ISO/IEC 27001:2022 IMPLEMENTATION KIT
sameerkhairkar.com/resources/iso27001/implementation-kit/

WHAT THIS IS
A complete paper set for taking an organisation from nothing to certified against
ISO/IEC 27001:2022. Seventeen Word documents and one Excel workbook. Free to
download, adapt and use, including commercially.

START HERE
  1. Open 01_How_To_Use_This_Kit.docx and read sections 1 and 2.
  2. Open the workbook and read the "00 Read Me" tab.
  3. Work through the workbook from tab 05 (Document Register) outward.

WHAT IS IN IT
  ISO27001-2022_Implementation_Workbook_TEMPLATE.xlsx  27 tabs - the centre of the kit
  01  How to Use This Kit                              guide: milestones, sessions, FAQ
  02  ISMS Scope Document                              Clause 4.3
  03  Information Security Policy                      Clause 5.2
  04  Risk Management Methodology                      Clauses 6.1.2 and 6.1.3
  05  Topic-Specific Policy Pack                       17 policies
  06  Gap Analysis Report
  07  Internal Audit Plan and Report                   Clause 9.2
  08  Management Review Pack and Minutes               Clause 9.3
  09  Nonconformity and Corrective Action Report       Clause 10.2
  10  Measurement Plan                                 Clause 9.1
  11  Document Control Procedure                       Clauses 7.5.2 and 7.5.3
  12  Incident Response Plan and Runbooks              A.5.24 to A.5.28
  13  Business Continuity and ICT Recovery Plan        A.5.29 and A.5.30
  14  Contract Security Schedule                       A.5.19 to A.5.22
  15  Operating Procedure Template                     one copy per procedure
  16  ISO 27003 and 27004 Conformance Matrix           reference
  17  Current Standard Supplement                      reference: the 2024 amendment

HOW TO FILL IT IN
Text in [square brackets] must be completed or deleted. Shaded GUIDANCE boxes are
notes to whoever is filling the document in and must be deleted before issue. In the
workbook, pale cells are yours to complete and grey cells are reference material.

SOURCES AND COPYRIGHT
This kit uses the clause numbering and the Annex A control reference numbers and
short titles from ISO/IEC 27001:2022 as identifiers. All requirement restatements,
guidance, evidence suggestions, questions and commentary are original text written
for this kit. No part of ISO/IEC 27001:2022 or ISO/IEC 27002:2022 is reproduced.

You need licensed copies of ISO/IEC 27001:2022 (requirements) and ISO/IEC 27002:2022
(control implementation guidance). ISO/IEC 27005:2022 is strongly recommended for the
risk work, ISO/IEC 27003 for implementation guidance. Buy them from ISO or your
national standards body.

NOT LEGAL ADVICE
Practitioner material, independent work, personal views. Not affiliated with any
employer. Check every reference against the current published standard before
operational use.
