ISO 27001 vs ISO 22301 compared: information security versus business continuity, where the two overlap, and why 27001's continuity controls are not enough.
A practical ISO 27001 implementation plan in ten steps for the 2022 edition, with realistic timings and the three steps security projects always underestimate.
A practical 2026 guide to choosing an accredited ISO 27001 certification body: what changed on 1 January 2026, seven selection criteria, audit-day maths, costs and the three-year cycle.
Five complete ISO 27001 templates, free by email — real fill-in documents from the ISO 27001 Documentation Toolkit, not outlines. One ZIP or five PDFs.
What ISO 27001 clause 9.2 requires from an internal audit, who can run it, a seven-step method, and the records certification auditors ask to see in 2026.
ISO 27001 Stage 1 vs Stage 2 explained by clause: what each audit checks, how audit days are set, the gap between them, and the six-month major nonconformity rule.
An ISO 27001 gap analysis compares what you actually do against clauses 4-10 and the 93 Annex A controls. Here is the seven-step method, a 0-3 scoring scale, typical costs...
How to run an ISO 27001 risk assessment that survives an audit: what clause 6.1.2 actually requires, the six steps in order, a worked 5x5 scoring example, and the three...
The ISO 27001 Statement of Applicability is mandatory under clause 6.1.3(d). What it must contain for all 93 Annex A controls, a worked example, and the six mistakes auditors flag.
ISO 27001 vs NIST CSF compared: certification versus self-assessment, 93 Annex A controls versus 106 CSF outcomes, and which one your buyers actually ask for.