Resources

Sample policies & guides

Original, ISO-mapped collateral you can use today. Every template is authored in our own words and mapped to ISO/IEC 27001:2022 by clause number, no copyrighted standard text.

Looking for how-to guidance? Our Learn hub has no-jargon guides to SOC 2 and ISO 27001, audit prep, choosing an auditor, and what it all costs. Browse the guides →

Want a ready-to-run checklist? Grab the SOC 2 Evidence Kit: every control and the evidence that proves it, as a CSV. See all toolkits →

Policy templates

Grab ready-to-edit policy templates from our free policy-template library: each one is authored in plain English, mapped to ISO/IEC 27001:2022 or SOC 2 by clause, and free to preview in full and download, no email required. Browse the templates →

  • Information Security Policy, mapped to ISO-27001.
  • Remote Access & BYOD, mapped to ISO-27001.
  • Information Security & Privacy Governance, mapped to ISO-27001.
  • Policy Management & Exception Handling, mapped to ISO-27001.
  • Privacy & Data-Subject Rights, mapped to GDPR.
  • Secure Configuration & Hardening, mapped to CIS-CONTROLS.
  • Risk Management, mapped to ISO-27001.
  • Vulnerability & Patch Management, mapped to CIS-CONTROLS.
  • Vendor & Third-Party Risk, mapped to ISO-27001.
  • Change & Release Management, mapped to SOC-2.
  • Secure Software Development Lifecycle, mapped to ISO-27001.
  • Information Sharing & Transfer, mapped to ISO-27001.
  • Compliance & Regulatory Monitoring, mapped to ISO-27001.
  • Acceptable Use & Workstation Security, mapped to ISO-27001.
  • Background Screening & On/Off-boarding, mapped to ISO-27001.
  • Sanctions & Disciplinary, mapped to ISO-27001.
  • Data Classification & Handling, mapped to ISO-27001.
  • Security & Privacy Awareness Training, mapped to ISO-27001.
  • Authentication & Password, mapped to CIS-CONTROLS.
  • Change Management Policy, mapped to SOC-2.
  • Backup, Business Continuity & Disaster Recovery, mapped to ISO-27001.
  • Logging, Monitoring & Audit, mapped to ISO-27001.
  • Supplier / Vendor Evaluation Policy, mapped to ISO-9001.
  • Document Control Procedure, mapped to ISO-9001.
  • Incident Response & Breach Notification, mapped to ISO-27001.
  • Encryption & Crypto Controls, mapped to ISO-27001.
  • Code of Business Conduct, mapped to ESG-ESSENTIALS.
  • AI Policy Control Framework, mapped to ISO-27001.
  • Third-Party Processors (Vendors), mapped to GDPR.
  • Retention & Secure Disposal, mapped to ISO-27001.
  • Quality Objectives, mapped to ISO-9001.
  • QMS Scope, mapped to ISO-9001.
  • Internal Audit Procedure, mapped to ISO-9001.
  • Quality Policy, mapped to ISO-9001.
  • Physical Security & Environmental, mapped to ISO-27001.
  • Access Control & Least Privilege, mapped to ISO-27001.
  • Service Provider Acknowledgement, mapped to PCI-DSS.
  • PIPEDA Privacy Notice Policy, mapped to GDPR.
  • Children's and Minors' Data Policy, mapped to GDPR.
  • PIPEDA Consent Management Policy, mapped to GDPR.
  • Information Security Safeguards Policy, mapped to ISO-27001.
  • Data Retention and Disposal Policy, mapped to GDPR.
  • PIPEDA Data Accuracy Policy, mapped to GDPR.
  • Incident Response and Breach Notification Policy, mapped to ISO-27001.
  • Vendor and Third-Party Management Policy, mapped to GDPR.
  • Data Classification and Inventory Policy, mapped to GDPR.
  • Consumer Rights Request Policy, mapped to GDPR.
  • Privacy Policy, mapped to GDPR.
  • Network Security, mapped to CIS-CONTROLS.
  • PIPEDA Personal Information Inventory & Purpose Register Policy, mapped to GDPR.
  • PIPEDA Access Request Policy, mapped to GDPR.
  • PIPEDA Privacy Complaint Policy, mapped to GDPR.
  • Privacy Awareness and Training Policy, mapped to GDPR.

ISO 27001:2022 at a glance

The Annex A controls Keel maps, grouped into the four 2022 themes:

  • A.5 Organizational controls, 37 controls
  • A.6 People controls, 8 controls
  • A.7 Physical controls, 14 controls
  • A.8 Technological controls, 34 controls

ISO/IEC 27001 is referenced factually by name and clause number. Keel is not affiliated with or endorsed by ISO/IEC.