Resources & Insights

The ISO 27001
Knowledge Hub

Practical guides, implementation tips, and expert insights for IT and security professionals navigating ISO 27001 certification.

Complete Guide

ISO 27001:2022 — The Complete Implementation Guide for IT Directors

Everything you need to know to take your organisation from zero to certified. Covers all four implementation phases, common pitfalls, and what auditors actually look for.

15 min readMay 2025
ISO 27001

What's Changed in ISO 27001:2022 — The 11 New Controls You Need to Know

The 2022 revision introduced 11 new Annex A controls. Here's exactly what they require and how to implement them.

8 min readApril 2025
Risk Assessment

How to Write a Risk Register That Actually Satisfies Clause 6.1.2

Most risk registers fail audits for the same five reasons. Here's what Clause 6.1.2 requires and how to get it right first time.

6 min readMarch 2025
SoA
ISO 27001

Statement of Applicability: A Worked Example for a SaaS Company

A line-by-line walkthrough of completing the SoA for a cloud-native SaaS business with 50 employees.

12 min read
AI
AI & Compliance

Can AI-Generated Compliance Documents Pass a Real ISO 27001 Audit?

We tested AI-generated documentation against actual audit criteria. Here's what worked, what didn't, and what the key differentiator is.

9 min read
Risk Assessment

ISO 27001 for Azure/AWS Hybrid Environments — Mapping Cloud Risks to Annex A

Cloud-specific risks that most generic risk registers miss, and the exact Annex A controls that address them.

10 min read
§
Policies

The 12 ISO 27001 Policies Every Organization Must Have

The mandatory policy documents, what each one must contain, and the most common reasons they fail audit review.

7 min read
Audit Prep

Stage 1 vs Stage 2 Audit — What Auditors Look for at Each Phase

A former ISO lead auditor explains exactly what evidence they check, what questions they ask, and what triggers a non-conformity.

11 min read
$
ISO 27001

ISO 27001 Certification Cost Breakdown — What You're Really Paying For

Consultant fees, certification body costs, internal time, and how to reduce total spend without cutting corners on compliance.

8 min read