ISO/IEC 27001:2022 Document Kits
The ISO 27001 Document Kits by KLS Academy PLT provide a structured set of ready-to-use documents to support organizations in implementing and achieving ISO/IEC 27001:2022 Information Security Management System (ISMS) certification. Priced at RM3,899, this package includes 57 essential documents, categorized into four levels.
The document kits comprise general templates. If your organization requires further customization based on your business processes, activities, scope, and context, you may Request for Quotation by contacting us at enquiry@kls-academy.com.
The document kit is structured into four levels for clarity, ease of implementation, and compliance assurance:
Level 1: Manual (7 Files)
Covers the ISMS Manual, Policies, Objectives, key registers for internal and external information security issues, stakeholder expectations, and process mapping.
- Information Security Management System Manual
- ISMS Policy
- ISMS Objectives
- Internal and External Issues Register
- Needs and Expectations of Interested Parties Register
- Roles & Responsibilities of ISMS Steering Committee
- Process Mapping
Level 2: Mandatory Procedures (10 Files)
Includes key ISMS procedures, such as risk assessment and treatment, incident management, access control, business continuity, compliance, internal audits, and corrective actions.
- Control of Documented Information
- Information Security Risk Assessment
- Information Security Risk Treatment
- Incident Management and Response
- Internal Audit
- Management Review
- Nonconformity and Corrective Action
- Access Control and Identity Management
- Business Continuity and Disaster Recovery Plan
- Compliance with Legal, Regulatory, and Contractual Requirements
Level 2: Standard Operating Procedures (SOPs) (10 Files)
Provides detailed SOPs for security risk management, incident handling, access control, cryptographic management, data backup, network security, and secure software development.
- SOP for Information Security Risk Management
- SOP for Security Incident Handling and Reporting
- SOP for Asset Management and Classification
- SOP for Access Control Management
- SOP for Cryptographic Key Management
- SOP for Data Backup and Recovery
- SOP for Secure Software Development Lifecycle (SDLC)
- SOP for Patch Management and Vulnerability Assessment
- SOP for Network Security and Firewalls
- SOP for Physical and Environmental Security
Level 3: Work Instructions (10 Files)
Offers step-by-step instructions for securing IT systems, covering user access, data disposal, third-party security, personal data protection, cloud security, and endpoint protection.
- Work Instruction for Managing User Accounts and Privileged Access
- Work Instruction for Secure Disposal of Data and IT Equipment
- Work Instruction for Managing Third-Party Security Risks
- Work Instruction for Handling Personal Identifiable Information (PII)
- Work Instruction for Secure Configuration of IT Systems
- Work Instruction for Secure Authentication and Multi-Factor Authentication (MFA)
- Work Instruction for Security Monitoring and Log Management
- Work Instruction for Secure Remote Access and VPN Usage
- Work Instruction for Mobile Device and Endpoint Security
- Work Instruction for Cloud Security and Data Protection
Level 4: Forms and Checklists (20 Files)
Includes essential templates and checklists, such as risk assessments, incident reports, access control reviews, legal compliance, backup verification, security performance monitoring, and internal audit documentation.
- Master List of Documents
- Information Security Risk Assessment Form
- Incident Report and Investigation Form
- Access Control Review Checklist
- Internal Audit Program
- Internal Audit Plan
- Internal Audit Checklist
- Internal Audit Report
- Non-Conformity and Corrective Action Report
- Supplier Security Compliance Evaluation Form
- Data Classification and Handling Checklist
- Backup and Recovery Verification Form
- Compliance and Legal Requirements Checklist
- Performance Monitoring Checklist
- Performance Monitoring Dashboard
- Management Review Meeting Minutes Template
- Staff Training Attendance Form
- Employee Competency Assessment Form
- Training Evaluation Feedback Form
- Continual Improvement Register