ISMS_METRICS_DASHBOARD.md
July 17, 2026 Β· View on GitHub
π Hack23 AB β ISMS Metrics Dashboard
Real-Time Policy Health Monitoring
Automated Review Tracking β’ Compliance Coverage β’ Proactive ISMS Management
π Document Owner: CEO | π Version: 1.1 | π€ Last Generated: 2026-07-17 07:52 UTC
π Update Frequency: Weekly (Automated) | π Data Source: All ISMS *.md files
π― Purpose Statement
Hack23 AB's ISMS Metrics Dashboard provides real-time visibility into our Information Security Management System health through automated policy review tracking and compliance monitoring. This dashboard embodies our π transparency principle - making our security governance posture publicly visible demonstrates operational excellence and proactive risk management.
Our automated metrics collection eliminates manual policy tracking overhead, enabling π° cost efficiency through reduced administrative burden while ensuring π‘οΈ risk reduction through proactive identification of overdue reviews. This systematic approach to ISMS governance showcases the π competitive advantage of our cybersecurity consulting methodology.
By maintaining π live ISMS monitoring with β‘ automated weekly updates, we demonstrate the operational maturity that our consulting clients expect.
β James Pether SΓΆrling, CEO/Founder
π¦ Review Status Summary
Current Status as of 2026-07-17:
| Status | Count | Description |
|---|---|---|
| π΄ Overdue | 1 | Policy reviews past their due date - immediate action required |
| π‘ Due Soon (< 30 days) | 6 | Policy reviews approaching deadline - plan review activities |
| π’ Current | 35 | Policy reviews on schedule - no immediate action needed |
| π Total Documents | 42 | Total active ISMS policy documents |
π¨ Overdue Policy Reviews - Action Required
- FUTURE_WORKFLOWS.md - 42 days overdue (Due: 2026-06-05)
π¨ Oversized Documents Alert
Documents exceeding 40KB threshold requiring consolidation:
| Document | Current Size | Status | Recommendation |
|---|---|---|---|
| Compliance_Checklist.md | 243 KB | π΄ Oversized | Split into focused sub-documents |
| Secure_Development_Policy.md | 142 KB | π΄ Oversized | Split into focused sub-documents |
| Information_Security_Strategy.md | 122 KB | π΄ Oversized | Split into focused sub-documents |
| Risk_Register.md | 107 KB | π΄ Oversized | Split into focused sub-documents |
| SUPPLIER.md | 100 KB | π΄ Oversized | Split into focused sub-documents |
| Security_Metrics.md | 96 KB | π΄ Oversized | Split into focused sub-documents |
| Vulnerability_Management.md | 82 KB | π΄ Oversized | Split into focused sub-documents |
| Threat_Modeling.md | 79 KB | π΄ Oversized | Split into focused sub-documents |
| OWASP_LLM_Security_Policy.md | 79 KB | π΄ Oversized | Split into focused sub-documents |
| Incident_Response_Plan.md | 77 KB | π΄ Oversized | Split into focused sub-documents |
| ISO_5230_Self_Certification.md | 69 KB | π΄ Oversized | Split into focused sub-documents |
| Open_Source_Policy.md | 68 KB | π΄ Oversized | Split into focused sub-documents |
| Asset_Register.md | 68 KB | π΄ Oversized | Split into focused sub-documents |
| CLASSIFICATION.md | 62 KB | π΄ Oversized | Split into focused sub-documents |
| Data_Classification_Policy.md | 61 KB | π΄ Oversized | Split into focused sub-documents |
| Partnership_Framework.md | 60 KB | π΄ Oversized | Split into focused sub-documents |
| Business_Continuity_Plan.md | 53 KB | π΄ Oversized | Split into focused sub-documents |
| Risk_Assessment_Methodology.md | 52 KB | π΄ Oversized | Split into focused sub-documents |
| Network_Security_Policy.md | 51 KB | π΄ Oversized | Split into focused sub-documents |
| Third_Party_Management.md | 50 KB | π΄ Oversized | Split into focused sub-documents |
| SWOT.md | 50 KB | π΄ Oversized | Split into focused sub-documents |
| CRA_Conformity_Assessment_Process.md | 46 KB | π΄ Oversized | Split into focused sub-documents |
| SECURITY_ARCHITECTURE.md | 45 KB | π΄ Oversized | Split into focused sub-documents |
| External_Stakeholder_Registry.md | 42 KB | π΄ Oversized | Split into focused sub-documents |
π― Size Optimization Target: Reduce all documents to <35KB for improved maintainability and navigability.
π Consolidation Guidelines:
- Identify duplicate content across related policies
- Extract implementation details to operational documents
- Move detailed specifications to technical architecture documents
- Consolidate repetitive sections while preserving unique guidance
- Add cross-references instead of repeating content
π Upcoming Reviews (Next 90 Days)
| Review Date | Document | Review Cycle | Days Until Due | Status |
|---|---|---|---|---|
| 2026-07-25 | Backup_Recovery_Policy.md | Semi-Annual | 7 | π‘ Due Soon |
| 2026-07-25 | Disaster_Recovery_Plan.md | Semi-Annual | 7 | π‘ Due Soon |
| 2026-07-25 | Mobile_Device_Management_Policy.md | Semi-Annual | 7 | π‘ Due Soon |
| 2026-07-25 | Access_Control_Policy.md | Semi-Annual | 7 | π‘ Due Soon |
| 2026-07-25 | External_Stakeholder_Registry.md | Semi-Annual | 7 | π‘ Due Soon |
| 2026-08-01 | Security_Metrics.md | Monthly | 14 | π‘ Due Soon |
| 2026-09-05 | SWOT.md | Semi-Annual | 49 | π’ Current |
| 2026-09-05 | Business_Continuity_Plan.md | Semi-Annual | 49 | π’ Current |
| 2026-09-13 | Vulnerability_Management.md | Quarterly | 57 | π’ Current |
| 2026-09-20 | OWASP_LLM_Security_Policy.md | Quarterly | 64 | π’ Current |
| 2026-09-20 | AI_Policy.md | Quarterly | 64 | π’ Current |
| 2026-09-28 | Risk_Register.md | Quarterly | 72 | π’ Current |
π Document Health Matrix
Complete status of all ISMS documentation:
| Document | Version | Last Updated | Next Review | Review Cycle | Status | Compliance |
|---|---|---|---|---|---|---|
| FUTURE_WORKFLOWS.md | 1.2 | 2026-03-05 | 2026-06-05 | Quarterly | π΄ Overdue | ISO NIST CIS |
| Backup_Recovery_Policy.md | 1.2 | 2026-01-25 | 2026-07-25 | Semi-Annual | π‘ Due Soon | ISO NIST CIS |
| Disaster_Recovery_Plan.md | 2.3 | 2026-01-25 | 2026-07-25 | Semi-Annual | π‘ Due Soon | ISO NIST CIS |
| Mobile_Device_Management_Policy.md | 1.1 | 2026-01-25 | 2026-07-25 | Semi-Annual | π‘ Due Soon | ISO NIST CIS |
| Access_Control_Policy.md | 2.6 | 2026-01-25 | 2026-07-25 | Semi-Annual | π‘ Due Soon | ISO NIST CIS |
| External_Stakeholder_Registry.md | 1.5 | 2026-01-25 | 2026-07-25 | Semi-Annual | π‘ Due Soon | ISO NIST CIS |
| Security_Metrics.md | 3.8 | 2026-07-01 | 2026-08-01 | Monthly | π‘ Due Soon | ISO NIST CIS |
| SWOT.md | 1.3 | 2026-03-05 | 2026-09-05 | Semi-Annual | π’ Current | ISO NIST CIS |
| Business_Continuity_Plan.md | 1.4 | 2026-03-05 | 2026-09-05 | Semi-Annual | π’ Current | ISO NIST CIS |
| Vulnerability_Management.md | 3.1 | 2026-06-13 | 2026-09-13 | Quarterly | π’ Current | ISO NIST CIS |
| OWASP_LLM_Security_Policy.md | 1.5 | 2026-06-20 | 2026-09-20 | Quarterly | π’ Current | ISO |
| AI_Policy.md | 2.3 | 2026-06-20 | 2026-09-20 | Quarterly | π’ Current | ISO NIST CIS |
| Risk_Register.md | 3.9 | 2026-06-28 | 2026-09-28 | Quarterly | π’ Current | ISO NIST CIS |
| SUPPLIER.md | 1.5 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| Compliance_Checklist.md | 2.6 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| NIS2_Compliance_Service.md | 1.3 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| SECURITY_ARCHITECTURE.md | 1.3 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| Third_Party_Management.md | 2.4 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| Incident_Response_Plan.md | 1.7 | 2026-05-10 | 2026-11-10 | Semi-Annual | π’ Current | ISO NIST CIS |
| Privacy_Policy.md | 1.1 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST |
| ISMS_Transparency_Plan.md | 2.2 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Acceptable_Use_Policy.md | 1.1 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Cryptography_Policy.md | 1.2 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Physical_Security_Policy.md | 1.1 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Change_Management.md | 3.1 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Segregation_of_Duties_Policy.md | 2.1 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Network_Security_Policy.md | 2.3 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| Data_Classification_Policy.md | 2.3 | 2026-01-25 | 2027-01-25 | Annual | π’ Current | ISO NIST CIS |
| ISO_5230_Self_Certification.md | 1.0 | 2026-04-10 | 2027-04-10 | Annual | π’ Current | ISO NIST CIS |
| ISMS_QA_CHECKLIST.md | 1.3 | 2026-05-10 | 2027-05-10 | Annual | π’ Current | ISO NIST CIS |
| Risk_Assessment_Methodology.md | 2.3 | 2026-05-10 | 2027-05-10 | Annual | π’ Current | ISO NIST CIS |
| Partnership_Framework.md | 1.3 | 2026-05-10 | 2027-05-10 | Annual | π’ Current | ISO NIST CIS |
| CLASSIFICATION.md | 1.5 | 2026-05-10 | 2027-05-10 | Annual | π’ Current | ISO NIST CIS |
| Information_Security_Strategy.md | 4.7 | 2026-06-28 | 2027-06-02 | Annual | π’ Current | ISO NIST CIS |
| Asset_Register.md | 2.4 | 2026-06-02 | 2027-06-02 | Annual | π’ Current | ISO NIST CIS |
| WORKFLOWS.md | 1.2 | 2026-06-13 | 2027-06-13 | Annual | π’ Current | ISO NIST CIS |
| End-of-Life-Strategy.md | 1.0 | 2026-06-13 | 2027-06-13 | Annual | π’ Current | ISO NIST CIS |
| Information_Security_Policy.md | 2.1 | 2026-06-28 | 2027-06-28 | Annual | π’ Current | ISO NIST CIS |
| CRA_Conformity_Assessment_Process.md | 1.5 | 2026-06-28 | 2027-06-28 | Annual | π’ Current | ISO NIST CIS |
| Threat_Modeling.md | 1.6 | 2026-06-28 | 2027-06-28 | Annual | π’ Current | ISO NIST CIS |
| Secure_Development_Policy.md | 2.5 | 2026-07-12 | 2027-07-12 | Annual | π’ Current | ISO NIST CIS |
| Open_Source_Policy.md | 2.7 | 2026-07-12 | 2027-07-12 | Annual | π’ Current | ISO NIST CIS |
π Compliance Framework Coverage
Our ISMS documentation alignment with major security frameworks:
| Framework | Coverage | Documents | Percentage |
|---|---|---|---|
| ISO 27001:2022 | 42/42 | Information Security Management | 100% |
| NIST CSF 2.0 | 41/42 | Cybersecurity Framework | 97% |
| CIS Controls v8.1 | 40/42 | Center for Internet Security | 95% |
Note: All ISMS documents are designed to align with ISO 27001:2022, NIST CSF 2.0, and CIS Controls v8.1 requirements. Framework badges in individual documents indicate explicit alignment.
π Document Size Analysis
Monitor document sizes to identify consolidation opportunities and maintain optimal document length for readability and maintainability.
π Size Distribution
| Size Range | Count | Percentage | Status |
|---|---|---|---|
| π΄ Oversized (>40KB) | 24 | 57% | β Requires consolidation |
| π‘ Large (30-40KB) | 7 | 16% | β οΈ Monitor for growth |
| π’ Normal (<30KB) | 11 | 26% | β Optimal size |
Target Metrics:
- Average Document Size: 57 KB (Target: <25 KB)
- Maximum Document Size: 243 KB (Target: <35 KB)
- Oversized Documents: 24 (Target: 0)
π Detailed Size Listing
| Document | Size (KB) | Size Status | Review Status | Last Updated |
|---|---|---|---|---|
| Compliance_Checklist.md | 243 | π΄ Oversized | π’ Current | 2026-05-10 |
| Secure_Development_Policy.md | 142 | π΄ Oversized | π’ Current | 2026-07-12 |
| Information_Security_Strategy.md | 122 | π΄ Oversized | π’ Current | 2026-06-28 |
| Risk_Register.md | 107 | π΄ Oversized | π’ Current | 2026-06-28 |
| SUPPLIER.md | 100 | π΄ Oversized | π’ Current | 2026-05-10 |
| Security_Metrics.md | 96 | π΄ Oversized | π‘ Due Soon | 2026-07-01 |
| Vulnerability_Management.md | 82 | π΄ Oversized | π’ Current | 2026-06-13 |
| Threat_Modeling.md | 79 | π΄ Oversized | π’ Current | 2026-06-28 |
| OWASP_LLM_Security_Policy.md | 79 | π΄ Oversized | π’ Current | 2026-06-20 |
| Incident_Response_Plan.md | 77 | π΄ Oversized | π’ Current | 2026-05-10 |
| ISO_5230_Self_Certification.md | 69 | π΄ Oversized | π’ Current | 2026-04-10 |
| Open_Source_Policy.md | 68 | π΄ Oversized | π’ Current | 2026-07-12 |
| Asset_Register.md | 68 | π΄ Oversized | π’ Current | 2026-06-02 |
| CLASSIFICATION.md | 62 | π΄ Oversized | π’ Current | 2026-05-10 |
| Data_Classification_Policy.md | 61 | π΄ Oversized | π’ Current | 2026-01-25 |
| Partnership_Framework.md | 60 | π΄ Oversized | π’ Current | 2026-05-10 |
| Business_Continuity_Plan.md | 53 | π΄ Oversized | π’ Current | 2026-03-05 |
| Risk_Assessment_Methodology.md | 52 | π΄ Oversized | π’ Current | 2026-05-10 |
| Network_Security_Policy.md | 51 | π΄ Oversized | π’ Current | 2026-01-25 |
| Third_Party_Management.md | 50 | π΄ Oversized | π’ Current | 2026-05-10 |
| SWOT.md | 50 | π΄ Oversized | π’ Current | 2026-03-05 |
| CRA_Conformity_Assessment_Process.md | 46 | π΄ Oversized | π’ Current | 2026-06-28 |
| SECURITY_ARCHITECTURE.md | 45 | π΄ Oversized | π’ Current | 2026-05-10 |
| External_Stakeholder_Registry.md | 42 | π΄ Oversized | π‘ Due Soon | 2026-01-25 |
| FUTURE_WORKFLOWS.md | 39 | π‘ Large | π΄ Overdue | 2026-03-05 |
| AI_Policy.md | 38 | π‘ Large | π’ Current | 2026-06-20 |
| Segregation_of_Duties_Policy.md | 37 | π‘ Large | π’ Current | 2026-01-25 |
| Change_Management.md | 37 | π‘ Large | π’ Current | 2026-01-25 |
| Physical_Security_Policy.md | 36 | π‘ Large | π’ Current | 2026-01-25 |
| Access_Control_Policy.md | 36 | π‘ Large | π‘ Due Soon | 2026-01-25 |
| Privacy_Policy.md | 31 | π‘ Large | π’ Current | 2026-01-25 |
| NIS2_Compliance_Service.md | 29 | π’ Normal | π’ Current | 2026-05-10 |
| ISMS_QA_CHECKLIST.md | 29 | π’ Normal | π’ Current | 2026-05-10 |
| Cryptography_Policy.md | 29 | π’ Normal | π’ Current | 2026-01-25 |
| WORKFLOWS.md | 28 | π’ Normal | π’ Current | 2026-06-13 |
| Mobile_Device_Management_Policy.md | 28 | π’ Normal | π‘ Due Soon | 2026-01-25 |
| Disaster_Recovery_Plan.md | 28 | π’ Normal | π‘ Due Soon | 2026-01-25 |
| Acceptable_Use_Policy.md | 27 | π’ Normal | π’ Current | 2026-01-25 |
| Information_Security_Policy.md | 26 | π’ Normal | π’ Current | 2026-06-28 |
| Backup_Recovery_Policy.md | 21 | π’ Normal | π‘ Due Soon | 2026-01-25 |
| ISMS_Transparency_Plan.md | 18 | π’ Normal | π’ Current | 2026-01-25 |
| End-of-Life-Strategy.md | 7 | π’ Normal | π’ Current | 2026-06-13 |
π Size Optimization Recommendations
For documents >40KB:
- Identify duplicate content across related policies
- Extract implementation details to operational policy documents
- Move detailed specifications to technical architecture documents
- Consolidate repetitive sections while preserving unique guidance
- Add cross-references instead of repeating content
Best Practices:
- Keep policy documents focused on "what" and "why" (strategic level)
- Move "how" details to procedure documents or technical guides
- Use tables and diagrams to convey complex information concisely
- Link to related documents rather than duplicating content
- Review quarterly for opportunities to streamline
Note: Size growth >10% per quarter triggers consolidation review.
π Quality Metrics
| Metric | Status | Description |
|---|---|---|
| π Document Completeness | β 42/42 | All ISMS documents have complete metadata |
| π Review Cycle Defined | β 100% | All documents have defined review frequencies |
| π Review Dates Set | β 100% | All documents have scheduled next review dates |
| π·οΈ Version Control | β Active | All documents maintain version numbers |
| π Dashboard Automation | β Active | Weekly automated updates via GitHub Actions |
| π Size Monitoring | β οΈ 24 oversized | Automated document size tracking and alerts |
Quality Standards:
- β All documents follow STYLE_GUIDE.md formatting
- β All documents include document control footers
- β All documents reference relevant compliance frameworks
- β All documents maintained in version control (Git)
π Related Documents
- π Security Metrics Dashboard - Application-level security monitoring
- π Information Security Policy - Master security policy framework
- π Compliance Checklist - Regulatory compliance tracking
- β οΈ Risk Register - Risk identification and treatment
- π¨ Style Guide - Documentation standards
π Using This Dashboard
For Policy Owners (CEO)
- Weekly Review: Check π΄ Overdue and π‘ Due Soon sections every Monday
- Size Monitoring: Review π΄ Oversized documents for consolidation opportunities
- Quarterly Planning: Use "Upcoming Reviews (Next 90 Days)" to schedule review activities
- Compliance Audits: Reference "Document Health Matrix" for audit evidence
For Stakeholders (Clients, Auditors, Partners)
- ISMS Health: Review Status Summary for overall governance maturity
- Compliance Coverage: Verify framework alignment for regulatory requirements
- Transparency Validation: Compare dashboard dates with individual policy documents
Automation Details
- Update Frequency: Automated weekly (every Monday 08:00 UTC)
- Data Source: Metadata extracted from all *.md files in repository root
- Size Monitoring: Document sizes calculated using
wc -ccommand - Status Calculation:
- π΄ Overdue: Review date has passed
- π‘ Due Soon: Review date within 30 days
- π’ Current: Review date more than 30 days away
- Size Thresholds:
- π΄ Oversized: >40KB (requires consolidation)
- π‘ Large: 30-40KB (monitor for growth)
- π’ Normal: <30KB (optimal size)
- Generation Script:
.github/scripts/generate-metrics.sh - Workflow:
.github/workflows/update-metrics.yml
π Document Control:
β
Generated by: Automated GitHub Actions Workflow
π€ Distribution: Public (GitHub Repository)
π·οΈ Classification:
π
Last Generated: 2026-07-17 07:52 UTC
β° Next Update: Weekly (Automated)
π― Framework Compliance: