Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # ## Sitemaps - [XML Sitemap](https://soc2.makeauditeasy.in/sitemap_index.xml): Includes all crawlable and indexable pages. ## Pages - [Compliance Wiki](https://soc2.makeauditeasy.in/compliance-wiki/): ISO/IEC 27001 1. Why Organization need ISO 27001 1.1 Who need ISO 27001 1.2 How to Select an Auditor for ISO 27001 1.3 How to Select an ISO 27001 Auditor When You Have a Budget Constraint 1.4 When Do You Need ISO 27001? 1.5 Industries That Most Commonly Need ISO 27001 1.6 When Do You Not Need ISO 27001? 2. ISO 27001 Annex A Controls - Organizational Controls (A.5 – 37 controls) ISO 27001 Annex A 5.7 Threat intelligence ISO 27001 Annex A 5.23 Information security for use of cloud services ISO 27001 Annex A 5.8 Information security in project management ISO 27001 Annex A 5.9 Inventory of information and other associated assets ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets ISO 27001 Annex A 5.11 Return of assets ISO 27001 Annex A 5.12 Classification of information ISO 27001 Annex A 5.13 Labelling of information ISO 27001 Annex A 5.14 Information transfer ISO 27001 Annex A 5.15 Access control ISO 27001 Annex A 5.16 Identity management ISO 27001 Annex A 5.1 Policies for information security ISO 27001 Annex A 5.17 Authentication information ISO 27001 Annex A 5.2 Information security roles and responsibilities ISO 27001 Annex A 5.18 Access rights – change ISO 27001 Annex A 5.3 Segregation of duties ISO 27001 Annex A 5.19 Information security in supplier relationships ISO 27001 Annex A 5.4 Management responsibilities ISO 27001 Annex A 5.20 Addressing information security within supplier agreements ISO 27001 Annex A 5.5 Contact with authorities ISO 27001 Annex A 5.21 Managing information security in the ICT supply chain ISO 27001 Annex A 5.6 Contact with special interest groups ISO 27001 Annex A 5.22 Monitoring, review and change management of supplier services ISO 27001 Annex A 5.24 Information security incident management planning and preparation ISO 27001 Annex A 5.25 Assessment and decision on information security events ISO 27001 Annex A 5.26 Response to information security incidents ISO 27001 Annex A 5.27 Learning from information security incidents ISO 27001 Annex A 5.28 Collection of evidence ISO 27001 Annex A 5.29 Information security during disruption ISO 27001 Annex A 5.30 ICT readiness for business continuity ISO 27001 Annex A 5.31 Identification of legal, statutory, regulatory and contractual requirements ISO 27001 Annex A 5.32 Intellectual property rights ISO 27001 Annex A 5.33 Protection of records ISO 27001 Annex A 5.34 Privacy and protection of PII ISO 27001 Annex A 5.35 Independent review of information security ISO 27001 Annex A 5.36 Compliance with policies and standards for information security ISO 27001 Annex A 5.37 Documented operating procedures Information Transfer Policy 3. ISO 27001 Annex A Controls - People Controls (A.6 – 8 controls) ISO 27001 Annex A 6.1 Screening ISO 27001 Annex A 6.2 Terms and conditions of employment ISO 27001 Annex A 6.3 Information security awareness, education and training ISO 27001 Annex A 6.4 Disciplinary process ISO 27001 Annex A 6.5 Responsibilities after termination or change of employment ISO 27001 Annex A 6.6 Confidentiality or non-disclosure agreements ISO 27001 Annex A 6.7 Remote working ISO 27001 Annex A 6.8 Information security event reporting 4. ISO 27001 Annex A Controls - Physical Controls (A.7 – 14 controls) ISO 27001 Annex A 7.8 Equipment siting and protection ISO 27001 Annex A 7.9 Security of assets off-premises ISO 27001 Annex A 7.10 Storage media ISO 27001 Annex A 7.11 Supporting utilities ISO 27001 Annex A 7.12 Cabling security ISO 27001 Annex A 7.13 Equipment maintenance ISO 27001 Annex A 7.14 Secure disposal or re-use of equipment ISO 27001 Annex A 7.1: Physical Security Perimeters ISO 27001 Annex A 7.2 Physical entry controls ISO 27001 Annex A 7.3 Securing offices, rooms and facilities ISO 27001 Annex A 7.4 Physical security monitoring ISO 27001 Annex A 7.5 Protecting against physical and environmental threats ISO 27001 Annex A 7.6 Working in secure areas ISO 27001 Annex A 7.7 Clear desk and clear screen 5. ISO 27001 Annex A - 8 Technological controls ISO 27001 Annex A 8.9 Configuration management ISO 27001 Annex A 8.25 Secure development lifecycle ISO 27001 Annex A 8.10 Information deletion ISO 27001 Annex A 8.26 Application security requirements ISO 27001 Annex A 8.11 Data masking ISO 27001 Annex A 8.27 Secure system architecture and engineering principles ISO 27001 Annex A 8.12 Data leakage prevention ISO 27001 Annex A 8.29 Security testing in development and acceptance ISO 27001 Annex A 8.13 Information backup ISO 27001 Annex A 8.30 Outsourced development ISO 27001 Annex A 8.14 Redundancy of information processing facilities SO 27001 Annex A 8.31 Separation of development, test and production environments ISO 27001 Annex A 8.15 Logging ISO 27001 Annex A 8.32 Change management ISO 27001 Annex A 8.16: Monitoring Activities ISO 27001 Annex A 8.33 Test information ISO 27001 Annex A 8.1 User endpoint devices ISO 27001 Annex A 8.17 Clock synchronisation ISO 27001 Annex A 8.34 Protection of information systems during audit and testing ISO 27001 Annex A 8.2 Privileged access rights ISO 27001 Annex A 8.18 Use of privileged utility programs ISO 27001 Annex A 8.3 Information access restriction ISO 27001 Annex A 8.19 Installation of software on operational systems ISO 27001 Annex A 8.4 Access to source code ISO 27001 Annex A 8.20 Network controls ISO 27001 Annex A 8.5 Secure authentication ISO 27001 Annex A 8.21 Security of network services ISO 27001 Annex A 8.6 Capacity management ISO 27001 Annex A 8.22: Segregation of Networks ISO 27001 Annex A 8.7 Protection against malware ISO 27001 Annex A 8.23 Web filtering ISO 27001 Annex A 8.8 Management of technical vulnerabilities ISO 27001 Annex A 8.24 Use of cryptography Other Doc ISO 27001 Risk Assessment Guide Example: AWS SaaS Startup ISO 27001 Statement of Applicability (SoA) Guide How to Prepare an ISO 27001 Statement of Applicability — AWS SaaS Startup Example ISO 27001 Roles & Responsibilities Template ISO 27001 RACI Matrix ISO 27001 Risk Assessment Guide ISO 27001 Implementation Guide for Startups ISO 27001 Internal Audit Checklist ISO 27001 Implementation Guide for Startups ISO 27001 Access Control Policy Segregation of Duties Policy ISO 27001 Security Awareness Policy ISO 27001 Management Review Guide ISO 27001 Authority & Regulatory Contact Register Incident Response Plan Security Incident Management Procedure Data Breach Response Procedure Regulatory Compliance Register Vulnerability Management Procedure Draft Special Interest Group Register External Security Information Monitoring Procedure Threat Intelligence Procedure Security Risk Assessment Template Threat Assessment Template Threat Intelligence Procedure Threat Intelligence Register Project Security Checklist Project Security Requirements Template Project Risk Assessment Template Security Architecture Review Template Secure Development Checklist Security Testing Checklist SaaS Application Register Data Handling Guidelines ISO 27001 Asset Lifecycle Management Procedure Data Inventory Template Acceptable Use Policy Employee IT Usage Policy AI Acceptable Use Policy Remote Working Policy BYOD (Bring Your Own Device) Policy Information Classification Policy Security Awareness Training Material Asset Return Checklist Go-Live Security Approval Form Employee Offboarding Checklist Information & Asset Inventory Template Contractor Offboarding Checklist Asset Classification Procedure IT Asset Handover Form Asset Ownership Register Access Revocation Checklist Cloud Asset Inventory Lost/Stolen Asset Incident Form Information Handling Procedure Confidential Document Template Restricted Document Template Secure Information Transfer Procedure External Data Sharing Procedure Approved Information Transfer Channels Third-Party Information Sharing Agreement Secure File Transfer Checklist Information Transfer Training User Access Request Access Control Matrix User Access Review Checklist Privileged Access Register Third-Party Access Procedure Access Review Report Joiner-Mover-Leaver Procedure Identity Management Policy User Account Management Procedure Identity Register Service Account Register Contractor Account Procedure Privileged Identity Management Procedure Identity Review Checklist Authentication & Password Policy Secrets Management Procedure PI Key Management Procedure User Access Request Form User Access Management Procedure User Onboarding & Authentication Procedure Credential Reset Procedure Credential Compromise Response Procedure Authentication Information Register Access Rights Register Periodic Access Review Template Privileged Access Review Template Contractor Access Review Checklist Supplier Security Addendum Supplier Contract Security Checklist Supplier Security Management Policy Supplier Risk Assessment Template Supplier Security Questionnaire Supplier Register Critical Supplier Register Third-Party Due Diligence Checklist Supplier Security Review Template Supplier Onboarding Checklist Supplier Offboarding Checklist Supplier Security Requirements Template Supplier Risk Assessment Data Processing Agreement Checklist Supplier Due Diligence Questionnaire Supplier Contract Review Checklist ICT Supply Chain Security Policy ICT Dependency Register Supplier Monitoring Procedure Supplier Monitoring Register Supplier Change Management Procedure Supplier Change Assessment Template Subprocessor Review Checklist Supplier Security Evidence Review Checklist Software Dependency Inventory Third-Party Software Assessment Checklist Software Bill of Materials (SBOM) Template Critical Technology Dependency Assessment Supply Chain Risk Assessment Third-Party Component Vulnerability Procedure Supply Chain Security Incident Response Procedure Draft Supplier Monitoring & Review Policy Supplier Corrective Action Register Critical Supplier Review Template Cloud Security Policy Cloud Services Register Cloud Security Risk Assessment Cloud Provider Due Diligence Questionnaire Cloud Secure Configuration Standard Cloud Incident Response Procedure Cloud Backup and Recovery Procedure Cloud Access Review Checklist Cloud Exit Checklist SaaS / Shadow IT Register Information Security Incident Management Policy Incident Response Procedure Incident Response Playbook – Account Compromise Incident Response Playbook – Ransomware Incident Response Playbook – Data Breach Incident Response Playbook – Phishing Incident Response Playbook – Cloud Compromise Incident Investigation Template Incident Timeline Template Incident Closure Report Corrective Action Tracker Incident Severity Matrix Incident Escalation Matrix Incident Response Team RACI Incident Reporting Form Incident Register Security Incident Communication Procedure Evidence Preservation Procedure Incident Response Tabletop Exercise Template Incident Response Tabletop Exercise Template Information Security Event Assessment Procedure Security Event Classification Matrix Security Event Reporting Form Security Event Register Security Alert Investigation Checklist Event-to-Incident Decision Checklist Incident Trend Report ISMS Improvement Log Incident Response Playbook Evidence Collection Procedure Evidence Collection Form Evidence Register Post-Incident Review Template Root Cause Analysis Template Lessons Learned Register Corrective Action Tracker Business Continuity Testing Checklist Chain-of-Custody Form Incident Investigation Report Digital Forensics Procedure Security Log Retention Standard Business Continuity & Information Security Policy Information Security During Disruption Procedure Business Continuity Plan Disaster Recovery Plan Emergency Access Procedure Emergency Change Procedure Disaster Recovery Test Report ICT Business Continuity Plan RTO/RPO Assessment Template ICT Dependency Register Disaster Recovery Runbook Backup & Restore Procedure Compliance Obligations Assessment Template Corrective Action Tracker Legal & Regulatory Compliance Checklist Independent Review Follow-Up Checklist Intellectual Property Protection Policy Information Security Compliance Monitoring Procedure Intellectual Property Register Security Compliance Checklist Software License Register Policy Compliance Review Checklist Open-Source Software Register Information Security Exception Register Open-Source License Review Checklist Access Compliance Review Checklist Disaster Recovery Test Plan Contractor IP Review Checklist Security Policy Acknowledgement Register Disaster Recovery Test Report Source Code Access Review Checklist Information Security Compliance Report Template ICT Recovery Checklist Third-Party Content License Register Business Impact Analysis Template Independent Information Security Review Procedure Legal & Regulatory Requirements Register Annual Security Review Plan Contractual Security Requirements Register Independent Reviewer Assessment Checklist Requirement-to-Control Mapping Matrix Information Security Review Checklist Customer Contract Security Review Checklist Independent Review Report Template Regulatory Monitoring Procedure Security Findings Register Operating Procedure Register Procedure Review Checklist Documented Operating Procedures Policy Operating Procedure Template IT Operations Procedure Access Management Procedure Change Management Procedure Production Deployment Procedure Disaster Recovery Procedure Employee Onboarding Checklist Contractor Security Agreement Employee Screening Policy Role-Based Security Responsibilities Matrix Background Verification Procedure Employee Role Change Checklist Role-Based Screening Matrix Personnel Security Audit Checklist Employee Screening Checklist Contractor Screening Procedure Screening Exception Form Background Verification Register Sensitive Role Identification Checklist HR Security Audit Checklist Human Resources Security Policy Employee Security Responsibilities Employment Security Clause Template Confidentiality Agreement Template Employee Security Acknowledgement Information Security Awareness Policy Security Awareness and Training Procedure Annual Security Awareness Plan Employee Security Training Checklist New Employee Security Onboarding Checklist Role-Based Security Training Matrix Security Awareness Training Register Phishing Awareness Procedure Information Security Disciplinary Policy Contractor Offboarding Procedure Disciplinary Process Exit Security Acknowledgement Security Violation Investigation Procedure Access Revocation Evidence Register Security Violation Classification Matrix Employee Security Violation Report Security Investigation Checklist Corrective Action Tracker Security Policy Violation Register Employee Security Conduct Guidelines Personnel Security Audit Checklist Employee Offboarding Policy Employee Termination Security Checklist Employee Role Change Checklist Security Awareness Quiz Access Revocation Checklist Security Training Effectiveness Assessment Asset Return Checklist Security Awareness Audit Checklist Privileged User Offboarding Checklist Confidentiality and Non-Disclosure Policy Employee NDA Template Contractor NDA Template Supplier Confidentiality Agreement Mutual NDA Template Confidentiality Requirements Matrix NDA and Confidentiality Agreement Register Employee Confidentiality Acknowledgement Contractor Onboarding Security Checklist Confidentiality Review Checklist Offboarding Confidentiality Checklist Supplier Contract Security Checklist Personnel Security Audit Checklist Information Security Event Reporting Policy Information Security Event Reporting Procedure View Details - [](https://soc2.makeauditeasy.in/): ISO/IEC 27001 is the internationally recognized standard for establishing and continually improving an Information Security Management System (ISMS). It helps organizations systematically identify risks, protect information, manage security controls, and demonstrate that information security is being managed effectively. - [Contact](https://soc2.makeauditeasy.in/contact/): There was an error trying to submit your form. Please try again. This field is required. This field is required. This field is required. SUBMIT There was an error trying to submit your form. Please try again. - [Privacy Policy](https://soc2.makeauditeasy.in/privacy-policy/): Suggested text: Our website address is: http://soc2.makeauditeasy.in. ## Forms - [Simple Contact Form](https://soc2.makeauditeasy.in/form/simple-contact-form/) ## Docs - [Information Security Event Reporting Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-event-reporting-procedure/) - [Information Security Event Reporting Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-event-reporting-policy/): The Information Security Event Reporting Policy establishes requirements for identifying, reporting, recording, assessing, and escalating information security events. - [Personnel Security Audit Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/personnel-security-audit-checklist-3/): The Personnel Security Audit Checklist provides a structured process for assessing whether personnel-security controls are properly designed, implemented, and operating effectively. - [Supplier Contract Security Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/supplier-contract-security-checklist-2/): The Supplier Contract Security Checklist provides a structured process for reviewing security requirements before entering into, renewing, or materially changing a contract with a supplier, vendor, service provider, consultant, cloud provider, SaaS provider, contractor, or other third party. - [Offboarding Confidentiality Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/offboarding-confidentiality-checklist/): The Offboarding Confidentiality Checklist provides a structured process for protecting confidential, sensitive, personal, customer, proprietary, and security information when an employee, contractor, consultant, supplier personnel, or other authorized individual leaves the organization or no longer requires access. - [Confidentiality Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/confidentiality-review-checklist/): The Confidentiality Review Checklist provides a structured process for reviewing whether confidentiality requirements remain appropriate and effective for employees, contractors, consultants, suppliers, partners, customers, and other parties who have access to non-public information. - [Contractor Onboarding Security Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-onboarding-security-checklist/): The Contractor Onboarding Security Checklist provides a structured process for securely onboarding contractors, consultants, freelancers, temporary workers, outsourced personnel, and other non-employees. - [Employee Confidentiality Acknowledgement](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-confidentiality-acknowledgement/): The Employee Confidentiality Acknowledgement records an employee's understanding and acceptance of the organization's confidentiality and information-protection responsibilities. - [NDA and Confidentiality Agreement Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/nda-and-confidentiality-agreement-register/): The NDA and Confidentiality Agreement Register provides a centralized record of confidentiality agreements entered into by the organization. - [Confidentiality Requirements Matrix](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/confidentiality-requirements-matrix/): The Confidentiality Requirements Matrix defines the minimum confidentiality and information-protection requirements that apply to information based on its classification, sensitivity, business purpose, and method of use or sharing. - [Mutual NDA Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/mutual-nda-template/): This Mutual Non-Disclosure Agreement (NDA) establishes the requirements for protecting confidential information exchanged between two parties during discussions, evaluation, negotiation, implementation, service delivery, partnership, or other business activities. - [Supplier Confidentiality Agreement](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/supplier-confidentiality-agreement/): This Supplier Confidentiality Agreement establishes the confidentiality obligations of a supplier, vendor, service provider, consultant company, technology provider, outsourcing provider, or other external organization that receives or accesses non-public information belonging to the Company or its customers. - [Contractor NDA Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-nda-template/): This Contractor Non-Disclosure Agreement (NDA) establishes the confidentiality and information-security obligations of a contractor, consultant, freelancer, temporary worker, or other external individual engaged by the Company. - [Employee NDA Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-nda-template/): This Employee Non-Disclosure Agreement (NDA) establishes the obligations of an employee to protect confidential, proprietary, personal, customer, technical, security, and business information obtained during employment. - [Confidentiality and Non-Disclosure Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/confidentiality-and-non-disclosure-policy/): The Confidentiality and Non-Disclosure Policy establishes requirements for protecting confidential, sensitive, proprietary, personal, customer, security, and other non-public information from unauthorized access, disclosure, use, copying, transfer, or retention. - [Access Revocation Evidence Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/access-revocation-evidence-register/): The Access Revocation Evidence Register provides a centralized record of evidence demonstrating that user access has been removed, disabled, modified, or otherwise controlled when access is no longer required. - [Exit Security Acknowledgement](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/exit-security-acknowledgement/): The Exit Security Acknowledgement records an employee's, contractor's, consultant's, or other user's confirmation of their continuing security obligations when their employment, contract, assignment, or access to the organization ends. - [Contractor Offboarding Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-offboarding-procedure/): The Contractor Offboarding Procedure defines the process for securely ending a contractor, consultant, freelancer, temporary worker, or external individual's access to organizational systems, information, facilities, and services when their engagement ends or their access is no longer required. - [Privileged User Offboarding Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/privileged-user-offboarding-checklist/): The Privileged User Offboarding Checklist provides a structured process for securely removing administrative and elevated access when a privileged user leaves the organization, changes role, loses authorization, or no longer requires privileged access. - [Asset Return Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/asset-return-checklist-2/): The Asset Return Checklist provides a structured process for recovering organizational assets when an employee, contractor, consultant, intern, supplier personnel, or other authorized user changes role or leaves the organization. - [Access Revocation Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/access-revocation-checklist-2/): The Access Revocation Checklist provides a structured process for removing user, system, application, cloud, privileged, physical, and remote access when access is no longer required. - [Employee Role Change Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-role-change-checklist-2/): The Employee Role Change Checklist provides a structured process for securely managing changes to an employee's role, responsibilities, department, employment status, or level of system access. - [Employee Termination Security Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-termination-security-checklist/): The Employee Termination Security Checklist provides a structured process for securely managing the termination of an employee, contractor, intern, consultant, or other personnel. - [Employee Offboarding Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-offboarding-policy/): The Employee Offboarding Policy establishes requirements for securely removing an employee's access, recovering organizational assets, protecting information, and completing security responsibilities when an employee leaves the organization. - [Personnel Security Audit Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/personnel-security-audit-checklist-2/): The Personnel Security Audit Checklist provides a structured method for reviewing whether personnel-security controls are defined, implemented, operating effectively, and supported by evidence. - [Employee Security Conduct Guidelines](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-security-conduct-guidelines/): The Employee Security Conduct Guidelines define the expected security behavior of employees, contractors, interns, temporary personnel, and other authorized personnel when using organizational information, systems, devices, applications, networks, cloud services, and physical facilities. - [Security Policy Violation Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-policy-violation-register/): The Security Policy Violation Register provides a centralized record of suspected, confirmed, and resolved violations of information-security policies, procedures, standards, and security requirements. - [Corrective Action Tracker](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/corrective-action-tracker-4/): The Corrective Action Tracker provides a structured method for recording, assigning, monitoring, verifying, and closing corrective actions arising from: - [Security Investigation Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-investigation-checklist/): The Security Investigation Checklist provides a structured method for investigating suspected information-security events, incidents, violations, unauthorized activity, control failures, and other security concerns. - [Employee Security Violation Report](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-security-violation-report/): The Employee Security Violation Report provides a standardized method for reporting suspected or observed violations of information-security requirements. - [Security Violation Classification Matrix](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-violation-classification-matrix/): The Security Violation Classification Matrix provides a consistent method for classifying suspected or confirmed information-security violations. - [Security Violation Investigation Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-violation-investigation-procedure/): The Security Violation Investigation Procedure defines a structured process for investigating suspected violations of information-security requirements. - [Disciplinary Process](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/disciplinary-process/): The Information Security Disciplinary Process defines how an organization should handle suspected violations of information-security requirements by employees, contractors, and other personnel. - [Information Security Disciplinary Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-disciplinary-policy/): An Information Security Disciplinary Policy establishes the organization's approach to handling violations of information-security requirements by employees, contractors, and other personnel. - [Security Awareness Audit Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-awareness-audit-checklist/): A Security Awareness Audit Checklist provides a structured method for reviewing whether an organization's security-awareness program is properly established, implemented, communicated, measured, and improved. - [Security Training Effectiveness Assessment](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-training-effectiveness-assessment/): Completing security training does not automatically mean that employees understand or apply secure practices. - [Security Awareness Quiz](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-awareness-quiz/): A Security Awareness Quiz helps employees, contractors, and other personnel test their understanding of basic information-security responsibilities. - [Phishing Awareness Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/phishing-awareness-procedure/): The Phishing Awareness Procedure defines how the organization identifies, communicates, trains, tests, monitors, and improves employee awareness against phishing and social-engineering attacks. - [Security Awareness Training Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-awareness-training-register/): The Security Awareness Training Register provides a centralized record of information-security awareness and training activities performed by the organization. - [Role-Based Security Training Matrix](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/role-based-security-training-matrix/): The Role-Based Security Training Matrix defines the security training requirements for different organizational roles based on their responsibilities, information access, system access, and security risk. - [New Employee Security Onboarding Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/new-employee-security-onboarding-checklist/): The New Employee Security Onboarding Checklist provides a structured process for securely onboarding a new employee before and after access to organizational systems and information is provided. - [Employee Security Training Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-security-training-checklist/): The Employee Security Training Checklist provides a structured method for verifying that employees receive, complete, understand, and apply required information-security training. - [Annual Security Awareness Plan](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/annual-security-awareness-plan/): The Annual Security Awareness Plan defines the organization's planned information-security awareness and training activities for the year. - [Security Awareness and Training Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-awareness-and-training-procedure/): The Security Awareness and Training Procedure defines how the organization plans, delivers, records, evaluates, and improves information-security awareness and training. - [Information Security Awareness Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-awareness-policy/): The Information Security Awareness Policy establishes the organization's requirements for ensuring that employees, contractors, consultants, interns, temporary workers, and relevant third-party personnel understand their information-security responsibilities. - [Personnel Security Audit Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/personnel-security-audit-checklist/): The Personnel Security Audit Checklist provides a structured method for reviewing whether personnel-related information-security requirements are defined, implemented, followed, and evidenced. - [Employee Role Change Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-role-change-checklist/): The Employee Role Change Checklist provides a structured process for managing security requirements when an employee changes role, department, responsibilities, location, reporting line, or level of system access. - [Role-Based Security Responsibilities Matrix](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/role-based-security-responsibilities-matrix/): The Role-Based Security Responsibilities Matrix defines information-security responsibilities for different organizational roles. - [Contractor Security Agreement](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-security-agreement/): The Contractor Security Agreement defines the information-security, confidentiality, access-control, privacy, technology, and operational-security obligations applicable to contractors providing services to the organization. - [Employee Onboarding Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-onboarding-checklist/): The Employee Onboarding Checklist provides a structured process for securely onboarding new employees and ensuring that required employment, information-security, access, confidentiality, training, and asset-management activities are completed before the employee begins normal work. - [Employee Security Acknowledgement](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-security-acknowledgement/): The Employee Security Acknowledgement records that an employee has received, reviewed, and acknowledged the organization's information-security responsibilities, policies, procedures, and applicable security requirements. - [Confidentiality Agreement Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/confidentiality-agreement-template/): Important: This is a general template for information-security and confidentiality purposes and is not legal advice. The organization should have the final agreement reviewed and adapted by qualified legal counsel for the applicable jurisdiction, employment relationship, data-protection requirements, intellectual-property provisions, and commercial terms. - [Employment Security Clause Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employment-security-clause-template/): Important: This is a security-control template, not legal advice. Employment terms should be reviewed and adapted by the organization's HR/legal function for applicable employment, privacy, labor, intellectual-property, and data-protection requirements. - [Employee Security Responsibilities](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-security-responsibilities/): The Employee Security Responsibilities document defines the information-security responsibilities expected from employees and other personnel who access organizational systems, information, facilities, or services. - [Human Resources Security Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/human-resources-security-policy/): The Human Resources Security Policy establishes the organization's requirements for managing information-security risks associated with employees, contractors, consultants, interns, temporary workers, and other personnel throughout the employment or engagement lifecycle. - [HR Security Audit Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/hr-security-audit-checklist/): The HR Security Audit Checklist provides a structured method for assessing whether personnel-security requirements are defined, implemented, followed, and supported by evidence throughout the employee lifecycle. - [Sensitive Role Identification Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/sensitive-role-identification-checklist/): The Sensitive Role Identification Checklist provides a structured method for identifying roles that may require enhanced security controls because of their access to: - [Background Verification Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/background-verification-register/): The Background Verification Register provides a centralized record of background verification activities performed for employees, contractors, consultants, interns, temporary workers, and other personnel where screening is required. - [Screening Exception Form](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/screening-exception-form/): The Screening Exception Form is used when an approved personnel screening requirement cannot be completed, cannot be completed within the required timeframe, or requires a temporary deviation from the organization's established screening requirements. - [Contractor Screening Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-screening-procedure/): The Contractor Screening Procedure defines how the organization identifies, assesses, performs, reviews, and records background screening for contractors and other non-employee personnel who may perform services on behalf of the organization. - [Employee Screening Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-screening-checklist/): The Employee Screening Checklist provides a structured method for verifying that required employee screening has been appropriately planned, authorized, completed, reviewed, and documented. - [Role-Based Screening Matrix](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/role-based-screening-matrix/): The Role-Based Screening Matrix defines the background verification and screening requirements applicable to different roles based on their responsibilities, access, information exposure, and associated security risk. - [Background Verification Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/background-verification-procedure/): The Background Verification Procedure defines how the organization performs, documents, reviews, and manages background verification for employees, contractors, interns, temporary workers, and other personnel where verification is required. - [Employee Screening Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/employee-screening-policy/): The Employee Screening Policy establishes requirements for conducting appropriate pre-employment and, where necessary, ongoing screening of employees, contractors, interns, and other personnel who may have access to organizational information, systems, facilities, or customer information. - [Procedure Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/procedure-review-checklist/): The Procedure Review Checklist provides a structured method for reviewing documented operating procedures to determine whether they remain: - [Operating Procedure Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/operating-procedure-register/): The Operating Procedure Register is the master record of documented operating procedures maintained by the organization. - [Disaster Recovery Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/disaster-recovery-procedure/): The Disaster Recovery Procedure defines how the organization restores critical information systems, applications, infrastructure, data, and technology services following a disruption or disaster. - [Production Deployment Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/production-deployment-procedure/): The Production Deployment Procedure defines how application code, infrastructure, configuration, database changes, security changes, and other technology changes are safely deployed into production. - [Change Management Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/change-management-procedure/): The Change Management Procedure defines how changes to information systems, applications, infrastructure, cloud environments, configurations, security controls, processes, and technology services are requested, assessed, approved, implemented, tested, monitored, and documented. - [Access Management Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/access-management-procedure/): The Access Management Procedure defines how user, privileged, service, application, cloud, database, and third-party access is requested, approved, provisioned, reviewed, modified, and revoked. - [IT Operations Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/it-operations-procedure/): The IT Operations Procedure defines how the organization's IT systems, infrastructure, applications, networks, cloud environments, endpoints, accounts, backups, logs, and operational services are securely managed and maintained. - [Operating Procedure Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/operating-procedure-template/): This Operating Procedure defines the standardized method for performing a specific business, information-security, technology, compliance, or operational activity. - [Documented Operating Procedures Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/documented-operating-procedures-policy/): The Documented Operating Procedures Policy establishes requirements for creating, maintaining, approving, communicating, and controlling documented operating procedures that support the organization's information-security and business operations. - [Information Security Compliance Report Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-compliance-report-template/): The Information Security Compliance Report provides a structured record of the organization's assessment of information-security compliance against applicable: - [Security Policy Acknowledgement Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-policy-acknowledgement-register/): The Security Policy Acknowledgement Register provides a structured method for recording whether personnel have received, reviewed, understood, and acknowledged applicable information-security policies. - [Access Compliance Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/access-compliance-review-checklist/): The Access Compliance Review Checklist provides a structured process for reviewing whether access to organizational information, systems, applications, cloud environments, databases, and other resources is: - [Information Security Exception Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-exception-register/): The Information Security Exception Register provides a controlled method for recording, assessing, approving, monitoring, and closing temporary or justified deviations from information-security requirements. - [Policy Compliance Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/policy-compliance-review-checklist/): The Policy Compliance Review Checklist provides a structured method for reviewing whether organizational information-security policies are: - [Security Compliance Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-compliance-checklist/): The Information Security Compliance Checklist provides a structured method for reviewing whether the organization's information-security requirements, controls, policies, and operational practices are implemented and supported by appropriate evidence. - [Information Security Compliance Monitoring Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-compliance-monitoring-procedure/): The Information Security Compliance Monitoring Procedure defines how the organization continuously monitors, evaluates, records, and reports compliance with applicable information-security requirements. - [Independent Review Follow-Up Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/independent-review-follow-up-checklist/): The Independent Review Follow-Up Checklist provides a structured process for determining whether findings identified during an independent information-security review have been appropriately addressed. - [Corrective Action Tracker](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/corrective-action-tracker-3/): The Corrective Action Tracker provides a centralized mechanism for recording, assigning, monitoring, verifying, and closing actions taken to address information-security findings, control weaknesses, incidents, audit observations, risks, and other identified issues. - [Security Findings Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/security-findings-register/): The Security Findings Register provides a centralized record for identifying, assessing, assigning, tracking, remediating, and closing information-security findings. - [Independent Review Report Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/independent-review-report-template/): This report presents the results of an independent review of the organization's information-security arrangements. - [Information Security Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/information-security-review-checklist/): The Information Security Review Checklist provides a structured method for reviewing the organization's information-security environment, controls, processes, technology, and supporting evidence. - [Independent Reviewer Assessment Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/independent-reviewer-assessment-checklist/): The Independent Reviewer Assessment Checklist provides a structured method for evaluating whether a person or organization selected to perform an independent information-security review has the required: - [Annual Security Review Plan](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/annual-security-review-plan/): The Annual Security Review Plan defines the organization's planned information-security reviews for each year. - [Independent Information Security Review Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/independent-information-security-review-procedure/): The Independent Information Security Review Procedure defines how the organization performs independent reviews of its information-security arrangements, controls, processes, and practices. - [Third-Party Content License Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/third-party-content-license-register/): The Third-Party Content License Register provides a centralized record of third-party content used, stored, published, distributed, or incorporated by the organization. - [Source Code Access Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/source-code-access-review-checklist/): The Source Code Access Review Checklist provides a structured process for reviewing access to source-code repositories, development platforms, CI/CD systems, package registries, code-hosting platforms, and related development environments. - [Contractor IP Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/contractor-ip-review-checklist/): The Contractor IP Review Checklist provides a structured process for reviewing intellectual-property ownership, confidentiality, permitted use, access, licensing, and return/deletion requirements when engaging contractors, consultants, freelancers, development partners, or other external personnel. - [Open-Source License Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/open-source-license-review-checklist/): The Open-Source License Review Checklist provides a structured process for identifying, reviewing, approving, monitoring, and documenting the licensing requirements of open-source software used by the organization. - [Open-Source Software Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/open-source-software-register/): The Open-Source Software Register provides a centralized inventory of open-source software components used by the organization. - [Software License Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/software-license-register/): The Software License Register provides a centralized record of software, SaaS products, libraries, frameworks, development tools, cloud services, AI tools, and other licensed software used by the organization. - [Intellectual Property Register](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/intellectual-property-register/): The Intellectual Property Register provides a centralized record of the organization's intellectual property (IP), ownership, classification, location, access, licensing, contractual restrictions, and protection requirements. - [Intellectual Property Protection Policy](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/intellectual-property-protection-policy/): The Intellectual Property Protection Policy establishes the organization's requirements for protecting intellectual property (IP) owned by the organization, entrusted to the organization by customers or third parties, or created by employees, contractors, and other authorized personnel. - [Legal & Regulatory Compliance Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/legal-regulatory-compliance-checklist/): The Legal & Regulatory Compliance Checklist provides a structured method for reviewing whether the organization has identified, assessed, implemented, monitored, and evidenced applicable legal, regulatory, contractual, privacy, cybersecurity, and industry requirements. - [Compliance Obligations Assessment Template](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/compliance-obligations-assessment-template/): The Compliance Obligations Assessment Template provides a structured method for identifying, understanding, assessing, documenting, and monitoring the organization's legal, regulatory, contractual, customer, industry, and other applicable compliance obligations. - [Regulatory Monitoring Procedure](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/regulatory-monitoring-procedure/): The Regulatory Monitoring Procedure defines how the organization identifies, monitors, assesses, communicates, and responds to changes in laws, regulations, regulatory guidance, industry requirements, and other applicable compliance obligations that may affect information security, privacy, technology, business operations, customers, or contractual commitments. - [Customer Contract Security Review Checklist](https://soc2.makeauditeasy.in/docs/iso-27001/other-doc/customer-contract-security-review-checklist/): The Customer Contract Security Review Checklist provides a structured method for reviewing customer contracts, agreements, statements of work, security schedules, DPAs, SLAs, and related documents for information-security, privacy, compliance, business continuity, and operational commitments.