Skip to content
TRANSFORMATIONAVAILABLE

ISO 27001 Transformation System

A complete practical framework for building, operating and continually improving an information security management system aligned with ISO/IEC 27001:2022

A comprehensive implementation framework that takes an organisation through the practical journey of establishing, operating and continually improving an information security management system aligned with ISO/IEC 27001:2022.

DOCUMENTS
151DOCUMENTS
CONTROL REFERENCES
93CONTROL REFERENCES
REGISTERS
21REGISTERS
BUY NOW — £399.99

One-time payment. Includes all future updates to this system.

ISO 27001 Transformation System cover: charcoal ground, thin gold corner framing and a large serif title.
Cover — the management system, from context and risk through to certification readiness.

OVERVIEW

Why it exists.

Most organisations meeting ISO/IEC 27001:2022 for the first time do not fail for want of intent. They fail because the work arrives as a pile of disconnected parts. A risk assessment nobody can repeat, policies written to be filed rather than followed, a Statement of Applicability assembled the week before an assessment, and no evidence that any of it has actually been operating.

This system replaces that with a sequence. It takes an organisation from context, scope and an honest gap assessment, through risk management, control selection and the Statement of Applicability, into the policies, procedures and registers that make the management system real — and then into the evidence, measurement, internal audit, management review and corrective action that keep it alive and make it demonstrable. It is a structured path through the transformation rather than a collection of templates.

FEATURES

Nine stages, in the order they have to happen.

ASSESS

An honest starting position

A gap assessment across twenty-three requirement areas, scored zero to five against evidence you can actually produce. It tells you where you are before anyone commits to a date, and it is the same scale you re-score against later, so progress is comparable rather than asserted.

DEFINE

Context, scope and obligations

Internal and external issues, interested parties and their requirements, and a scope statement drafted as the sentence you want on a certificate and then worked backwards. Includes the climate change consideration added by ISO/IEC 27001:2022/Amd 1:2024, described honestly and proportionately.

PLAN

A programme that survives the day job

Mandate, sponsorship, roles and an effort model in person-days, with three routes — twelve months, six to seven months, and an accelerated path with the preconditions it genuinely requires and the point at which you should step back to a longer one.

DESIGN

A risk method you can repeat

Asset, threat and vulnerability structure, a fifty-four entry threat library, likelihood and impact criteria, five risk bands and four treatment options. The output feeds control selection directly, so the Statement of Applicability is derived from risk rather than reverse engineered.

IMPLEMENT

Every control, with an owner

Implementation guidance for all ninety-three Annex A control references across the four themes, each with what implementing it proportionately looks like, the decisions you have to make, the evidence it produces and the way it commonly fails.

DOCUMENT

Policies and procedures that are usable

Thirty policies with numbered, testable statements an audit finding can cite, and eighteen procedures written so a competent person who has never run one can follow it without asking a question. Supplied as designed PDFs and editable Word documents.

MEASURE

Evidence as a by-product of the work

An evidence model with five evidence types, a naming convention and retention, a lookup of what evidence each requirement needs, and twelve measures with sources, owners and frequencies. Designed so the records accumulate as you work rather than in a scramble beforehand.

AUDIT

Assurance that finds real things

An audit programme across the twenty-three requirement areas, auditor competence and independence, checklists by requirement area, working papers and sampling, the four finding categories, root cause analysis and corrective action tracked through to verified effectiveness.

CERTIFICATION READINESS

Prepared, not hopeful

What a certification body actually assesses and how the two stages differ, a readiness assessment on a zero-to-five scale, control-by-control preparation, how to run the assessment days, and how to respond to findings. Readiness scoring is a management tool for your own use, never a prediction of an outcome.

WHO IT IS FOR

Written for whoever has been handed this.

  • Heads of IT and Technology

    Handed ISO 27001 on top of a full-time job because a customer or a contract has made it a condition, usually without a dedicated hire.

  • Information Security and Risk Managers

    Building or rebuilding a management system that has to hold up under independent assessment rather than merely exist on a shared drive.

  • Compliance and Governance Leads

    Accountable for the documentation, the evidence and the review cycle across several frameworks, and needing one that is genuinely operable.

  • Operations and Delivery Directors

    Answering security questionnaires that keep arriving with sales opportunities attached, and wanting a defensible answer rather than a hopeful one.

GALLERY

Transformation journey slide showing nine sequential stages from assess to certification readiness.
The transformation journey — nine stages, and the evidence each leaves.
Risk scoring slide showing a five by five likelihood and impact grid with five named response bands.
The risk model — likelihood by impact, five bands, one response each.
Control themes slide showing four columns for the organisational, people, physical and technological themes with their reference ranges.
The control themes — four themes, ninety-three control references.
Evidence model slide showing five tiles for documented information, operating records, system output, decision records and assurance output.
The evidence model — five kinds of evidence, and what each one proves.
Certification readiness slide showing a seven step path alongside a zero to five readiness scale.
Certification readiness — seven steps, scored honestly at each one.
ISO 27001 Transformation System cover slide with the chrysalis mark and a serif title on a charcoal ground.
The system at a glance — one library, one sequence, one licence.

WHAT’S INCLUDED

12 core components, one download.

  • PDF

    Gap Assessment and Roadmaps

    The gap assessment method across twenty-three requirement areas, plus the twelve-month and accelerated roadmaps and the operating calendar.

  • PDF

    Context and Scope

    Organisational context, interested parties, obligations, the climate change consideration, and the scope statement template.

  • PDF

    Leadership and Objectives

    Top management commitment in practice, the policy framework, security objectives, and the authorities and accountabilities reference.

  • PDF

    Risk Management System

    The risk method, criteria and appetite, asset mapping, a fifty-four entry threat library, treatment, residual risk and reassessment.

  • PDF

    Statement of Applicability

    What it has to do, applicability decided theme by theme, justifications that survive challenge, and how to maintain it over time.

  • PDF

    Control Implementation

    Implementation guidance for all ninety-three Annex A control references across the organisational, people, physical and technological themes.

  • DOCX

    Thirty Policies

    A complete policy library with numbered, testable statements, roles, exceptions and review cycles — adoptable as written, editable throughout.

  • DOCX

    Eighteen Procedures

    Access, assets, risk, change, vulnerabilities, backup, incident response, continuity, supplier, audit, corrective action and management review.

  • XLSX

    Fourteen Workbooks

    Twenty-one registers with working formulas, validation and conditional formatting: risk, applicability, assets, suppliers, evidence, audit, incidents, objectives and readiness.

  • PDF

    Evidence and Measurement

    The evidence model and naming convention, what evidence each requirement needs, the measurement framework and the reporting packs.

  • PDF

    Audit, Review and Improvement

    The internal audit programme and checklists, management review, nonconformity and corrective action, and the improvement pipeline.

  • PPTX

    Three Presentation Decks

    The executive case for the management system, the management review pack and an all-staff awareness briefing, each with full speaker notes.

FAQ

Before you buy.

  • One hundred and fifty-one documents across twenty-one numbered folders, each supplied both as a designed PDF and an editable Word document: the gap assessment and roadmaps, context and scope, leadership and objectives, the risk management system, the Statement of Applicability, implementation guidance for all ninety-three control references, thirty policies, eighteen procedures, evidence management, internal audit, management review, corrective action, certification readiness, continual improvement and reporting. Alongside them, fourteen Excel workbooks holding twenty-one registers, and three PowerPoint decks.

REVIEWS

Newly released.

This product has just been published, so there are no customer reviews yet. We would rather show you an empty space than a testimonial we wrote ourselves.

Bought it? Tell us how it went — the first reviews will appear here.

Turn scattered controls into a system you can evidence.

ISO 27001 Transformation Systema complete practical framework for building, operating and continually improving an information security management system aligned with ISO/IEC 27001:2022.

BUY NOW — £399.99

One-time payment. Includes all future updates to this system.

Digital Chrysalis © 2026

BUILD • TRANSFORM • EMERGE