Resources
Practical resources for audit and management-system work
Find practical implementation guidance organised by standard, workflow and content type, with related tools for focused application.
Current library
A focused collection with honest coverage
48 published articles currently focus on ISO/IEC 27001, including implementation guides, checklists, reference material and a framework comparison.
Featured resources
Start with current practical guidance
Use these published resources to understand the task before applying a related tool or workflow.
ISO 27001 Gap Analysis: The Complete Step-by-Step Guide
Learn how to run an ISO 27001 gap analysis, score findings, build a remediation plan and use a practical gap analysis template.
- Standard
- ISO/IEC 27001
- Workflow
- Audit preparation
How to Build an Information Security Risk Register
Build a practical information security risk register with clear ownership, consistent scoring and records that support risk treatment and review.
- Standard
- ISO/IEC 27001
- Workflow
- Risk assessment
ISO 27001 vs SOC 2: What Is the Practical Difference?
Compare ISO 27001 and SOC 2 in practical terms: certification vs attestation, scope, evidence, control approach, customer expectations and when an organization may need one or both.
- Standard
- ISO/IEC 27001
- Workflow
- Framework selection
ISO 27001 Annex A Controls: How to Select, Implement and Evidence Them
Learn how to move from Annex A control lookup to justified applicability, practical implementation, operating evidence and Statement of Applicability maintenance.
- Standard
- ISO/IEC 27001
- Workflow
- Control selection
ISO 27001 Audit Evidence: Implementation vs Operating Evidence
Learn the practical difference between implementation evidence and operating evidence in ISO 27001 audits, with examples, audit questions and a simple evidence-preparation method.
- Standard
- ISO/IEC 27001
- Workflow
- Evidence management
ISO 27001 Clauses 4–10 Explained: What Each Clause Does
Understand how ISO 27001 clauses 4–10 fit together, what evidence teams commonly prepare and how to avoid disconnected compliance paperwork.
- Standard
- ISO/IEC 27001
- Workflow
- ISO 27001 implementation
How to Build an ISO 27001 Evidence Register That Actually Helps During an Audit
Build a practical ISO 27001 evidence register that tracks ownership, requirements, freshness, review status, audit use and evidence reuse without creating duplicate files.
- Standard
- ISO/IEC 27001
- Workflow
- Evidence management
ISO 27001 Readiness Assessment: A Practical Pre-Audit Checklist
Use this practical ISO 27001 readiness assessment to find gaps in scope, risk management, evidence, internal audit and management review before certification.
- Standard
- ISO/IEC 27001
- Workflow
- Audit preparation
ISO 27001 Risk Matrix: How to Define Likelihood, Impact and Risk Levels
Build a repeatable ISO 27001 risk matrix with defined likelihood, impact and acceptance criteria, practical examples and calibration guidance.
- Standard
- ISO/IEC 27001
- Workflow
- Risk assessment
Browse by standard
Current and planned standards coverage
Start with ISO 27001 implementation support and explore the planned standards roadmap.
ISO/IEC 27001
48 published resources and 5 available free tools support implementation, risk assessment, control selection, evidence management and audit preparation.
ISO 22301
ISO/IEC 42001
ISO 9001
ISO 14001
ISO 45001
ADHICS
Browse by workflow
Move from guidance to a focused next step
Audit preparation
Risk assessment
Use the risk-register guide, then calculate inherent and residual risk with the free Risk Score Calculator.
Control selection
Research controls in the Annex A Control Lookup and record decisions in the free Statement of Applicability Builder.
Framework selection
Browse by content type
Published resource formats
Guides
37 published guides.
Browse current guidesComparisons
6 published comparison.
Read the comparisonReference
3 published reference article.
Explore clauses 4–10Checklists
2 published readiness checklists.
Open the readiness checklistResources and tools
Understand the task, then apply a focused tool
Resources explain the task. Free Website Tools help apply a focused part of it. Paid Self-Hosted Tools are intended for repeatable workflows in a customer-operated environment.
The readiness checker provides an indicative self-assessment across 25 questions and six areas. Use the gap-analysis guide for the wider evidence review and remediation process.
Planned
Expanding implementation support
ISO 22301 business continuity guidance
ISO/IEC 42001 AI governance guidance
ISO 9001 quality-management guidance
ISO 14001 environmental-management guidance
Audit and corrective-action guidance
Editorial approach
Practical guidance with clear sources
- Use plain language and direct explanations.
- Separate requirements from practical recommendations.
- Cite authoritative sources where relevant.
- Avoid reproducing protected standards text.
- Connect guidance to real tools and workflows.
- Review content when source requirements or product behaviour changes.
Start with a current resource or free tool
Choose the detailed gap-analysis guide or establish an initial baseline with the readiness checker.