Change Management, Strategies
- **Governance & Compliance:** Audits, Document Control, Legal Compliance, Objectives & Targets
- **People & Communication:** Training, Stakeholder Management, Meeting Manager

## Standards & frameworks

- ISO 27001:2022
- GDPR
- POPIA
- NIS Directive

## Frequently asked questions

### Does MSXCyber® replace our firewall or antivirus software?

No. MSXCyber® governs your ISMS — risk, controls, incidents and audit evidence. It does not replace technical security tools; it governs the processes around them.

### Is MSXCyber® aligned to ISO 27001:2022?

Yes. MSXCyber® implements the full plan-do-check-act cycle aligned to ISO 27001:2022, alongside GDPR, POPIA and NIS Directive requirements.

### Can MSXCyber® help with GDPR and POPIA compliance?

Yes. MSXCyber® links data protection obligations, processing records and incident response to the same ISMS governance framework.

### How does MSXCyber® relate to Hakware?

MSXCyber® governs your ISMS; Hakware is a partner solution that provides AI-powered penetration testing and vulnerability visibility. Findings from Hakware feed directly into MSXCyber® as governed risks and actions.

## Related solutions

- [MSX®](https://xgrcsoftware.com/msx)
- [Enterprise Risk Management](https://xgrcsoftware.com/erm)
- [MAIA®](https://xgrcsoftware.com/maia)

---

Source: https://xgrcsoftware.com/msxcyber
