ISO 27001 Documentation Kit

€590.00

Category

ISO 13485 & MDSAP Ready

Editable Word & Excel

ISO 13485 / MDSAP / FDA QMSR

Used by 100+ quality teams

ISO/IEC 27001:2022 · ANNEX A · NIS-2

ISO 27001 Documentation Kit

An information security management system ready to adopt: 21 procedures and policies, 18 forms and registers, and the Statement of Applicability with all 93 controls mapped.

€590

VAT calculated at checkout

Get the kit

42 files · 21 procedures · 18 templates
Editable Word and Excel files

Four ways an ISO 27001 project goes wrong

The first is writing the scope statement before the context and the interested parties have been worked through: written first, it describes the company and not the boundary of the system. The second is choosing controls from Annex A and then writing risks to justify them, which produces a Statement of Applicability that nothing supports.

The third is a system that has documents and no records. A certification audit samples evidence from a period, and a system that started operating three weeks before the audit cannot produce it. The fourth is letting the person who runs the system audit it, when the standard requires objectivity.

None of these are hard problems. They are the consequence of reading ISO/IEC 27001 as a list of documents to write rather than as a set of processes that have to run and leave records.

  • 42 files
  • 21 procedures and policies
  • 10 forms
  • 8 registers
  • 93 controls mapped
  • Word and Excel

Scope

What the kit covers

The kit covers the management system clauses, the risk process and the Annex A controls, each in a procedure of the same structure with the forms and registers it produces.

01

The management system

Clauses 4 to 10: manual and scope, policy, objectives and planning of changes, documented information and communication, competence and awareness, legal and contractual requirements, internal audit, management review, nonconformity and improvement.

02

Risk and the Statement of Applicability

Risk criteria, assessment and treatment, with the risk register, the assessment record and the Statement of Applicability listing the 93 controls of Annex A, each mapped to the procedure that implements it.

03

The operational controls

Twelve procedures for the Annex A controls: operational planning, assets and classification, access control, operations security, vulnerabilities, secure development, physical security, human resources, suppliers and cloud, incidents, continuity, logging and monitoring.

Contents

42 files: 21 procedures and policies with their forms and registers

SOP-ISMS-01ISMS Manual and Scopeprocedure
SOP-ISMS-02Information Security Policypolicy
SOP-ISMS-03Objectives and Planning of Changesprocedure
SOP-ISMS-04Documented Information and Communicationprocedure
SOP-ISMS-05Competence, Awareness and Resourcesprocedure
SOP-ISMS-06Information Security Risk Managementprocedure
SOP-ISMS-07Legal and Contractual Requirementsprocedure
SOP-ISMS-08Operational Planning and Controlprocedure
SOP-ISMS-09Asset and Information Classificationprocedure
SOP-ISMS-10Access Control and Identityprocedure
SOP-ISMS-11Operations Securityprocedure
SOP-ISMS-12Vulnerability and Configuration Managementprocedure
SOP-ISMS-13Secure Development and Changeprocedure
SOP-ISMS-14Physical and Environmental Securityprocedure
SOP-ISMS-15Human Resources Securityprocedure
SOP-ISMS-16Supplier and Cloud Securityprocedure
SOP-ISMS-17Incident Managementprocedure
SOP-ISMS-18Continuity and Resilienceprocedure
SOP-ISMS-19Logging and Monitoringprocedure
SOP-ISMS-20Performance, Audit and Management Reviewprocedure
SOP-ISMS-21Nonconformity and Improvementprocedure
F-ISMS-03.1Change Planning Recordform · Word
F-ISMS-06.3Risk Assessment Recordform · Word
F-ISMS-10.1Access Review Recordform · Word
F-ISMS-15.1Onboarding and Exit Recordform · Word
F-ISMS-16.1Security Clauses for Suppliersform · Word
F-ISMS-16.2Confidentiality Statementform · Word
F-ISMS-17.1Incident Recordform · Word
F-ISMS-20.1Internal Audit Programme and Reportform · Word
F-ISMS-20.2Management Review Minutesform · Word
F-ISMS-21.2Corrective Action Recordform · Word
F-ISMS-03.2Objectives Registerregister · Excel
F-ISMS-05.1Competence Registerregister · Excel
F-ISMS-06.1Risk Register and Treatment Planregister · Excel
F-ISMS-06.2Statement of Applicabilityregister · Excel
F-ISMS-07.1Legal and Contractual Requirements Registerregister · Excel
F-ISMS-09.1Asset Inventoryregister · Excel
F-ISMS-12.1Configuration Baselines Registerregister · Excel
F-ISMS-21.1Nonconformity and Corrective Action Registerregister · Excel
GlossaryGlossary of Information Security Termsterms, roles, abbreviations
READMEREADME and Implementation Guidethe sequence in five phases
Master IndexMaster Indexall files, clause and control maps

Audience

Who the kit is for

  • Organizations seeking ISO/IEC 27001 certification
  • Software and service companies asked for ISO/IEC 27001 by their customers
  • Entities within the scope of NIS-2 that need the Article 21 measures documented
  • Information security managers building a first management system
  • Consultants implementing ISO/IEC 27001 for a client

The kit assumes you can adapt a procedure to your organization and set the parameters it leaves to you: risk appetite, classification levels, deadlines, recovery objectives. It has no medical device content. It does not replace the standard, and you need your own copy.

What is included

What you get when you buy

  • 21 procedures and policies in Word, in one layout
  • 10 forms in Word, one for each record the procedures produce
  • 8 registers in Excel, including the risk register and the asset inventory
  • Statement of Applicability with the 93 Annex A controls, each mapped to its procedure
  • Master Index with the clause map, the Annex A control map and a NIS-2 mapping
  • README with the implementation sequence in five phases
  • Glossary of information security terms
  • Free updates when the kit is revised

Questions

Before you buy

Do I need to buy the standard as well?

Yes. The kit implements ISO/IEC 27001:2022 but does not reproduce it. The Statement of Applicability gives a short reminder of each control’s subject; the exact control text is taken from your copy of the standard.

Which edition of the standard does it follow?

ISO/IEC 27001:2022, with the 93 controls of the 2022 Annex A. The context analysis includes the determination on climate change introduced by the 2024 amendment.

Does it cover ISO 13485 as well?

No. This kit has no medical device content. A manufacturer that needs both standards in one system uses the ISO 13485 + ISO 27001 Integrated Documentation Kit.

Is the kit suitable for a small organization?

Yes. The README assumes a small organization with an Information Security Manager who gives the system one day a week, and it says which three decisions to take before editing any document.

How long does implementation take?

The README sets out five phases. The first three, up to the approved risk treatment plan and Statement of Applicability, take about nine to thirteen weeks. Three to six months of operation before the certification audit is realistic, because the audit samples records from a period.

Does it make us compliant with NIS-2?

No. The Master Index maps the measures of Article 21 to the documents of the kit and says where the coverage is partial. A mapping shows overlap, not equivalence: it reduces the work, it does not replace the assessment.

In which format are the documents?

Procedures and forms are Word files; registers and the Statement of Applicability are Excel files. Everything is editable, with bracketed placeholders for your company name, roles and dates.

Do I get updates when the kit changes?

Yes. When the kit is revised, you receive the updated files at no additional cost.

Can the kit be used in more than one company?

Yes. For use across several companies, for example by a consultant with several clients or a group with several legal entities, get in touch and we will arrange a multi-licence purchase.

Does the kit guarantee certification?

No. Certification depends on operating the processes and keeping the records. The kit defines the processes, gives you the forms and tells you what a certification auditor reads first.

ISO 27001 Documentation Kit

42 files: 21 procedures and policies, 10 forms, 8 registers, the Glossary and the Master Index for ISO/IEC 27001:2022, in editable Word and Excel.

Get the kit — €590

€590.00