Home › ISO Digital Products › All Products › ISO 27001:2022 — ISMS

SGRII Digital Solutions  ·  Information Security

ISO/IEC 27001:2022
ISMS Framework

All 93 Annex A controls. Statement of Applicability, DPIA alignment, and a structured ISMS built for SMEs pursuing certification — or maintaining continual improvement under an existing certificate.

Framework at a Glance

✓93 Annex A controls covered

✓Statement of Applicability (SoA)

✓10 Core procedures

✓15 Excel templates & registers

✓Risk & Opportunity Register (Cl.6.1)

✓NC & CA Register (Cl.10.2)

✓Internal audit pack & checklists

✓Clause 10.1 — Continual Improvement

Why Organisations Choose This Framework

Information Security Without the Guesswork

ISO/IEC 27001:2022 introduced 11 new controls and restructured Annex A from 114 to 93 controls across four themes. Most organisations attempting self-implementation face the same challenge: understanding which controls apply, how to evidence them, and how to structure the SoA. This framework answers all three.

93 Controls — Fully Mapped

Every Annex A control is addressed with applicability guidance, implementation notes, and exclusion justification templates. The SoA is pre-structured for Stage 2 audit submission.

Risk Register Correctly Separated

The information security risk register (Clause 6.1) is maintained structurally separate from the NC & CA Register (Clause 10.2) — the most common structural finding in Stage 1 audits.

DPIA Alignment Built In

Clause 8 operational planning incorporates data protection impact assessment alignment, supporting GDPR-adjacent obligations without duplicating documentation.

Clause 10.1 = Continual Improvement

ISO/IEC 27001:2022 Clause 10.1 covers continual improvement — not incident management. This framework correctly positions both, with incident management under Annex A.5.24–5.28.

Incident Response Structured

Annex A.5.24 to 5.28 controls provide a documented incident response process, classification framework, and evidence chain for forensic preservation.

Jurisdiction-Neutral by Design

No hardcoded regulatory references. The framework is applicable globally — adaptable to local data protection law, sector-specific requirements, or multi-site operations.

Built For

SMEs pursuing ISO 27001 certification

IT & Information Security managers

Operations and compliance teams

ISO consultants managing client implementations

Organisations transitioning from ISO 27001:2013

What You Get

Two Tiers. One Framework.

Choose the depth your organisation needs.

Professional

$149

Modules 01–06  ·  Self-implementing SME

✓

Foundation Guide & ISMS System Manual

✓

Core Procedures (10 procedures, asset classification to management review)

✓

15-template pack incl. NC & CA Register + Continual Improvement Register

✓

9-phase implementation roadmap (8–16 week timeline)

✓

Audit Pack with Stage 1 self-assessment & evidence checklist

GET PROFESSIONAL ›
MOST COMPLETE

Premium

$349

11 deliverables  ·  Compliance Manager & Consultant

✓

Everything in Professional (Modules 01–06)

✓

E2: Risk & Opportunity Register — 16 IS risks (L×I scored, CRITICAL→LOW) + 10 opportunities + KPI linkages

✓

E3: ISMS Compliance Checklist — 22/22 clause requirements, 93/93 Annex A controls verified

✓

E1: DI Register + Annex A Map — 16/16 mandatory items complete, all 93 controls mapped

✓

O7: Annex A Implementation Guide — 93 controls × 7 columns (objective, evidence, framework ref)

GET PREMIUM ›

Both tiers include immediate download  ·  Lifetime access  ·  Designed for Stage 2 audit readiness

Clause 10.1 · Improvement

Clause 10.1 Is Not Incident Management — And the Distinction Matters in a Stage 2 Audit

The single most common structural error in ISO 27001 implementations: conflating continual improvement with incident management.

SGRII Insights · ISMS

Read Article ›

Foundation · Systems

Foundation First: Why Integration Only Works When the Documents Work

Why standalone system quality is the non-negotiable prerequisite for any IMS. Document architecture matters as much as clause coverage.

SGRII Insights · Management Systems

Read Article ›

Clause 4 · Systems

Context & Scope — Where Most ISMS Implementations Fail Before They Start

Scope definition, interested parties, and the context analysis that determines whether the ISMS governs the right boundaries.

SGRII Insights · ISMS

Read Article ›

Clause 5 · Governance

Leadership — Why Signing the Information Security Policy Isn’t Leading

Top management accountability, policy governance, and the authority gap that creates audit findings.

SGRII Insights · ISMS

Read Article ›

Clause 6 · Risk

Risk, SoA & Traceability — The Architecture That Makes or Breaks Certification

Risk methodology, Statement of Applicability traceability, and the structural separation that auditors test at Stage 2.

SGRII Insights · ISMS

Read Article ›

Clause 7 · Integration

Support — Competence, Awareness, and the Documentation Reality

Resource allocation, competence evidence, awareness programmes, and documented information requirements for ISMS support.

SGRII Insights · ISMS

Read Article ›

Clause 8 · Risk

Operational Control — Where Risk Treatment Meets Evidence

Operational planning, risk treatment implementation, and the evidence chain that connects controls to the SoA.

SGRII Insights · ISMS

Read Article ›

Clause 9 · Improvement

Performance Evaluation — When Monitoring Drives Decisions, Not Reports

Internal audit, management review, and the performance evaluation framework that turns data into governance decisions.

SGRII Insights · ISMS

Read Article ›

Integration · Part 1

ISMS Integration — Building the Multi-Standard Architecture

How the ISMS integrates with ISO 9001, ISO 22301, and ISO 27701 without duplicated documentation or structural conflict.

SGRII Insights · ISMS

Read Article ›

Integration · Part 2

ISMS Integration — Shared Registers, Unified Audit Cycles

Operational integration mechanics: shared document control, combined audit programmes, and unified management review structures.

SGRII Insights · ISMS

Read Article ›

Annex A.5 · Governance

Organisational Controls — Policy vs. Control and the Evidence Gap

The 37 organisational controls in Annex A.5: policy hierarchy, access management, supplier security, and incident management architecture.

SGRII Insights · ISMS

Read Article ›

Annex A.8 · Systems

Technological Controls — Audit Evidence Beyond Configuration Screenshots

The 34 technological controls: endpoint protection, logging, network security, and the evidence auditors actually test at Stage 2.

SGRII Insights · ISMS

Read Article ›

Annex A.6 & A.7 · Governance

People & Physical Controls — The Human and Environmental Layer

Screening, awareness, disciplinary processes, physical entry controls, and the governance framework for people and premises security.

SGRII Insights · ISMS

Read Article ›

Risk Methodology

Risk Assessment — Scenario-Based Methodology for Information Security

Scenario-based risk assessment, asset-threat-vulnerability mapping, and the methodology that connects risk identification to control selection.

SGRII Insights · ISMS

Read Article ›

Corrective Action · Improvement

Corrective Action — Root Cause Analysis That Identifies System Deficiency

Why “human error” is never an acceptable root cause. System deficiency identification, evidence-based effectiveness verification, and the NC & CA architecture.

SGRII Insights · ISMS

Read Article ›

ISO 27701 · Integration

ISMS + PIMS — The Integration Architecture for ISO 27701

How the ISMS extends into a privacy information management system. Shared risk registers, combined SoA, and the architectural decisions that determine integration success.

SGRII Insights · ISMS · PIMS

Read Article ›

Internal Audit · Improvement

Internal Audit — Operational vs. Document Audit

The difference between auditing documents and auditing operations. Evidence-based audit methodology, sampling, and the findings that matter at Stage 2.

SGRII Insights · ISMS

Read Article ›

Metrics · Improvement

ISMS Metrics — Measuring Effectiveness, Not Activity

KPIs that demonstrate ISMS effectiveness to auditors and leadership. The difference between activity metrics and outcome metrics for information security.

SGRII Insights · ISMS

Read Article ›

Available Now on Gumroad

SGRII ISO 27001:2022 ISMS Framework

Two tiers. 93 controls. Audit-defensible documentation structured for certification — immediate download, no implementation support required.

Coverage is not compliance.

This framework provides structured coverage of ISO/IEC 27001:2022 requirements — documentation architecture, procedures, registers, and audit-preparation tools. It is designed for audit defensibility and structured for certification readiness. It does not certify you, does not guarantee a successful audit, and is not legal advice. You remain responsible for implementation, operation, evidence, and organizational conformity. This product does not imply endorsement by ISO, IAF, any accreditation body, or any certification body. The official ISO/IEC 27001 standard remains the only authoritative source of requirements.