Home › ISO Digital Products › All Products › ISO 27001:2022 — ISMS
SGRII Digital Solutions · Information Security
ISO/IEC 27001:2022
ISMS Framework
All 93 Annex A controls. Statement of Applicability, DPIA alignment, and a structured ISMS built for SMEs pursuing certification — or maintaining continual improvement under an existing certificate.
Framework at a Glance
✓93 Annex A controls covered
✓Statement of Applicability (SoA)
✓10 Core procedures
✓15 Excel templates & registers
✓Risk & Opportunity Register (Cl.6.1)
✓NC & CA Register (Cl.10.2)
✓Internal audit pack & checklists
✓Clause 10.1 — Continual Improvement
Why Organisations Choose This Framework
Information Security Without the Guesswork
ISO/IEC 27001:2022 introduced 11 new controls and restructured Annex A from 114 to 93 controls across four themes. Most organisations attempting self-implementation face the same challenge: understanding which controls apply, how to evidence them, and how to structure the SoA. This framework answers all three.
93 Controls — Fully Mapped
Every Annex A control is addressed with applicability guidance, implementation notes, and exclusion justification templates. The SoA is pre-structured for Stage 2 audit submission.
Risk Register Correctly Separated
The information security risk register (Clause 6.1) is maintained structurally separate from the NC & CA Register (Clause 10.2) — the most common structural finding in Stage 1 audits.
DPIA Alignment Built In
Clause 8 operational planning incorporates data protection impact assessment alignment, supporting GDPR-adjacent obligations without duplicating documentation.
Clause 10.1 = Continual Improvement
ISO/IEC 27001:2022 Clause 10.1 covers continual improvement — not incident management. This framework correctly positions both, with incident management under Annex A.5.24–5.28.
Incident Response Structured
Annex A.5.24 to 5.28 controls provide a documented incident response process, classification framework, and evidence chain for forensic preservation.
Jurisdiction-Neutral by Design
No hardcoded regulatory references. The framework is applicable globally — adaptable to local data protection law, sector-specific requirements, or multi-site operations.
Built For
SMEs pursuing ISO 27001 certification
IT & Information Security managers
Operations and compliance teams
ISO consultants managing client implementations
Organisations transitioning from ISO 27001:2013
What You Get
Two Tiers. One Framework.
Choose the depth your organisation needs.
Professional
$149
Modules 01–06 · Self-implementing SME
Foundation Guide & ISMS System Manual
Core Procedures (10 procedures, asset classification to management review)
15-template pack incl. NC & CA Register + Continual Improvement Register
9-phase implementation roadmap (8–16 week timeline)
Audit Pack with Stage 1 self-assessment & evidence checklist
Premium
$349
11 deliverables · Compliance Manager & Consultant
Everything in Professional (Modules 01–06)
E2: Risk & Opportunity Register — 16 IS risks (L×I scored, CRITICAL→LOW) + 10 opportunities + KPI linkages
E3: ISMS Compliance Checklist — 22/22 clause requirements, 93/93 Annex A controls verified
E1: DI Register + Annex A Map — 16/16 mandatory items complete, all 93 controls mapped
O7: Annex A Implementation Guide — 93 controls × 7 columns (objective, evidence, framework ref)
Both tiers include immediate download · Lifetime access · Designed for Stage 2 audit readiness
SGRII Insights
ISO 27001:2022 — Further Reading
Clause 10.1 · Improvement
Clause 10.1 Is Not Incident Management — And the Distinction Matters in a Stage 2 Audit
The single most common structural error in ISO 27001 implementations: conflating continual improvement with incident management.
SGRII Insights · ISMS
Read Article ›Foundation · Systems
Foundation First: Why Integration Only Works When the Documents Work
Why standalone system quality is the non-negotiable prerequisite for any IMS. Document architecture matters as much as clause coverage.
SGRII Insights · Management Systems
Read Article ›Clause 4 · Systems
Context & Scope — Where Most ISMS Implementations Fail Before They Start
Scope definition, interested parties, and the context analysis that determines whether the ISMS governs the right boundaries.
SGRII Insights · ISMS
Read Article ›Clause 5 · Governance
Leadership — Why Signing the Information Security Policy Isn’t Leading
Top management accountability, policy governance, and the authority gap that creates audit findings.
SGRII Insights · ISMS
Read Article ›Clause 6 · Risk
Risk, SoA & Traceability — The Architecture That Makes or Breaks Certification
Risk methodology, Statement of Applicability traceability, and the structural separation that auditors test at Stage 2.
SGRII Insights · ISMS
Read Article ›Clause 7 · Integration
Support — Competence, Awareness, and the Documentation Reality
Resource allocation, competence evidence, awareness programmes, and documented information requirements for ISMS support.
SGRII Insights · ISMS
Read Article ›Clause 8 · Risk
Operational Control — Where Risk Treatment Meets Evidence
Operational planning, risk treatment implementation, and the evidence chain that connects controls to the SoA.
SGRII Insights · ISMS
Read Article ›Clause 9 · Improvement
Performance Evaluation — When Monitoring Drives Decisions, Not Reports
Internal audit, management review, and the performance evaluation framework that turns data into governance decisions.
SGRII Insights · ISMS
Read Article ›Integration · Part 1
ISMS Integration — Building the Multi-Standard Architecture
How the ISMS integrates with ISO 9001, ISO 22301, and ISO 27701 without duplicated documentation or structural conflict.
SGRII Insights · ISMS
Read Article ›Integration · Part 2
ISMS Integration — Shared Registers, Unified Audit Cycles
Operational integration mechanics: shared document control, combined audit programmes, and unified management review structures.
SGRII Insights · ISMS
Read Article ›Annex A.5 · Governance
Organisational Controls — Policy vs. Control and the Evidence Gap
The 37 organisational controls in Annex A.5: policy hierarchy, access management, supplier security, and incident management architecture.
SGRII Insights · ISMS
Read Article ›Annex A.8 · Systems
Technological Controls — Audit Evidence Beyond Configuration Screenshots
The 34 technological controls: endpoint protection, logging, network security, and the evidence auditors actually test at Stage 2.
SGRII Insights · ISMS
Read Article ›Annex A.6 & A.7 · Governance
People & Physical Controls — The Human and Environmental Layer
Screening, awareness, disciplinary processes, physical entry controls, and the governance framework for people and premises security.
SGRII Insights · ISMS
Read Article ›Risk Methodology
Risk Assessment — Scenario-Based Methodology for Information Security
Scenario-based risk assessment, asset-threat-vulnerability mapping, and the methodology that connects risk identification to control selection.
SGRII Insights · ISMS
Read Article ›Corrective Action · Improvement
Corrective Action — Root Cause Analysis That Identifies System Deficiency
Why “human error” is never an acceptable root cause. System deficiency identification, evidence-based effectiveness verification, and the NC & CA architecture.
SGRII Insights · ISMS
Read Article ›ISO 27701 · Integration
ISMS + PIMS — The Integration Architecture for ISO 27701
How the ISMS extends into a privacy information management system. Shared risk registers, combined SoA, and the architectural decisions that determine integration success.
SGRII Insights · ISMS · PIMS
Read Article ›Internal Audit · Improvement
Internal Audit — Operational vs. Document Audit
The difference between auditing documents and auditing operations. Evidence-based audit methodology, sampling, and the findings that matter at Stage 2.
SGRII Insights · ISMS
Read Article ›Metrics · Improvement
ISMS Metrics — Measuring Effectiveness, Not Activity
KPIs that demonstrate ISMS effectiveness to auditors and leadership. The difference between activity metrics and outcome metrics for information security.
SGRII Insights · ISMS
Read Article ›Available Now on Gumroad
SGRII ISO 27001:2022 ISMS Framework
Two tiers. 93 controls. Audit-defensible documentation structured for certification — immediate download, no implementation support required.
Coverage is not compliance.
This framework provides structured coverage of ISO/IEC 27001:2022 requirements — documentation architecture, procedures, registers, and audit-preparation tools. It is designed for audit defensibility and structured for certification readiness. It does not certify you, does not guarantee a successful audit, and is not legal advice. You remain responsible for implementation, operation, evidence, and organizational conformity. This product does not imply endorsement by ISO, IAF, any accreditation body, or any certification body. The official ISO/IEC 27001 standard remains the only authoritative source of requirements.