This page is the complete inventory of what ships in the box — every template, worklist item, risk scenario and Annex A control, counted the way the workspace counts them.

The counts are real: 69 templates, 38 worklist items (31 mandatory), 102 risk scenarios, 93 controls — the same numbers you will find inside.

The library

Everything is already drafted.

Nobody should write an ISMS policy from a blank page. Four chapters, in the order the product hands them to you: the document library, the worklist that organises it, the risk library, and the controls everything maps back to.

01

The document library

69 drafted templates, each generated to Word merged with your answers — your scope, your context, your decisions, not boilerplate.

The management-system set
Templates · Clauses 4–10
The documents your certification body reads first: the Information Security Policy, the risk assessment and treatment methodology, objectives, competence records, the internal audit programme and report, management review.
Why it exists Clauses 4–10 are the management system itself — the documents that prove the ISMS is run, not just written.
The Annex A priority set
Templates · Annex A
The control documents auditors ask to read: access control, incident response, cloud security, backup, secure development, physical security and more.
Why it exists Your SoA decides which controls apply; these drafts mean each applicable control arrives with its document already started.
What generation doesYours — export any time
Merge · your answers → Word
Each template generates to Word merged with your answers. Edit offline, upload your completed version — every version is stored.
Why it exists A template you cannot make your own is decoration. These become your documents the moment they generate.
02

The worklist

A worklist, not a document dump: 38 items in two sections, each one knowing which templates merge into it and which of your answers pre-fill it.

Section A — the management system
Worklist · MS-4.1…MS-10.2
25 items, one per sub-clause of Clauses 4–10: scope, policy, objectives, competence, audit programme, management review, corrective action and the rest.
Why it exists Working sub-clause by sub-clause is how you know the management system is complete — not by counting files in a folder.
Section B — Annex A priorities
Worklist · Annex A priorities
13 curated control-document items — access control, incident response, cloud, backup, logging, secure development and more. Not a document per control.
Why it exists A document per control would be 93 documents nobody reads. Section B covers what auditors actually ask for.
The honest flags
Flags · 31 of 38 mandatory
Every item carries a Mandatory / Recommended / Non-Mandatory flag taken from the document matrix.
Why it exists A worklist that inflates "everything is mandatory" to look thorough wastes your time. This one never does.
03

The risk library

102 scenarios written in our own words, ready to score on the 5×5 grid — so your risk register starts from a defensible list, not a blank sheet.

The core scenarios
Risk library · 36 core
36 scenarios that apply to every organisation — the floor of any honest register, and the free starter slice on the resources page.
Why it exists Some risks do not care what sector you are in. Every assessment starts by facing them.
The sector packs
Risk library · 102 total
The remaining scenarios are sector-aware — surfaced when they fit the organisation you described in Stage 1.
Why it exists A hospital and a software company do not share a threat model. The library knows the difference.
The citations
NIST 800-30 · ATT&CK
Each scenario carries a source citation — NIST SP 800-30 threat events and MITRE ATT&CK techniques.
Why it exists When your auditor asks where a risk came from, "we thought of it" is not an answer. A citation is.
04

The controls

All 93 Annex A controls, mapped one-to-one — every applicability decision, risk treatment and audit finding traces back to them.

The 93 decisions
Annex A · themes 5/6/7/8
Every control across the four themes — organizational, people, physical, technological — each declared Applicable or Not Applicable with a justification either way.
Why it exists The Statement of Applicability is 93 justified decisions, and an auditor reads every one.
The 17 baseline controls
Pre-justified · editable
17 baseline controls arrive with an editable written justification already in place. The remaining decisions stay yours.
Why it exists Some controls apply everywhere; drafting those justifications for you is an honest head start, not a presumption.
Where next
Take the free resources with you
Five working files drawn from this inventory — three download directly.
Take the readiness check
Computed in your browser only — nothing stored.
See the pricing
Where the paywall sits, stated exactly.

Clause and control references are by number with our own paraphrase — the standard's text is never reproduced. You still need your licensed copy of ISO/IEC 27001:2022, and we say so.

Begin

Your scope statement, this afternoon.

Nineteen questions about your organisation. One formal, audit-ready scope statement out the other side. Free, and yours to keep.

Start free — define your scope

Sign in with your existing Google or Microsoft work account — no separate registration.

What's inside — ISO 27001 — regXperience