Knowledge hub

ISO 27001

ISO/IEC 27001. The international standard for information security management. Everything you need to understand, scope, and get certified.

ISO 27001 starter pack

Turn the ISMS into documents, controls, and evidence.

Use this path when a buyer, auditor, or internal sponsor asks what needs to exist before certification.

Open Markdown pack ->

Guides

7 min read

What Is ISO 27001? A Plain-English Guide

ISO/IEC 27001 is the international standard for managing information security. Here is what it is, who needs it, and what certification proves.

8 min read

The ISO 27001 Certification Process, Step by Step

From scoping to the Stage 2 audit and beyond. A clear walkthrough of how organisations actually achieve ISO 27001 certification.

6 min read

How Much Does ISO 27001 Cost?

A realistic breakdown of ISO 27001 costs, from the certification audit to software, consultancy, and the internal time it really takes.

6 min read

ISO 27001 vs SOC 2: Which Do You Need?

ISO 27001 and SOC 2 both prove you take security seriously, but they differ in origin, format, and audience. Here is how to choose.

12 min read

The Ultimate ISO 27001 Implementation Checklist for SaaS Founders

A practical, technical roadmap for SaaS founders to achieve ISO 27001 certification, from scoping to audit readiness.

6 min read

ISO 27001 Annex A Controls: The Four Themes (2022)

The 2022 version of ISO 27001 lists 93 Annex A controls across four themes: organisational, people, physical, and technological. Here is how they fit together.

5 min read

ISO 27001 Statement of Applicability (SoA), Explained

The Statement of Applicability is a mandatory ISO 27001 document listing which Annex A controls apply, why, and their implementation status.

8 min read

ISO 27001 Risk Assessment, Step by Step

The risk assessment is the engine of an ISO 27001 ISMS. Here is how to choose a methodology, score likelihood and impact, build a risk register, and link it all to your Statement of Applicability.

7 min read

The ISO 27001 Internal Audit: Clause 9.2 in Practice

ISO 27001 requires internal audits before the certification body ever arrives. Here is how to plan the audit programme, keep it independent, run the audit, and feed findings into management review.

Buyer guides

Ranked, independently tested picks with pricing and where to buy.

Software to automate ISO 27001

Platforms that map the controls, collect evidence, and keep you audit-ready.

// Signal, not noise

Getting started with ISO 27001?

A short, practical email on scoping, controls, and choosing software. No spam.