run your ISO 27001 information security management system in one place: controls, security measures, risks, action plans and audits
Deming is an open source information security management system (ISMS) and governance, risk and compliance application. Security and compliance teams use it to run an ISO 27001 programme in one place: maintain the catalogue of security controls and the security measures that implement them, record and score risks, plan and track remediation actions, run internal audits and record observations, and report on the maturity of the whole management system. The ISO 27001:2022 control set ships pre-loaded, and the product also carries ISO 27001:2013, ISO 22301, DORA, NIS2, PCI DSS 4.0 and NIST 800-53 ready to import.
cloudimg ships the full Deming application assembled and hardened, served by nginx and PHP 8.4 with MariaDB, with the ISO 27001:2022 controls already imported, so a working ISMS answers within minutes of launch. There is no shared credential in the image: it carries no environment file, no application encryption key and no database schema, so the documented default administrator account does not exist in the image. On first boot each instance mints its own encryption key, database password and administrator password, imports the controls, rotates the seeded administrator to that per instance password and scrambles the demonstration accounts, then proves the defaults are dead before it will serve. The web server and PHP runtime are gated on a bootstrap marker, and public self registration is disabled, so an unprovisioned instance can never be reached.
Real screenshots taken while testing this image against its deployment guide.