Sample policies & guides
Original, ISO-mapped collateral you can use today. Every template is authored in our own words and mapped to ISO/IEC 27001:2022 by clause number, no copyrighted standard text.
Looking for how-to guidance? Our Learn hub has no-jargon guides to SOC 2 and ISO 27001, audit prep, choosing an auditor, and what it all costs. Browse the guides →
Want a ready-to-run checklist? Grab the SOC 2 Evidence Kit: every control and the evidence that proves it, as a CSV. See all toolkits →
Policy templates
Grab ready-to-edit policy templates from our free policy-template library: each one is authored in plain English, mapped to ISO/IEC 27001:2022 or SOC 2 by clause, and free to preview in full and download, no email required. Browse the templates →
- Information Security Policy, mapped to ISO-27001.
- Remote Access & BYOD, mapped to ISO-27001.
- Information Security & Privacy Governance, mapped to ISO-27001.
- Policy Management & Exception Handling, mapped to ISO-27001.
- Privacy & Data-Subject Rights, mapped to GDPR.
- Secure Configuration & Hardening, mapped to CIS-CONTROLS.
- Risk Management, mapped to ISO-27001.
- Vulnerability & Patch Management, mapped to CIS-CONTROLS.
- Vendor & Third-Party Risk, mapped to ISO-27001.
- Change & Release Management, mapped to SOC-2.
- Secure Software Development Lifecycle, mapped to ISO-27001.
- Information Sharing & Transfer, mapped to ISO-27001.
- Compliance & Regulatory Monitoring, mapped to ISO-27001.
- Acceptable Use & Workstation Security, mapped to ISO-27001.
- Background Screening & On/Off-boarding, mapped to ISO-27001.
- Sanctions & Disciplinary, mapped to ISO-27001.
- Data Classification & Handling, mapped to ISO-27001.
- Security & Privacy Awareness Training, mapped to ISO-27001.
- Authentication & Password, mapped to CIS-CONTROLS.
- Change Management Policy, mapped to SOC-2.
- Backup, Business Continuity & Disaster Recovery, mapped to ISO-27001.
- Logging, Monitoring & Audit, mapped to ISO-27001.
- Supplier / Vendor Evaluation Policy, mapped to ISO-9001.
- Document Control Procedure, mapped to ISO-9001.
- Incident Response & Breach Notification, mapped to ISO-27001.
- Encryption & Crypto Controls, mapped to ISO-27001.
- Code of Business Conduct, mapped to ESG-ESSENTIALS.
- AI Policy Control Framework, mapped to ISO-27001.
- Third-Party Processors (Vendors), mapped to GDPR.
- Retention & Secure Disposal, mapped to ISO-27001.
- Quality Objectives, mapped to ISO-9001.
- QMS Scope, mapped to ISO-9001.
- Internal Audit Procedure, mapped to ISO-9001.
- Quality Policy, mapped to ISO-9001.
- Physical Security & Environmental, mapped to ISO-27001.
- Access Control & Least Privilege, mapped to ISO-27001.
- Service Provider Acknowledgement, mapped to PCI-DSS.
- PIPEDA Privacy Notice Policy, mapped to GDPR.
- Children's and Minors' Data Policy, mapped to GDPR.
- PIPEDA Consent Management Policy, mapped to GDPR.
- Information Security Safeguards Policy, mapped to ISO-27001.
- Data Retention and Disposal Policy, mapped to GDPR.
- PIPEDA Data Accuracy Policy, mapped to GDPR.
- Incident Response and Breach Notification Policy, mapped to ISO-27001.
- Vendor and Third-Party Management Policy, mapped to GDPR.
- Data Classification and Inventory Policy, mapped to GDPR.
- Consumer Rights Request Policy, mapped to GDPR.
- Privacy Policy, mapped to GDPR.
- Network Security, mapped to CIS-CONTROLS.
- PIPEDA Personal Information Inventory & Purpose Register Policy, mapped to GDPR.
- PIPEDA Access Request Policy, mapped to GDPR.
- PIPEDA Privacy Complaint Policy, mapped to GDPR.
- Privacy Awareness and Training Policy, mapped to GDPR.
ISO 27001:2022 at a glance
The Annex A controls Keel maps, grouped into the four 2022 themes:
- A.5 Organizational controls, 37 controls
- A.6 People controls, 8 controls
- A.7 Physical controls, 14 controls
- A.8 Technological controls, 34 controls
ISO/IEC 27001 is referenced factually by name and clause number. Keel is not affiliated with or endorsed by ISO/IEC.