Guides
Practical guides to the standards we build toolkits for, written by auditors. Learn what each standard requires and how to get certified.
9 guides · filtered by Information Security
Information Security guides
Clear filter
What is ISO/IEC 27701? Building a Privacy Information Management System That Regulators Respect
Privacy has become one of the defining compliance challenges of the decade. Between the GDPR, a fast-multiplying family of national privacy laws, and customers who increasingly...

ISO/IEC 19770-1: The Complete Guide to IT Asset Management Certification
Ask most organizations how many software licenses they own, which laptops hold sensitive data, or what happens to servers at end of life, and the answers...

ISO/IEC 27017: A Practical Guide to Cloud Security Controls
The cloud rewrote the rules of information security. Assets you once locked in your own server room now live in someone else's data center, on shared...

What is ISO/IEC 42001:2023? The World's First AI Management System Standard Explained
Every transformative technology eventually gets its management system standard. Quality got ISO 9001. Information security got ISO 27001. In December 2023, artificial intelligence got ISO/IEC 42001...

Governing Artificial Intelligence: A Guide to ISO/IEC 38507:2022
Artificial intelligence has moved from the innovation lab to the boardroom agenda with startling speed. Algorithms now approve loans, screen job candidates, price products, and draft...

ISO/IEC 38500: What Every Board Should Know About IT Governance
Technology decisions have become board-level decisions. Digital transformation budgets, cyber risk, cloud strategy, AI adoption — all of them land, sooner or later, on the governing...

ISO/IEC 20000-1:2018 Explained: Your Guide to Certifiable IT Service Management
Every organization runs on services — help desks, applications, infrastructure, cloud platforms — yet remarkably few can prove those services are managed to an international benchmark....

Your Biggest Security Gap Might Be a Missing Document
Firewalls don't fail security audits — paperwork does. When an enterprise customer sends a security questionnaire, or an ISO/IEC 27001 auditor asks for your access-control policy...

What is ISO/IEC 27001:2022? A Complete Overview Guide
Information is the lifeblood of the modern organization — and the target of choice for attackers, competitors, and simple human error. ISO/IEC 27001:2022 is the world's...
Nothing matched that search Try a different term, or press Enter to search every guide.