Resources

Sample policies & guides

Original, ISO-mapped collateral you can use today. Every template is authored in our own words and mapped to ISO/IEC 27001:2022 by clause number, no copyrighted standard text.

Looking for how-to guidance? Our Learn hub has no-jargon guides to SOC 2 and ISO 27001, audit prep, choosing an auditor, and what it all costs. Browse the guides →

Want a ready-to-run checklist? Grab the SOC 2 Evidence Kit: every control and the evidence that proves it, as a CSV. See all toolkits →

Policy templates

Grab ready-to-edit policy templates from our free policy-template library: each one is authored in plain English, mapped to ISO/IEC 27001:2022 or SOC 2 by clause, and free to preview in full and download, no email required. Browse the templates →

  • Information Security Policy, mapped to ISO-27001.
  • Remote Access & BYOD, mapped to ISO-27001.
  • Information Security & Privacy Governance, mapped to ISO-27001.
  • Policy Management & Exception Handling, mapped to ISO-27001.
  • Privacy & Data-Subject Rights, mapped to GDPR.
  • Secure Configuration & Hardening, mapped to CIS-CONTROLS.
  • Risk Management, mapped to ISO-27001.
  • Vulnerability & Patch Management, mapped to CIS-CONTROLS.
  • Vendor & Third-Party Risk, mapped to ISO-27001.
  • Change & Release Management, mapped to SOC-2.
  • Secure Software Development Lifecycle, mapped to ISO-27001.
  • Information Sharing & Transfer, mapped to ISO-27001.
  • Compliance & Regulatory Monitoring, mapped to ISO-27001.
  • Acceptable Use & Workstation Security, mapped to ISO-27001.
  • Background Screening & On/Off-boarding, mapped to ISO-27001.
  • Sanctions & Disciplinary, mapped to ISO-27001.
  • Data Classification & Handling, mapped to ISO-27001.
  • Security & Privacy Awareness Training, mapped to ISO-27001.
  • Authentication & Password, mapped to CIS-CONTROLS.
  • Change Management Policy, mapped to SOC-2.
  • Backup, Business Continuity & Disaster Recovery, mapped to ISO-27001.
  • Logging, Monitoring & Audit, mapped to ISO-27001.
  • Supplier / Vendor Evaluation Policy, mapped to ISO-9001.
  • Document Control Procedure, mapped to ISO-9001.
  • Incident Response & Breach Notification, mapped to ISO-27001.
  • Encryption & Crypto Controls, mapped to ISO-27001.
  • Code of Business Conduct, mapped to ESG-ESSENTIALS.
  • AI Policy Control Framework, mapped to ISO-27001.
  • Third-Party Processors (Vendors), mapped to GDPR.
  • Retention & Secure Disposal, mapped to ISO-27001.
  • Quality Objectives, mapped to ISO-9001.
  • QMS Scope, mapped to ISO-9001.
  • Internal Audit Procedure, mapped to ISO-9001.
  • Quality Policy, mapped to ISO-9001.
  • Physical Security & Environmental, mapped to ISO-27001.
  • Access Control & Least Privilege, mapped to ISO-27001.
  • Service Provider Acknowledgement, mapped to PCI-DSS.
  • PIPEDA Privacy Notice Policy, mapped to PIPEDA.
  • PIPEDA Consent Management Policy, mapped to PIPEDA.
  • PIPEDA Data Accuracy Policy, mapped to PIPEDA.
  • PIPEDA Personal Information Inventory & Purpose Register Policy, mapped to PIPEDA.
  • PIPEDA Access Request Policy, mapped to PIPEDA.
  • PIPEDA Privacy Complaint Policy, mapped to PIPEDA.
  • Children's and Minors' Data Policy, mapped to GDPR.
  • Information Security Safeguards Policy, mapped to ISO-27001.
  • Data Retention and Disposal Policy, mapped to GDPR.
  • Incident Response and Breach Notification Policy, mapped to ISO-27001.
  • Vendor and Third-Party Management Policy, mapped to GDPR.
  • Data Classification and Inventory Policy, mapped to GDPR.
  • Consumer Rights Request Policy, mapped to GDPR.
  • Privacy Policy, mapped to GDPR.
  • Network Security, mapped to CIS-CONTROLS.
  • Privacy Awareness and Training Policy, mapped to GDPR.
  • Children's Privacy Program, Notice and Parental Consent, mapped to APPLE-KIDS.
  • Child-Appropriate Experience and Parental Gates, mapped to APPLE-KIDS.
  • Children's Advertising and Monetization, mapped to GOOGLE-PLAY-FAMILIES.
  • Third-Party SDK Governance for Children's Apps, mapped to GOOGLE-PLAY-FAMILIES.
  • Children's App Store Declarations and Metadata, mapped to APPLE-KIDS.
  • Age Screening and Data Minimization for Children's Apps, mapped to GOOGLE-PLAY-FAMILIES.
  • AI Governance Policy, Roles and Competence, mapped to ISO-42001.
  • AI Risk and Impact Assessment, mapped to NIST-AI-RMF.
  • Responsible AI Development, Validation and Documentation, mapped to ISO-42001.
  • Data Governance for AI, mapped to ISO-42001.
  • AI Transparency, Disclosure and Customer Information, mapped to ISO-42001.
  • Human Oversight and Responsible Use of AI, mapped to ISO-42001.
  • AI Logging, Monitoring and Incident Reporting, mapped to EU-AI-ACT.
  • AI Supplier and Third-Party Management, mapped to NIST-AI-RMF.
  • HIPAA Business Associate Management, mapped to HIPAA.
  • HIPAA Breach Risk Assessment and Notification, mapped to HIPAA.
  • HIPAA Contingency Plan, mapped to HIPAA.
  • HIPAA Individual Rights and Notice of Privacy Practices, mapped to HIPAA.
  • HIPAA Workforce Security, Sanctions and Information Access Management, mapped to HIPAA.
  • IT General Controls for Financial Reporting, mapped to SOX.
  • Segregation of Duties and Delegation of Authority, mapped to SOX.
  • Financial Close and Reporting Controls, mapped to SOX.
  • Fraud Risk and Management Override, mapped to SOX.
  • Control Deficiency Evaluation and Remediation, mapped to SOX.
  • US Hiring, Employment Eligibility Verification and Background Checks, mapped to US-EMPLOYMENT-FEDERAL.
  • US Wage, Hour and Worker Classification, mapped to US-EMPLOYMENT-FEDERAL.
  • US Pay Equity and Compensation Review, mapped to US-EMPLOYMENT-FEDERAL.
  • US Leave and Time Off, mapped to US-EMPLOYMENT-FEDERAL.
  • US Equal Employment Opportunity, Anti-Harassment and Accommodation, mapped to US-EMPLOYMENT-FEDERAL.
  • System Security Plan and Control Baseline, mapped to NIST-800-171.
  • Security Control Assessment, Authorization and Plan of Action & Milestones, mapped to NIST-800-53.
  • Media Protection and Sanitization, mapped to NIST-800-171.
  • System Maintenance, mapped to NIST-800-53.
  • ICT Supply Chain Risk Management and Component Authenticity, mapped to NIST-CSF.
  • Prohibited and High-Risk AI Use Screening, mapped to EU-AI-ACT.
  • EU AI Act Provider Obligations for High-Risk AI Systems, mapped to EU-AI-ACT.
  • AI Copyright Compliance and General-Purpose AI Model Obligations, mapped to EU-AI-ACT.
  • AI Testing, Evaluation and Independent Review, mapped to NIST-AI-RMF.
  • Change Control, Rollback and Decommissioning for AI Systems, mapped to AI-GOVERNANCE-ESSENTIALS.
  • COPPA Children’s Privacy Notices: Direct Notice and Online Notice, mapped to COPPA.
  • COPPA Verifiable Parental Consent, mapped to COPPA.
  • COPPA Consent Exceptions and Their Conditions, mapped to COPPA.
  • COPPA Parent Review, Refusal and Deletion Requests, mapped to COPPA.
  • QMS Customer Requirements, Order Review and Satisfaction, mapped to ISO-9001.
  • QMS Operational Planning, Production and Service Provision, mapped to ISO-9001.
  • QMS Design and Development Control, mapped to ISO-9001.

ISO 27001:2022 at a glance

The Annex A controls Keel maps, grouped into the four 2022 themes:

  • A.5 Organizational controls, 37 controls
  • A.6 People controls, 8 controls
  • A.7 Physical controls, 14 controls
  • A.8 Technological controls, 34 controls

ISO/IEC 27001 is referenced factually by name and clause number. Keel is not affiliated with or endorsed by ISO/IEC.