This page is the complete inventory of what ships in the box — every template, worklist item, risk scenario and Annex A control, counted the way the workspace counts them.
The counts are real: 69 templates, 38 worklist items (31 mandatory), 102 risk scenarios, 93 controls — the same numbers you will find inside.
Everything is already drafted.
Nobody should write an ISMS policy from a blank page. Four chapters, in the order the product hands them to you: the document library, the worklist that organises it, the risk library, and the controls everything maps back to.
The document library
69 drafted templates, each generated to Word merged with your answers — your scope, your context, your decisions, not boilerplate.
- The management-system setTemplates · Clauses 4–10
- The documents your certification body reads first: the Information Security Policy, the risk assessment and treatment methodology, objectives, competence records, the internal audit programme and report, management review.Why it exists Clauses 4–10 are the management system itself — the documents that prove the ISMS is run, not just written.
- The Annex A priority setTemplates · Annex A
- The control documents auditors ask to read: access control, incident response, cloud security, backup, secure development, physical security and more.Why it exists Your SoA decides which controls apply; these drafts mean each applicable control arrives with its document already started.
- What generation doesYours — export any timeMerge · your answers → Word
- Each template generates to Word merged with your answers. Edit offline, upload your completed version — every version is stored.Why it exists A template you cannot make your own is decoration. These become your documents the moment they generate.
The worklist
A worklist, not a document dump: 38 items in two sections, each one knowing which templates merge into it and which of your answers pre-fill it.
- Section A — the management systemWorklist · MS-4.1…MS-10.2
- 25 items, one per sub-clause of Clauses 4–10: scope, policy, objectives, competence, audit programme, management review, corrective action and the rest.Why it exists Working sub-clause by sub-clause is how you know the management system is complete — not by counting files in a folder.
- Section B — Annex A prioritiesWorklist · Annex A priorities
- 13 curated control-document items — access control, incident response, cloud, backup, logging, secure development and more. Not a document per control.Why it exists A document per control would be 93 documents nobody reads. Section B covers what auditors actually ask for.
- The honest flagsFlags · 31 of 38 mandatory
- Every item carries a Mandatory / Recommended / Non-Mandatory flag taken from the document matrix.Why it exists A worklist that inflates "everything is mandatory" to look thorough wastes your time. This one never does.
The risk library
102 scenarios written in our own words, ready to score on the 5×5 grid — so your risk register starts from a defensible list, not a blank sheet.
- The core scenariosRisk library · 36 core
- 36 scenarios that apply to every organisation — the floor of any honest register, and the free starter slice on the resources page.Why it exists Some risks do not care what sector you are in. Every assessment starts by facing them.
- The sector packsRisk library · 102 total
- The remaining scenarios are sector-aware — surfaced when they fit the organisation you described in Stage 1.Why it exists A hospital and a software company do not share a threat model. The library knows the difference.
- The citationsNIST 800-30 · ATT&CK
- Each scenario carries a source citation — NIST SP 800-30 threat events and MITRE ATT&CK techniques.Why it exists When your auditor asks where a risk came from, "we thought of it" is not an answer. A citation is.
The controls
All 93 Annex A controls, mapped one-to-one — every applicability decision, risk treatment and audit finding traces back to them.
- The 93 decisionsAnnex A · themes 5/6/7/8
- Every control across the four themes — organizational, people, physical, technological — each declared Applicable or Not Applicable with a justification either way.Why it exists The Statement of Applicability is 93 justified decisions, and an auditor reads every one.
- The 17 baseline controlsPre-justified · editable
- 17 baseline controls arrive with an editable written justification already in place. The remaining decisions stay yours.Why it exists Some controls apply everywhere; drafting those justifications for you is an honest head start, not a presumption.
- Take the free resources with you
- Five working files drawn from this inventory — three download directly.
- Take the readiness check
- Computed in your browser only — nothing stored.
- See the pricing
- Where the paywall sits, stated exactly.
Clause and control references are by number with our own paraphrase — the standard's text is never reproduced. You still need your licensed copy of ISO/IEC 27001:2022, and we say so.
Your scope statement, this afternoon.
Nineteen questions about your organisation. One formal, audit-ready scope statement out the other side. Free, and yours to keep.
Start free — define your scopeSign in with your existing Google or Microsoft work account — no separate registration.