Compliance library

Guides

Practical guides to the standards we build toolkits for, written by auditors. Learn what each standard requires and how to get certified.

9 guides · filtered by Information Security

Information Security guides

Clear filter
What is ISO/IEC 27701? Building a Privacy Information Management System That Regulators Respect
Information Security

What is ISO/IEC 27701? Building a Privacy Information Management System That Regulators Respect

Privacy has become one of the defining compliance challenges of the decade. Between the GDPR, a fast-multiplying family of national privacy laws, and customers who increasingly...

Apr 1, 2026 4 min read
ISO/IEC 19770-1: The Complete Guide to IT Asset Management Certification
Information Security

ISO/IEC 19770-1: The Complete Guide to IT Asset Management Certification

Ask most organizations how many software licenses they own, which laptops hold sensitive data, or what happens to servers at end of life, and the answers...

Mar 20, 2026 4 min read
ISO/IEC 27017: A Practical Guide to Cloud Security Controls
Information Security

ISO/IEC 27017: A Practical Guide to Cloud Security Controls

The cloud rewrote the rules of information security. Assets you once locked in your own server room now live in someone else's data center, on shared...

Mar 11, 2026 4 min read
What is ISO/IEC 42001:2023? The World's First AI Management System Standard Explained
Information Security

What is ISO/IEC 42001:2023? The World's First AI Management System Standard Explained

Every transformative technology eventually gets its management system standard. Quality got ISO 9001. Information security got ISO 27001. In December 2023, artificial intelligence got ISO/IEC 42001...

Feb 27, 2026 4 min read
Governing Artificial Intelligence: A Guide to ISO/IEC 38507:2022
Information Security

Governing Artificial Intelligence: A Guide to ISO/IEC 38507:2022

Artificial intelligence has moved from the innovation lab to the boardroom agenda with startling speed. Algorithms now approve loans, screen job candidates, price products, and draft...

Feb 17, 2026 4 min read
ISO/IEC 38500: What Every Board Should Know About IT Governance
Information Security

ISO/IEC 38500: What Every Board Should Know About IT Governance

Technology decisions have become board-level decisions. Digital transformation budgets, cyber risk, cloud strategy, AI adoption — all of them land, sooner or later, on the governing...

Feb 4, 2026 4 min read
ISO/IEC 20000-1:2018 Explained: Your Guide to Certifiable IT Service Management
Information Security

ISO/IEC 20000-1:2018 Explained: Your Guide to Certifiable IT Service Management

Every organization runs on services — help desks, applications, infrastructure, cloud platforms — yet remarkably few can prove those services are managed to an international benchmark....

Jan 22, 2026 4 min read
Your Biggest Security Gap Might Be a Missing Document
Information Security

Your Biggest Security Gap Might Be a Missing Document

Firewalls don't fail security audits — paperwork does. When an enterprise customer sends a security questionnaire, or an ISO/IEC 27001 auditor asks for your access-control policy...

Jan 21, 2026 1 min read
What is ISO/IEC 27001:2022? A Complete Overview Guide
Information Security

What is ISO/IEC 27001:2022? A Complete Overview Guide

Information is the lifeblood of the modern organization — and the target of choice for attackers, competitors, and simple human error. ISO/IEC 27001:2022 is the world's...

Jan 9, 2026 4 min read