ISO 27001 Guidance Documents
Purchase framework guidance directly from the ISO governing body.
Written By Micah
If you are looking to dive deeper into the ISO clause and annex requirements you can purchase the guidance documents published by the IEC, which is the governing body that maintains the ISO 27001 certification.
These documents contain detailed guidance on implementing every single annex and clause item. You can purchase the ISO/IEC 27001:2022 document here which gives guidance on implementing the clauses, and you can purchase the ISO/IEC 27002:2022
document here which gives guidance on implementing the annexes.
Both documents are great resources, most Strike Graph customers find detailed guidance on implementing annex controls more helpful since Strike Graph provided templates will satisfy most of the clause requirements.
You can find how your Strike Graph controls map to the annexes and clauses by using the framework tree (see gif below).
