Skip to content

The hard part of ISO 27001 is not the policies

Every template pack on the internet gives you the same thing: a folder of Word documents with your company name find-and-replaced into them. Information Security Policy, Access Control Policy, seventeen more. They look like progress.

They are the easy half. The hard half is proving, on a Tuesday in month nine, that requirement 6.1.3(d) is met and pointing at the thing that meets it.

What template packs leave out

An auditor does not read your policy pack cover to cover and award you a certificate. They pick a requirement, ask what you do about it, and ask to see it. Then they do that forty more times.

A folder of documents cannot answer that. It has no notion of coverage. Nothing in it knows that Clause 9.1 requires you to determine what needs monitoring and when, and nothing in it goes red when you have not. You find out in the certification audit, which is the most expensive possible moment to find out.

So the kit I have published inverts the usual arrangement. The workbook is the centre and the documents hang off it, rather than the other way round.

Every requirement is a row

Fifty-four requirement rows for Clauses 4 to 10. Ninety-three control rows for Annex A. Each one has an owner, a status, a date and an evidence pointer.

That is the whole design, and it is almost embarrassingly simple. The point is what it makes impossible. A skipped requirement is a visibly blank row, and the dashboard counts it. You cannot quietly not do 7.5.3 because the blank sits there in a count that somebody looks at every week. The failure mode of a document folder is silence. The failure mode of a row-per-requirement workbook is a number that will not move, which is a much better failure mode to have.

It also changes the conversation with the business. "We are 61 percent through Annex A, and the twelve open ones all belong to IT operations" is a sentence a management review can act on. "We have written most of the policies" is not.

Seventeen documents, and one of them is not a policy

The document set covers what you would expect: scope, information security policy, risk methodology aligned with ISO/IEC 27005:2022, the topic-specific policy pack, gap analysis, internal audit, management review, corrective action, measurement plan structured on ISO/IEC 27004:2016, document control, incident response, business continuity, contract security schedule.

The one people skip is 01, How to Use This Kit, and it is the one that matters most. It carries the milestones, the working sessions, the questions that actually get real answers out of a room, and the warning signs that a programme is drifting. Everything else in the kit is paper. That document is the method.

Two deliberate choices in there worth naming. The Information Security Policy is three to five pages, on purpose — a thirty-page policy is a policy nobody has read, and an auditor can tell within two questions. And the internal audit document flags the independence trap explicitly, because the single most common Clause 9.2 finding is a person auditing work they did themselves.

What it will not do

It will not make you certified. It will not survive being filled in by one person in a room on their own, because half the requirements are questions about a business only the business can answer. And the guidance boxes are meant to be deleted before you issue anything, which means somebody has to read them first.

If you want a folder of documents to point at, there are a hundred of those and most are free. This is for the case where you have to actually get through the audit.

Free, no sign-up, adapt it however you like.

ISO/IEC 27001:2022 Implementation Kit →

ISO/IEC 27001:2022 and Amd 1:2024, with 27002, 27003, 27004 and 27005 as the guidance set. Practitioner material, not legal advice, and not affiliated with or endorsed by ISO.