
Sofia KargiotiOnset, a Greek company founded in 2017 in Serres, builds software for distribution companies and runs an ISO/IEC 27001 information security management system (ISMS) as part of that operation. Their work covers SoftOne ERP, a warehouse management system shaped for the Greek market, and mobile services for ordering, merchandising, routing, and proof of delivery. On a working day, more than 1,500 people use those mobile services.
The system was already in use. The place it lived was easy to miss.
For years, the ISO documentation sat in a restricted shared folder on Microsoft SharePoint. Policies, procedures, and records were there, available to the people who had access to that folder. Reaching them meant knowing the folder existed and having permission to open it. A management system kept in a restricted shared folder is hard to keep current across the team, and hard to walk through when an auditor asks to see it.
Onset was already using Confluence for their product user manual. However, their official ISO processes were stored in a restricted SharePoint folder.
We moved those processes into a dedicated Confluence Cloud space set up for ISO/IEC 27001:2022. By doing so, the user manual and the processes now sit in the same tool. A policy, the process that applies it, and the latest record are pages the whole team can access.
The move was carried out by respecting and following the document management control process of the ISMS. It had two stages.
The person responsible for information security gained a system they can run from one place.
One home for the processes. The processes left the restricted SharePoint folder and now sit in Confluence, next to the user manual the company already used. Finding a process, updating it, and showing it in an audit all happen in the same tool.
Fewer processes to maintain. Processes that described the same work were merged. Now, there is only one page to keep up to date.
The record sits with the process. Training, objectives, supplier reviews, internal audit, and management review were already happening. The current record now sits next to the process that asks for it.
A list that opens the page. Each row in the document list opens the current process, with its document code and revision on the page.
Day to day, the work is simpler: open Confluence, find the process, update it as a new revision, and walk someone through it without asking for access to a separate folder.
During the external audit, the person responsible for information security could instantly open and present evidence within Confluence. Several key records became easier to track and show.
Equipment tracking. The equipment list now shows what each item is, when it was last checked, how it is maintained, and when the supplier's support ends. The next check is set before that support ends.
Proof that people have read the policies. Onboarding records show which procedures and policies were given to new people who joined the company, and when they received their equipment.
Cloud suppliers. Cloud services are evaluated in the same way as other suppliers, using a short checklist and direct links to the supplier's certificates.
Access for a new colleague. There is now a known record that says who approves user access rights and what specific access is granted to each team member.
In the next audit, the person who will be responsible for information security will open these pages and show the record, without searching a separate folder.
A restricted shared folder on SharePoint can hold an entire Information Security Management System but still be the wrong place for it. The employees following a procedure, and the auditor who's reviewing the record, should be looking at the same page.
A move to Confluence pays off when it is treated as an opportunity to also review and clean up the documentation:
Onset's ISMS was already functional, but moving to Confluence transformed it into a truly collaborative system the entire team can easily access, update, and present during audits.
If you are looking to make a similar shift for your own ISMS, explore our Information Security & Data Protection (ISO 27001) consulting service. Our suggested workspace structure is built based on our ISO/IEC 27001:2022 template for Confluence Cloud.