Resources
Sample policies & guides
Original, ISO-mapped collateral you can use today. Every template is authored in our own words and mapped to ISO/IEC 27001:2022 by clause number, no copyrighted standard text.
Looking for how-to guidance? Our Learn hub has no-jargon guides to SOC 2 and ISO 27001, audit prep, choosing an auditor, and what it all costs. Browse the guides →
Want a ready-to-run checklist? Grab the SOC 2 Evidence Kit: every control and the evidence that proves it, as a CSV. See all toolkits →
Policy templates
Grab ready-to-edit policy templates from our free policy-template library: each one is authored in plain English, mapped to ISO/IEC 27001:2022 or SOC 2 by clause, and free to preview in full and download, no email required. Browse the templates →
- Information Security Policy
- Remote Access & BYOD
- Information Security & Privacy Governance
- Policy Management & Exception Handling
- Privacy & Data-Subject Rights
- Secure Configuration & Hardening
- Risk Management
- Vulnerability & Patch Management
- Vendor & Third-Party Risk
- Change & Release Management
- Secure Software Development Lifecycle
- Information Sharing & Transfer
- Compliance & Regulatory Monitoring
- Acceptable Use & Workstation Security
- Background Screening & On/Off-boarding
- Sanctions & Disciplinary
- Data Classification & Handling
- Security & Privacy Awareness Training
- Authentication & Password
- Change Management Policy
- Backup, Business Continuity & Disaster Recovery
- Logging, Monitoring & Audit
- Supplier / Vendor Evaluation Policy
- Document Control Procedure
- Incident Response & Breach Notification
- Encryption & Crypto Controls
- Code of Business Conduct
- AI Policy Control Framework
- Third-Party Processors (Vendors)
- Retention & Secure Disposal
- Quality Objectives
- QMS Scope
- Internal Audit Procedure
- Quality Policy
- Physical Security & Environmental
- Access Control & Least Privilege
- Service Provider Acknowledgement
- PIPEDA Privacy Notice Policy
- PIPEDA Consent Management Policy
- PIPEDA Data Accuracy Policy
- PIPEDA Personal Information Inventory & Purpose Register Policy
- PIPEDA Access Request Policy
- PIPEDA Privacy Complaint Policy
- Children's and Minors' Data Policy
- Information Security Safeguards Policy
- Data Retention and Disposal Policy
- Incident Response and Breach Notification Policy
- Vendor and Third-Party Management Policy
- Data Classification and Inventory Policy
- Consumer Rights Request Policy
- Privacy Policy
- Network Security
- Privacy Awareness and Training Policy
- Children's Privacy Program, Notice and Parental Consent
- Child-Appropriate Experience and Parental Gates
- Children's Advertising and Monetization
- Third-Party SDK Governance for Children's Apps
- Children's App Store Declarations and Metadata
- Age Screening and Data Minimization for Children's Apps
- AI Governance Policy, Roles and Competence
- AI Risk and Impact Assessment
- Responsible AI Development, Validation and Documentation
- Data Governance for AI
- AI Transparency, Disclosure and Customer Information
- Human Oversight and Responsible Use of AI
- AI Logging, Monitoring and Incident Reporting
- AI Supplier and Third-Party Management
- HIPAA Business Associate Management
- HIPAA Breach Risk Assessment and Notification
- HIPAA Contingency Plan
- HIPAA Individual Rights and Notice of Privacy Practices
- HIPAA Workforce Security, Sanctions and Information Access Management
- IT General Controls for Financial Reporting
- Segregation of Duties and Delegation of Authority
- Financial Close and Reporting Controls
- Fraud Risk and Management Override
- Control Deficiency Evaluation and Remediation
- US Hiring, Employment Eligibility Verification and Background Checks
- US Wage, Hour and Worker Classification
- US Pay Equity and Compensation Review
- US Leave and Time Off
- US Equal Employment Opportunity, Anti-Harassment and Accommodation
- System Security Plan and Control Baseline
- Security Control Assessment, Authorization and Plan of Action & Milestones
- Media Protection and Sanitization
- System Maintenance
- ICT Supply Chain Risk Management and Component Authenticity
- Prohibited and High-Risk AI Use Screening
- EU AI Act Provider Obligations for High-Risk AI Systems
- AI Copyright Compliance and General-Purpose AI Model Obligations
- AI Testing, Evaluation and Independent Review
- Change Control, Rollback and Decommissioning for AI Systems
- COPPA Children’s Privacy Notices: Direct Notice and Online Notice
- COPPA Verifiable Parental Consent
- COPPA Consent Exceptions and Their Conditions
- COPPA Parent Review, Refusal and Deletion Requests
- QMS Customer Requirements, Order Review and Satisfaction
- QMS Operational Planning, Production and Service Provision
- QMS Design and Development Control
ISO 27001:2022 at a glance
The Annex A controls Keel maps, grouped into the four 2022 themes:
- A.5
- A.6
- A.7
- A.8
ISO/IEC 27001 is referenced factually by name and clause number. Keel is not affiliated with or endorsed by ISO/IEC.