Onset: Bringing an ISO 27001 System out of SharePoint and into Confluence

Onset: Bringing an ISO 27001 System out of SharePoint and into Confluence

Published on 24 September, 2026 by Sofia KargiotiSofia Kargioti

Onset, a Greek company founded in 2017 in Serres, builds software for distribution companies and runs an ISO/IEC 27001 information security management system (ISMS) as part of that operation. Their work covers SoftOne ERP, a warehouse management system shaped for the Greek market, and mobile services for ordering, merchandising, routing, and proof of delivery. On a working day, more than 1,500 people use those mobile services.

The system was already in use. The place it lived was easy to miss.

For years, the ISO documentation sat in a restricted shared folder on Microsoft SharePoint. Policies, procedures, and records were there, available to the people who had access to that folder. Reaching them meant knowing the folder existed and having permission to open it. A management system kept in a restricted shared folder is hard to keep current across the team, and hard to walk through when an auditor asks to see it.

Confluence for the user manual, SharePoint for the processes

Onset was already using Confluence for their product user manual. However, their official ISO processes were stored in a restricted SharePoint folder.

We moved those processes into a dedicated Confluence Cloud space set up for ISO/IEC 27001:2022. By doing so, the user manual and the processes now sit in the same tool. A policy, the process that applies it, and the latest record are pages the whole team can access.

How we carried out the migration

The move was carried out by respecting and following the document management control process of the ISMS. It had two stages.

  1. Initial content transfer. We moved each process from the restricted SharePoint folder into the new Confluence Cloud space. The content stayed the same: the same text, the same document code, and the same revision.
  2. Review and optimization. The next revision was raised in that same Confluence space, and the further changes were made there. That revision brought procedures that described the same work into one page, filed the current record with the procedure that calls for it, linked each catalogue entry to the current page, and gave every policy and procedure a visible identity on the page: document code, first issue, current revision, and the date of the last update.

What got better

The person responsible for information security gained a system they can run from one place.

One home for the processes. The processes left the restricted SharePoint folder and now sit in Confluence, next to the user manual the company already used. Finding a process, updating it, and showing it in an audit all happen in the same tool.

Fewer processes to maintain. Processes that described the same work were merged. Now, there is only one page to keep up to date.

The record sits with the process. Training, objectives, supplier reviews, internal audit, and management review were already happening. The current record now sits next to the process that asks for it.

A list that opens the page. Each row in the document list opens the current process, with its document code and revision on the page.

Day to day, the work is simpler: open Confluence, find the process, update it as a new revision, and walk someone through it without asking for access to a separate folder.

What the audit made easier to show

During the external audit, the person responsible for information security could instantly open and present evidence within Confluence. Several key records became easier to track and show.

Equipment tracking. The equipment list now shows what each item is, when it was last checked, how it is maintained, and when the supplier's support ends. The next check is set before that support ends.

Proof that people have read the policies. Onboarding records show which procedures and policies were given to new people who joined the company, and when they received their equipment.

Cloud suppliers. Cloud services are evaluated in the same way as other suppliers, using a short checklist and direct links to the supplier's certificates.

Access for a new colleague. There is now a known record that says who approves user access rights and what specific access is granted to each team member.

In the next audit, the person who will be responsible for information security will open these pages and show the record, without searching a separate folder.

For a team whose ISO set still sits in SharePoint

A restricted shared folder on SharePoint can hold an entire Information Security Management System but still be the wrong place for it. The employees following a procedure, and the auditor who's reviewing the record, should be looking at the same page.

A move to Confluence pays off when it is treated as an opportunity to also review and clean up the documentation:

  • Merge procedures that cover the same task.
  • File the current record beside the procedure.
  • Display document codes, revision numbers, and dates on the page, so an export stays readable.
  • Use the auditor's observations as a checklist for the year ahead: equipment and support dates, proof that policies were read, a visible review of cloud suppliers, and a clear path for access.

Onset's ISMS was already functional, but moving to Confluence transformed it into a truly collaborative system the entire team can easily access, update, and present during audits.

If you are looking to make a similar shift for your own ISMS, explore our Information Security & Data Protection (ISO 27001) consulting service. Our suggested workspace structure is built based on our ISO/IEC 27001:2022 template for Confluence Cloud.