NEWSLETTER

From ZERO to AUDIT-READY.

Be the GRC Practitioner AI can't replace

Our ISO/IEC 27001 Lead Implementer Toolkit gives you the roadmap, project plan and templates to be audit-ready in months, not years.

Our ISO/IEC 27001 Lead Implementer Toolkit gives you the roadmap, project plan and templates to be audit-ready in months, not years.

Trusted by 100+ Professionals

Newsletter edition preview

You are ACCOUNTABLE, if the Audit FAILS.

Most ISO 27001 projects don’t fail because people are careless. They fail because the work is fragmented: unclear ownership, scattered documents, and no reliable sequence from kickoff to audit.

You are overwhelmed.

You spend hundreds of hours researching and debating vague clauses. Every hour spent searching "how to implement Annex A" is implementation time you never get back.

You are overwhelmed.

You spend hundreds of hours researching and debating vague clauses. Every hour spent searching "how to implement Annex A" is implementation time you never get back.

You don't know where to start.

You are responsible for leading the project, but the sheer scope leaves you paralysed and unsure of the correct first move.

You don't know where to start.

You are responsible for leading the project, but the sheer scope leaves you paralysed and unsure of the correct first move.

You can't tell what's right.

You can draft a policy in seconds now. What you cannot see is whether it would survive an audit: whether the scope holds, the control fits, and the answer stands up when the auditor asks why.

You can't tell what's right.

You can draft a policy in seconds now. What you cannot see is whether it would survive an audit: whether the scope holds, the control fits, and the answer stands up when the auditor asks why.

That’s the gap our toolkit closes: one sequence, one project plan, and one set of deliverables that keeps the implementation moving.

TOOLKIT

Everything you need to take control

The toolkit turns the messy implementation into a guided operating system: navigate the work, execute the plan, deliver the evidence, and understand the system behind it.

TOOLKIT

Built on both sides of the audit table.

Created by Aron Lange

CISM

CISA

CRISC

CGEIT

ISO 27001 Lead Auditor

For years I was the auditee. As a Security Officer, I implemented and ran an ISMS in accordance with ISO 27001, and in every audit I was the one answering for it. You learn quickly what holds up and what falls apart the moment someone asks why.

Then I switched sides. As a Lead Auditor for ISO 27001 and ISO 27701, I now ask the questions. Across dozens of management systems, I kept meeting the same problem I once had myself: trained, certified professionals who could show me the policy but froze when I asked why it exists. I knew that feeling. I had been in their seat.

So I built the Toolkit from both experiences at once. The sequence follows how implementations actually unfold, because I have run one. The templates contain what certification audits actually examine, because examining them is my job.

So I built this Toolkit in the direction the audit taught me: start from what will be examined, and work backwards to what must be built. The sequence follows how implementations actually unfold, because I have run one. The templates contain what certification audits examine, because examining them is my job.

Founder of GRC Lab

Managing Director @ Lange Advisory GmbH

SEE IT IN ACTION

Watch how the toolkit guides an
ISO 27001 project

A short walkthrough of the roadmap, project plan, templates, and mind maps—so you can see how the system fits together before you buy.

Watch the
trailer

01 · NAVIGATE

Start with the roadmap — then move through the work in order

The Navigate layer gives the project its sequence: 12 connected implementation steps from defining scope through certification audit readiness.

01

Scope of the ISMS

Define what the ISMS covers so the project has clear boundaries from the start.

02

Gap Analysis

Compare your current security posture against ISO/IEC 27001:2022 requirements before you build.

03

Management Support

Secure leadership commitment, ownership, resources, and a clear reason for the certification project.

04

Information Security Policy

Create the policy foundation that communicates intent, responsibilities, and expectations across the organization.

05

Asset Inventory

Map the information assets that matter and make ownership, classification, and protection decisions visible.

06

Risk Management Methodology

Set the scoring approach, risk criteria, and repeatable method your team will use for decisions.

07

Risk Assessment

Identify, analyze, and prioritize information security risks before deciding how to treat them.

08

Risk Treatment

Choose controls, document decisions, and create a treatment plan that connects risks to action.

09

Competence & Awareness

Make sure people understand their responsibilities and can prove awareness when the auditor asks.

10

Performance Evaluation

Track whether the ISMS is working through monitoring, internal audits, and management review.

11

Improvement

Handle nonconformities, corrective actions, and continuous improvement without losing momentum.

12

Certification Audit

Prepare for Stage 1 and Stage 2 audits with the right evidence, mindset, and process readiness.

02 · EXECUTE

Turn the roadmap into action.

Each of the 12 steps breaks down into generic, actionable tasks — that can be used by any organization, regardless, of size or industry.

03 · DELIVER

The output an auditor actually wants to see.

Pre-built templates so you can focus on what really matters.

See What’s Inside Before You Buy

Get instant free access to a full preview of every template in the Toolkit so you can buy with confidence.

Policies

Processes

Records

Information Security Policy

Physical and Environmental Security Policy

Personnel Security Policy

Equipment Maintenance Policy

Removable Storage Media Policy

Remote Work Policy

Information Classification Policy

Information Handling Policy

Risk Management Policy

System Development Policy

Audit and Assessment Policy

Privacy Policy

Records Management Policy

Access Control Policy

Security Incident Management Policy

Asset and Configuration Management Policy

Business Continuity Policy

System Security Policy

Supply Chain Risk Management Policy

Identification and Authentication Policy

Policies

Processes

Records

Information Security Policy

Physical and Environmental Security Policy

Personnel Security Policy

Equipment Maintenance Policy

Removable Storage Media Policy

Remote Work Policy

Information Classification Policy

Information Handling Policy

Risk Management Policy

System Development Policy

Audit and Assessment Policy

Privacy Policy

Records Management Policy

Access Control Policy

Security Incident Management Policy

Asset and Configuration Management Policy

Business Continuity Policy

System Security Policy

Supply Chain Risk Management Policy

Identification and Authentication Policy

04 · MASTER

Mind Maps

Because a visual speaks louder than text.

Clear. Concise. Visual.

Explore beautifully-designed mind maps that simplify selected standards — available in PDF, PNG, MindNode, and FreeMind formats.

TOOLKIT

Bonus Resources

Additional resources included with your purchase

Speak every framework’s language

Align ISO 27001 with NIST CSF and NIST SP 800-53 instantly — no manual mapping required.

ONE-TIME PAYMENT

Pay once, implement anytime

Enjoy lifetime access, occasional updates, and no subscription fees.

GUARANTEE

100% Satisfaction Guarantee

We are so confident in the value of this toolkit that we offer a 14-day money back guarantee. If the toolkit does not provide the clarity you expected for building your own ISMS, we'll refund your investment in full—no questions asked. No risk in verifying the methodology for yourself

FAQ

FAQ

The answers to the most frequently asked questions.

How is this different from documents AI can generate?

How is this different from free template packs?

Is this aligned with ISO/IEC 27001:2022?

Is the Toolkit enough, or do I need training as well?

What exactly do I receive?

Can I use the Toolkit for client projects?

How long do I have access?

What if it is not right for me?

From ZERO to AUDIT-READY.

One proven sequence, one project plan, and templates built from the audit backwards. Risk-free for 14 days.

Not sure you can do this on your own? Get in touch with us.

From ZERO to AUDIT-READY.

One proven sequence, one project plan, and templates built from the audit backwards. Risk-free for 14 days.

Not sure you’ll pass on your own? Talk to a trainer first.