Resources
The substance, published openly.
Plain-spoken guides, articles and checklists on compliance, testing and managed security: the kind of answers we'd give in a first call. Choose a section below to get started.
ISO 27001 toolkit
A plain-language guide and a downloadable Control Pack for all 93 ISO 27001:2022 Annex A controls. A new control publishes every day.
Browse 93 controlsISO 22301 toolkit
A plain-language guide and a downloadable Control Pack for all 26 ISO 22301:2019 business continuity (BCMS) clauses, from context to continual improvement.
Browse 26 clausesISO 27701 toolkit
A plain-language guide and a downloadable Control Pack for every ISO 27701 privacy (PIMS) clause and Annex A control, split by controller and processor duties, with DPDP Act context throughout.
Browse 43 guidesISO 42001 toolkit
A plain-language guide and a downloadable Control Pack for every ISO/IEC 42001:2023 AI management clause and Annex A control, from AI risk and impact assessment through the system life cycle.
Browse 55 guidesGuides & downloads
Whitepapers, checklists, and guides with formatted PDFs to take away. We publish the substance openly.
Browse downloadsArticles
Short, plain-spoken answers to the compliance and testing questions buyers actually ask.
Read articlesInteractive tools
Quick, interactive checks you can run yourself to baseline compliance readiness, vendor risk, security budget ROI, and maturity.
Run checksLatest articles.
- Compliance · article
ISO 27001 vs ISO 22301: information security or business continuity?
ISO 27001 protects information; ISO 22301 keeps the business running. Annex A covers ICT recovery, but here is where it stops, and when the BCMS is worth certifying.
- Compliance · article
ISO 27001 vs SOC 2: which one does your buyer actually want?
ISO 27001 certifies a management system; SOC 2 attests to your controls. Which one unblocks the deal depends on who is asking, and doing both is far less than twice the work.
- Compliance · guide
ISO 27001: a practical guide to information security management
ISO 27001 is a management system, not a checklist. Here are the core principles and a seven-step path from gap analysis to certification.
Still exploring?
Get the next resource by email.
No spam. We share the guides and tools we publish, and you can unsubscribe any time.