Business Operations
Keep your security and compliance records in one place, up to date and ready for the auditor.
Frameworks such as ST4S and ISO 27001 ask you to show your work: who owns each control, which risks you carry, who has access to what, who has done their training and what you did when something went wrong. Most small teams keep this in spreadsheets and shared folders that drift out of date between audits. Business Operations is the portal MAICEM built to run its own security and compliance, and it can be set up for your business, with the registers, runbooks and review dates kept together so the evidence is current when someone asks for it.
Why it exists
An audit asks for evidence across many areas at once, and that evidence is only as good as the last time someone updated it. Business Operations gives every register an owner and a next review date, so an overdue review shows up on the dashboard and the calendar, not in the audit.
What you can see
- Open incidents, open risks, training completion, access reviews and supplier reviews due, on one dashboard
- Everything overdue or due in the next 30 days, across every register, and a calendar of it
- ST4S and ISO 27001 controls with status, owner, response and the policy that covers each, including the ISO Statement of Applicability
- An activity log of every change and who made it
What you can do
- Keep risk, controls, supplier, access, training, product version and key storage registers (names and locations of keys only, never the keys)
- Run incident response, data breach, backup, access review and other runbooks as forms, with a saved history of every run
- Send simulated phishing emails, see who clicks and who reports, and let staff report suspicious messages
- Export ST4S and ISO 27001 controls to CSV or Excel, and set what each role can see and change