North Carolina SISM Compliance Software

The GRC Assessment Platform™ for NC SISM compliance

Isora GRC gives North Carolina executive agencies one connected workspace to operationalize the Statewide Information Security Manual. In Isora, teams can run NIST-aligned assessments, manage POA&Ms, track risks, and produce EGRC-ready reports for ESRMO oversight, all in one place.

Trusted by established organizations & partners
https://vt.eduhttps://www.af.milhttps://utexas.eduhttps://yale.eduhttps://www.tdi.texas.govhttps://www.ttuhsc.eduhttps://aws.amazon.comhttps://www.osu.eduhttps://www.wilcotx.govhttps://www.utoronto.cahttps://www.tdcj.texas.govhttps://www.uchicago.edu/enhttps://www.utah.eduhttps://dir.texas.govhttps://www.dps.texas.govhttps://www.berkeley.eduhttps://www.techstars.comhttps://cccs.eduhttps://www.iwu.eduhttps://msu.eduhttps://www.auburn.eduhttps://www.stthomas.eduhttps://www.getezmoney.comhttps://www.sait.cahttps://www.ubc.cahttps://www.cuanschutz.eduhttps://www.tjc.eduhttps://marymount.eduhttps://www.umt.eduhttps://www.pdx.eduhttps://www.tccd.eduhttps://ltu.eduhttps://morantechnology.comhttps://www.merit.eduhttps://www.tccd.eduhttps://www.gonzaga.eduhttps://www.bhc.eduhttps://www.dallascollege.edu

Problem

NC SISM distributes responsibility across dozens of agencies

North Carolina’s Statewide Information Security Manual (NC SISM) requires every executive agency to implement security programs aligned with NIST SP 800-53 and the Risk Management Framework. Agencies must conduct annual risk assessments, maintain POA&Ms in the EGRC system, submit results within 30-day windows, and complete independent or self-assessments every three years.

Responsibility is distributed — NCDIT sets policy, agency CISOs execute, security liaisons coordinate — but the tools are disconnected. Assessments live in spreadsheets, POA&Ms live in separate trackers, vendor evidence sits in shared drives organized by date instead of by policy domain, and VRARs are completed but not linked to the systems they evaluate. When ESRMO requests a status update, the agency CISO assembles a response from five different files, hoping the numbers reconcile. Spreadsheets and shared drives simply weren’t designed for the level of coordination NC SISM requires across a distributed compliance program.

Solution

One platform for the NC SISM compliance lifecycle

Isora GRC structures the workflows for executive agencies required by NC SISM in one connected workspace. Launch NIST-aligned assessments mapped to SCIO-SEC policy families, track risks, manage POA&Ms, link VRARs to asset and vendor inventories, and generate reports aligned to EGRC submission requirements. In Isora, every control, risk, and inventory item stays connected to create the verifiable compliance record ESRMO expects.

Assessments

Run NIST-aligned assessments mapped to SCIO-SEC policy families

Launch structured assessments using prebuilt questionnaires aligned to NIST SP 800-53 control families and SCIO-SEC policies 301–318. Target agency departments, systems, and data repositories. Collect evidence inline — access control documentation, encryption records, incident response procedures — so responses and proof stay connected. Support both the annual assessment requirement and the three-year independent assessment cycle with recurring campaigns.

Learn More

Inventory

Link VRARs to asset and vendor inventories

Build the inventory foundation SISM compliance requires. In Isora, every system, application, and vendor record links to its assessments, risks, POA&Ms, and documentation. Track Vendor Readiness Assessment Reports (VRARs) and third-party attestations (FedRAMP, SOC 2, ISO 27001) in the same workspace. When procurement or ESRMO asks about a vendor's security posture, the VRAR, assessment history, and risk rating are connected — not scattered across shared drives.

Risk Management

Turn SISM assessment findings into tracked POA&Ms with owners and deadlines

Publish control gaps that surfaced during the assessment directly to the risk register and POA&M tracker. In Isora, every finding carries lineage across the SCIO-SEC policy it maps to, the NIST 800-53 control it references, the assessment that surfaced it, and the system it applies to. From there, teams can assign owners, set remediation milestones, and track progress toward submitting POA&M results to ESRMO within the 30-day window.

Learn More

Reports & Scorecards

Produce EGRC-ready reports for ESRMO oversight

Generate reports that pull directly from live assessment scores, POA&M status, risk register entries, and inventory records. Demonstrate control implementation status, remediation progress, and program maturity across the agency. Produce structured outputs aligned to EGRC submission requirements and SCIO-SEC policy families. In Isora, reports export in formats ready for ESRMO review, State CIO oversight, and agency leadership briefings.

Learn More
Latest Content
Our latest content
Stay ahead of the curve with our latest research on a diverse range of topics exploring the ever-changing world of governance, risk, and compliance.

State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...

All of North Carolina SISM's (Statewide Information Security Manual) requirements, controls, implementation steps for agency compliance.

Frequently Asked Questions
North Carolina SISM Compliance FAQs
Find the answers you need here, or chat with us.
Contact Sales
What is North Carolina's SISM and who must comply?

The Statewide Information Security Manual (SISM) establishes minimum cybersecurity requirements for all North Carolina executive-branch agencies, departments, and institutions. Issued under the authority of the State CIO and enforced by ESRMO, SISM aligns with NIST SP 800-37 (Risk Management Framework) and NIST SP 800-53 Rev. 5 (Security and Privacy Controls). SCIO-SEC policies 301–318 define the control domains agencies must implement.

What are SCIO-SEC policies and how do they relate to SISM?

SCIO-SEC policies 301 through 318 translate NIST SP 800-53 control families into enforceable, North Carolina-specific standards. Each policy governs a security domain — access control, risk assessment, incident response, system integrity — and defines implementation requirements for executive agencies. Together with SISM, they form the operational framework for statewide cybersecurity compliance.

How do agencies report to ESRMO under SISM?

Agencies must submit risk assessment results and remediation plans to ESRMO within 30 days of completion through the EGRC system. Isora generates structured reports aligned to EGRC submission requirements, consolidating assessment findings, POA&M status, and continuous monitoring data into exports ready for ESRMO review.

How does Isora support North Carolina's three-year assessment cycle?

SISM requires agencies to complete independent or self-assessments at least every three years. Isora supports both approaches with NIST-aligned questionnaire templates, recurring campaign scheduling, structured evidence capture during assessments, and remediation tracking. Agencies document assessment cycles, track POA&M closure, and demonstrate continuous improvement across multiple review periods in one platform.

Can Isora handle VRARs and vendor oversight under SISM?

Yes. Isora tracks Vendor Readiness Assessment Reports (VRARs), third-party attestations (FedRAMP, SOC 2, ISO 27001), and contract controls required under SISM. Each vendor record links to associated assessments and risks, providing complete visibility into third-party compliance and supporting ESRMO vendor oversight.

How long does it take to deploy Isora for SISM compliance?

Isora deploys in weeks, not months. No-code setup, no consultants, no dedicated admin headcount. Agencies can run their first NIST-aligned assessment within days of onboarding. Prebuilt NIST SP 800-53 questionnaire templates map to SCIO-SEC policy families out of the box.

Resource
NIST 800-53 Multi-Framework Crosswalk
Map NIST SP 800-53 controls to NIST CSF 2.0, SOC 2, ISO 27001, NIST 800-171, and HIPAA, and track their implementation status, assessment objectives, and evidence, all in one place.
Access
NIST 800-53 multi-framework crosswalk Map NIST SP 800-53 controls to NIST CSF 2.0, SOC 2, ISO 27001, NIST 800-171, and HIPAA, and track their implementation status, assessment objectives, and evidence, all in one place.