ISO 27001 policy templates
22 free, editable security policies mapped to the 93 Annex A controls of ISO/IEC 27001:2022. 91 controls are documented by at least one policy; the 2 that are not are listed below with the reason.
Written for SOC 2, mapped to Annex A
The Policyseed policies were written against the SOC 2 Trust Services Criteria, for small SaaS companies that run on a cloud provider. SOC 2 and ISO 27001 ask about largely the same things (access, change, incidents, suppliers, encryption, people), so the same documents carry over well. This page shows how far.
Each Annex A control below is mapped to the policies whose statements or procedures actually address it. We read the policy text for every mapping rather than matching on topic names, and where a policy only partly covers a control the note says so. Control numbers and short names follow the 2022 edition; the one-line summaries are our own plain-English paraphrase, not the text of the standard, which you should get from ISO or your national standards body.
Coverage at a glance
91 of 93 controls (98%) have at least one policy that documents them.
| Theme | Controls | Documented by a policy | Not covered |
|---|---|---|---|
| 5. Organizational | 37 | 37 | 0 |
| 6. People | 8 | 8 | 0 |
| 7. Physical | 14 | 12 | 2 |
| 8. Technological | 34 | 34 | 0 |
| All of Annex A | 93 | 91 | 2 |
The 2 controls the set does not cover
These are physical controls that only matter if you operate your own premises: for a cloud-hosted company they usually sit with the hosting provider or the landlord. Each one still needs an answer in your Statement of Applicability: a policy line you add, or a justified exclusion.
- 7.6 Working in secure areas. The policies assume no company-operated secure areas (no server rooms or data centres); the secure areas that hold production systems are the hosting provider's. If you operate one, add rules for working in it; otherwise record it as not applicable in your Statement of Applicability.
- 7.12 Cabling security. Not covered. For a cloud-hosted company, cabling that carries production traffic belongs to the hosting provider, and office cabling usually to the landlord; record it as such in your Statement of Applicability, or add a line if you run your own office network cabling.
A further handful are covered thinly, mostly physical controls that a cloud-hosted company inherits from its hosting provider. They are flagged with a note in the tables below.
Which policies carry the most
| Policy | Annex A controls documented |
|---|---|
| Endpoint and Workstation Security Policy | 11: 7.7, 7.9, 7.10, 7.13, 7.14, 8.1, 8.7, 8.9, 8.12, 8.19, 8.23 |
| Data Classification and Handling Policy | 10: 5.9, 5.10, 5.12, 5.13, 5.14, 5.34, 8.3, 8.11, 8.12, 8.33 |
| Secure Software Development Policy | 10: 5.8, 5.21, 5.32, 8.25, 8.26, 8.27, 8.28, 8.29, 8.31, 8.33 |
| Physical and Remote Work Security Policy | 10: 6.7, 7.1, 7.2, 7.3, 7.4, 7.5, 7.7, 7.8, 7.9, 7.11 |
| Logging and Monitoring Policy | 9: 5.7, 5.25, 5.33, 5.37, 8.6, 8.11, 8.15, 8.16, 8.17 |
| Network and Infrastructure Security Policy | 9: 5.23, 8.2, 8.9, 8.14, 8.20, 8.21, 8.22, 8.27, 8.31 |
| Information Security Policy | 8: 5.1, 5.2, 5.4, 5.6, 5.31, 5.35, 5.36, 6.3 |
| Access Control Policy | 8: 5.15, 5.16, 5.18, 6.5, 8.2, 8.3, 8.4, 8.18 |
| Change Management Policy | 8: 5.3, 8.4, 8.9, 8.19, 8.29, 8.30, 8.31, 8.32 |
| Human Resources Security Policy | 8: 5.4, 5.11, 6.1, 6.2, 6.3, 6.4, 6.5, 6.6 |
| Incident Response Policy | 7: 5.5, 5.24, 5.25, 5.26, 5.27, 5.28, 6.8 |
| Vendor and Third-Party Risk Management Policy | 7: 5.19, 5.20, 5.21, 5.22, 5.23, 6.6, 8.30 |
| Asset Management Policy | 6: 5.9, 5.11, 5.32, 7.10, 7.14, 8.6 |
| Acceptable Use Policy | 5: 5.10, 5.32, 6.7, 6.8, 8.12 |
| Business Continuity and Disaster Recovery Policy | 5: 5.29, 5.30, 5.37, 7.5, 8.14 |
| Data Retention and Disposal Policy | 4: 5.33, 7.10, 7.14, 8.10 |
| Privacy and Data Protection Policy | 4: 5.5, 5.8, 5.34, 8.10 |
| Authentication and Password Policy | 3: 5.16, 5.17, 8.5 |
| Encryption and Key Management Policy | 3: 5.3, 5.14, 8.24 |
| Vulnerability and Patch Management Policy | 3: 5.7, 8.8, 8.34 |
| Backup and Recovery Policy | 2: 5.30, 8.13 |
| Risk Assessment and Management Policy | 2: 5.35, 5.36 |
The Annex A controls list, with the policies that document each
5. Organizational controls (37)
Governance, asset and access rules, suppliers, incidents, continuity and legal obligations. The largest theme, and where most policy writing happens.
| Control | Name | In plain English | Policyseed policies |
|---|---|---|---|
| 5.1 | Policies for information security | Have a top-level security policy and supporting topic policies, approved by management, communicated to staff and reviewed on a schedule. | Information Security Policy |
| 5.2 | Information security roles and responsibilities | Decide who is responsible for which parts of security and write it down.Note: Every policy also has its own roles section. | Information Security Policy |
| 5.3 | Segregation of duties | Split conflicting duties between different people so one person cannot both make and approve a sensitive change.Note: Covered for code changes (author never approves) and key administration; there is no general segregation matrix. | Change Management Policy Encryption and Key Management Policy |
| 5.4 | Management responsibilities | Management requires everyone to follow the security policies and backs that up with funding and example. | Information Security Policy Human Resources Security Policy |
| 5.5 | Contact with authorities | Know which authorities (regulators, law enforcement) to contact and when, and keep that contact controlled. | Incident Response Policy Privacy and Data Protection Policy |
| 5.6 | Contact with special interest groups | Stay in touch with security forums, professional associations and similar groups. | Information Security Policy |
| 5.7 | Threat intelligence | Collect and analyse information about threats relevant to you and use it to adjust controls. | Vulnerability and Patch Management Policy Logging and Monitoring Policy |
| 5.8 | Information security in project management | Build security requirements into projects from the start rather than bolting them on later.Note: Covers product and feature work (threat models, privacy impact assessments); non-engineering projects are not addressed. | Secure Software Development Policy Privacy and Data Protection Policy |
| 5.9 | Inventory of information and other associated assets | Keep an up-to-date list of information and the assets that hold or process it, each with an owner. | Asset Management Policy Data Classification and Handling Policy |
| 5.10 | Acceptable use of information and other associated assets | Write down and enforce the rules for how people may use information and company assets. | Acceptable Use Policy Data Classification and Handling Policy |
| 5.11 | Return of assets | People and organisations hand back company assets when their employment or contract ends. | Asset Management Policy Human Resources Security Policy |
| 5.12 | Classification of information | Sort information into levels by how much harm its disclosure or loss would cause. | Data Classification and Handling Policy |
| 5.13 | Labelling of information | Mark information and systems with their classification so people know how to handle them. | Data Classification and Handling Policy |
| 5.14 | Information transfer | Have rules for sending information inside and outside the company, by any channel. | Data Classification and Handling Policy Encryption and Key Management Policy |
| 5.15 | Access control | Set rules for who may access information and systems, based on business and security needs. | Access Control Policy |
| 5.16 | Identity management | Manage the full lifecycle of user and system identities, one identity per person. | Access Control Policy Authentication and Password Policy |
| 5.17 | Authentication information | Control how passwords, keys and other credentials are issued, stored, reset and protected. | Authentication and Password Policy |
| 5.18 | Access rights | Grant, review, change and remove access rights through a defined, approved process. | Access Control Policy |
| 5.19 | Information security in supplier relationships | Manage the security risks that come from using suppliers' products and services. | Vendor and Third-Party Risk Management Policy |
| 5.20 | Addressing information security within supplier agreements | Put the security requirements that matter into each supplier's contract. | Vendor and Third-Party Risk Management Policy |
| 5.21 | Managing information security in the ICT supply chain | Manage the security risks further down the technology supply chain, such as sub-processors and software dependencies. | Vendor and Third-Party Risk Management Policy Secure Software Development Policy |
| 5.22 | Monitoring, review and change management of supplier services | Keep checking that suppliers deliver the agreed security, and manage changes to their service. | Vendor and Third-Party Risk Management Policy |
| 5.23 | Information security for use of cloud services | Have a process for choosing, using, managing and leaving cloud services securely.Note: Cloud providers are handled as Tier 1 vendors with exit plans, and the cloud environment is secured by the network policy; there is no standalone cloud services policy. | Vendor and Third-Party Risk Management Policy Network and Infrastructure Security Policy |
| 5.24 | Information security incident management planning and preparation | Plan in advance how incidents will be handled: roles, procedures and communication. | Incident Response Policy |
| 5.25 | Assessment and decision on information security events | Assess security events and decide whether each one is an incident. | Incident Response Policy Logging and Monitoring Policy |
| 5.26 | Response to information security incidents | Respond to incidents following the documented procedures. | Incident Response Policy |
| 5.27 | Learning from information security incidents | Use what was learned from incidents to strengthen controls. | Incident Response Policy |
| 5.28 | Collection of evidence | Identify, collect and preserve evidence about security events in a way that will stand up later. | Incident Response Policy |
| 5.29 | Information security during disruption | Keep security at an appropriate level while the business is disrupted. | Business Continuity and Disaster Recovery Policy |
| 5.30 | ICT readiness for business continuity | Plan, build and test IT recovery so continuity objectives can actually be met. | Business Continuity and Disaster Recovery Policy Backup and Recovery Policy |
| 5.31 | Legal, statutory, regulatory and contractual requirements | Identify the laws, regulations and contract terms that affect security, record them, and keep the list current.Note: Statement 4.15 and procedure 5.9 keep a register of obligations; the privacy, retention and incident policies hold the specific obligations. Which laws apply is for you and your counsel to decide. | Information Security Policy |
| 5.32 | Intellectual property rights | Respect intellectual property, including software licences and open-source terms. | Asset Management Policy Acceptable Use Policy Secure Software Development Policy |
| 5.33 | Protection of records | Protect records from loss, destruction, tampering and unauthorised access for as long as they are kept. | Data Retention and Disposal Policy Logging and Monitoring Policy |
| 5.34 | Privacy and protection of PII | Meet the privacy and personal data protection requirements that apply to you. | Privacy and Data Protection Policy Data Classification and Handling Policy |
| 5.35 | Independent review of information security | Have the security approach reviewed independently at planned intervals and after significant changes.Note: Annual independent evaluation of the risk process, plus the external SOC 2 examination. An ISMS internal audit (clause 9.2) is separate and not covered. | Risk Assessment and Management Policy Information Security Policy |
| 5.36 | Compliance with policies, rules and standards for information security | Check regularly that the company actually follows its own security policies and standards. | Information Security Policy Risk Assessment and Management Policy |
| 5.37 | Documented operating procedures | Write down operating procedures and make them available to the people who need them.Note: Recovery procedures and alert runbooks are required by these policies; each policy's section 5 is itself a procedure set. The day-to-day runbooks are yours to write. | Business Continuity and Disaster Recovery Policy Logging and Monitoring Policy |
6. People controls (8)
What happens before, during and after someone works for you: screening, agreements, training, discipline and reporting.
| Control | Name | In plain English | Policyseed policies |
|---|---|---|---|
| 6.1 | Screening | Check the background of candidates before they join, in proportion to the role and within the law. | Human Resources Security Policy |
| 6.2 | Terms and conditions of employment | Employment and contractor agreements state each side's security responsibilities. | Human Resources Security Policy |
| 6.3 | Information security awareness, education and training | Give staff security awareness and role-specific training when they join and regularly after. | Human Resources Security Policy Information Security Policy |
| 6.4 | Disciplinary process | Have a formal, communicated process for dealing with people who break security policy. | Human Resources Security Policy |
| 6.5 | Responsibilities after termination or change of employment | Make clear which security duties continue after someone leaves or changes role, and enforce them. | Human Resources Security Policy Access Control Policy |
| 6.6 | Confidentiality or non-disclosure agreements | Use confidentiality agreements with staff and outside parties, and review them when needs change. | Human Resources Security Policy Vendor and Third-Party Risk Management Policy |
| 6.7 | Remote working | Protect information that is accessed, processed or stored while working away from the office. | Physical and Remote Work Security Policy Acceptable Use Policy |
| 6.8 | Information security event reporting | Give staff a quick, simple way to report suspected security events, and expect them to use it. | Incident Response Policy Acceptable Use Policy |
7. Physical controls (14)
Premises, equipment and media. For a company whose servers all live with a cloud provider, much of this theme is inherited from the provider.
| Control | Name | In plain English | Policyseed policies |
|---|---|---|---|
| 7.1 | Physical security perimeters | Define and protect the physical boundaries around areas that hold information and equipment.Note: Data centre perimeters are delegated to the hosting provider and checked through its assurance report; office perimeters apply only where an office exists. | Physical and Remote Work Security Policy |
| 7.2 | Physical entry | Control who can enter secure areas, using entry controls and visitor procedures. | Physical and Remote Work Security Policy |
| 7.3 | Securing offices, rooms and facilities | Design and apply physical security for offices, rooms and other facilities. | Physical and Remote Work Security Policy |
| 7.4 | Physical security monitoring | Watch premises for unauthorised physical access, for example with alarms or surveillance.Note: Thin coverage: relies on the hosting provider's surveillance plus annual alarm tests and access-log reconciliation for any office. No CCTV requirement. | Physical and Remote Work Security Policy |
| 7.5 | Protecting against physical and environmental threats | Protect against fire, flood, power loss, natural disasters and other physical threats.Note: Environmental controls are the hosting provider's; multi-zone design limits the impact of a facility loss. | Physical and Remote Work Security Policy Business Continuity and Disaster Recovery Policy |
| 7.6 | Working in secure areas | Set rules for how people work inside designated secure areas.Note: The policies assume no company-operated secure areas (no server rooms or data centres); the secure areas that hold production systems are the hosting provider's. If you operate one, add rules for working in it; otherwise record it as not applicable in your Statement of Applicability. | Not covered |
| 7.7 | Clear desk and clear screen | Keep papers and removable media off desks and lock screens when away. | Physical and Remote Work Security Policy Endpoint and Workstation Security Policy |
| 7.8 | Equipment siting and protection | Place and protect equipment so it is safe from physical threats and unauthorised viewing or access.Note: Covers device storage, screen privacy and locked network cabinets; server siting is the hosting provider's. | Physical and Remote Work Security Policy |
| 7.9 | Security of assets off-premises | Protect laptops and other assets taken outside company premises. | Physical and Remote Work Security Policy Endpoint and Workstation Security Policy |
| 7.10 | Storage media | Manage storage media through its whole life: use, transport, reuse and disposal. | Asset Management Policy Endpoint and Workstation Security Policy Data Retention and Disposal Policy |
| 7.11 | Supporting utilities | Protect equipment from failures of power, cooling and other supporting utilities.Note: Delegated to hosting providers (power and cooling) and verified through their assurance reports; no office utility controls. | Physical and Remote Work Security Policy |
| 7.12 | Cabling security | Protect power and data cables from interception, interference and damage.Note: Not covered. For a cloud-hosted company, cabling that carries production traffic belongs to the hosting provider, and office cabling usually to the landlord; record it as such in your Statement of Applicability, or add a line if you run your own office network cabling. | Not covered |
| 7.13 | Equipment maintenance | Maintain equipment properly so it stays available and its information stays protected.Note: Covers laptop repairs by the manufacturer or authorised service providers; servers and network hardware are maintained by the hosting provider. | Endpoint and Workstation Security Policy |
| 7.14 | Secure disposal or re-use of equipment | Wipe or destroy data and software on equipment before it is reused or thrown away. | Asset Management Policy Data Retention and Disposal Policy Endpoint and Workstation Security Policy |
8. Technological controls (34)
Endpoints, identity, logging, networks, cryptography and the secure development of software.
| Control | Name | In plain English | Policyseed policies |
|---|---|---|---|
| 8.1 | User endpoint devices | Protect information stored on, processed by or reachable from laptops, phones and other user devices. | Endpoint and Workstation Security Policy |
| 8.2 | Privileged access rights | Restrict, control and monitor the use of administrator and other privileged access. | Access Control Policy Network and Infrastructure Security Policy |
| 8.3 | Information access restriction | Limit access to information and systems in line with the access control rules. | Access Control Policy Data Classification and Handling Policy |
| 8.4 | Access to source code | Control read and write access to source code, development tools and software libraries. | Access Control Policy Change Management Policy |
| 8.5 | Secure authentication | Use authentication methods, such as MFA, that fit the sensitivity of what is being accessed. | Authentication and Password Policy |
| 8.6 | Capacity management | Monitor resource use and plan capacity so systems keep performing as needed. | Asset Management Policy Logging and Monitoring Policy |
| 8.7 | Protection against malware | Protect against malware with tools and with user awareness. | Endpoint and Workstation Security Policy |
| 8.8 | Management of technical vulnerabilities | Find out about technical vulnerabilities, assess your exposure and fix them on time. | Vulnerability and Patch Management Policy |
| 8.9 | Configuration management | Define secure configurations for hardware, software and networks, apply them and watch for drift. | Network and Infrastructure Security Policy Endpoint and Workstation Security Policy Change Management Policy |
| 8.10 | Information deletion | Delete information when it is no longer needed. | Data Retention and Disposal Policy Privacy and Data Protection Policy |
| 8.11 | Data masking | Mask, pseudonymise or anonymise data where the full values are not needed. | Data Classification and Handling Policy Logging and Monitoring Policy |
| 8.12 | Data leakage prevention | Take measures to stop sensitive information leaking out of systems, networks and devices.Note: Handled through handling rules, removable-media blocking and quarterly exposure checks; no DLP tool is required. | Data Classification and Handling Policy Endpoint and Workstation Security Policy Acceptable Use Policy |
| 8.13 | Information backup | Take backups of information and systems and test that they restore. | Backup and Recovery Policy |
| 8.14 | Redundancy of information processing facilities | Build in enough redundancy to meet availability requirements. | Business Continuity and Disaster Recovery Policy Network and Infrastructure Security Policy |
| 8.15 | Logging | Produce, keep, protect and analyse logs of activity, errors and security events. | Logging and Monitoring Policy |
| 8.16 | Monitoring activities | Monitor networks, systems and applications for unusual behaviour and act on it. | Logging and Monitoring Policy |
| 8.17 | Clock synchronization | Synchronise system clocks to a trusted time source so events line up across systems. | Logging and Monitoring Policy |
| 8.18 | Use of privileged utility programs | Restrict and control tools that can override system and application controls. | Access Control Policy |
| 8.19 | Installation of software on operational systems | Control how software is installed on production and other operational systems. | Change Management Policy Endpoint and Workstation Security Policy |
| 8.20 | Networks security | Secure and manage networks and network devices to protect the information on them. | Network and Infrastructure Security Policy |
| 8.21 | Security of network services | Identify the security features and service levels network services need, and make sure they are delivered. | Network and Infrastructure Security Policy |
| 8.22 | Segregation of networks | Separate groups of services, users and systems onto different networks or segments. | Network and Infrastructure Security Policy |
| 8.23 | Web filtering | Control which external websites people can reach to reduce exposure to malicious content.Note: Browser safe-browsing protection on every endpoint, plus DNS or web filtering where the MDM supports it. There is no category-based blocking of websites. | Endpoint and Workstation Security Policy |
| 8.24 | Use of cryptography | Define and follow rules for using cryptography, including key management. | Encryption and Key Management Policy |
| 8.25 | Secure development life cycle | Define and apply rules for developing software and systems securely. | Secure Software Development Policy |
| 8.26 | Application security requirements | Identify and approve security requirements when building or buying applications. | Secure Software Development Policy |
| 8.27 | Secure system architecture and engineering principles | Set principles for designing secure systems and apply them to all system development. | Secure Software Development Policy Network and Infrastructure Security Policy |
| 8.28 | Secure coding | Apply secure coding principles when writing software. | Secure Software Development Policy |
| 8.29 | Security testing in development and acceptance | Define and run security tests during development and before release. | Secure Software Development Policy Change Management Policy |
| 8.30 | Outsourced development | Direct, monitor and review development work done by outside parties.Note: Contractors follow the same review and deployment process as staff; there is no dedicated outsourced-development clause. | Change Management Policy Vendor and Third-Party Risk Management Policy |
| 8.31 | Separation of development, test and production environments | Keep development, test and production environments separate and secured. | Network and Infrastructure Security Policy Secure Software Development Policy Change Management Policy |
| 8.32 | Change management | Changes to systems and information processing facilities go through a change management process. | Change Management Policy |
| 8.33 | Test information | Choose, protect and manage test data, avoiding real production data where possible. | Data Classification and Handling Policy Secure Software Development Policy |
| 8.34 | Protection of information systems during audit testing | Plan audits and technical tests of live systems so they do not disrupt operations. | Vulnerability and Patch Management Policy |
What ISO 27001 requires beyond the Annex A policies
Annex A is an appendix. The certifiable part of ISO 27001 is clauses 4 to 10, which describe an information security management system (ISMS): the way you decide what to protect, choose controls, and keep checking and improving them. Policies are one output of that system, not the system itself. In outline, and in our words:
- Context and ISMS scope (clause 4). A written scope saying which parts of the organisation, locations, products and systems the ISMS covers, informed by the issues and interested parties (customers, regulators, suppliers) that matter to you.
- Leadership (clause 5). Top management visibly owns the ISMS: approves the top-level policy, assigns roles and provides resources. The Information Security Policy covers the policy and roles; the commitment has to show up in records.
- Planning (clause 6). A defined risk assessment method, a risk treatment plan, measurable security objectives, and the Statement of Applicability: all 93 Annex A controls, whether each is included or excluded, why, and whether it is implemented. The Risk Assessment and Management Policy gives you the method and register; the Statement of Applicability and treatment plan are separate documents.
- Support (clause 7). Resources, competence of the people doing security work, awareness, communication, and control of documented information (versioning, approval and access to the documents themselves).
- Operation (clause 8). Actually running the risk assessments and treatment plan on schedule and keeping the results.
- Performance evaluation (clause 9). Monitoring and measurement, a planned internal audit programme covering the whole ISMS, and a periodic management review with defined inputs and recorded decisions.
- Improvement (clause 10). Handling nonconformities with corrective actions, and showing the ISMS gets better over time.
A certification auditor will look at these records at least as closely as at the Annex A policies. The policies here give you a head start on the control side; the scope statement, Statement of Applicability, risk treatment plan, objectives, internal audit reports and management review minutes are yours to produce.
Who certifies you
ISO 27001 certification is issued by a certification body accredited by a national accreditation body (UKAS in the UK, ANAB in the US, and their equivalents elsewhere). The audit runs in two stages: a review of your ISMS documentation, then an assessment of whether it operates in practice. A certificate lasts three years, with surveillance audits in between. Policyseed is a template generator; it does not audit or certify anyone, and adopting these templates does not by itself mean an organisation meets the standard.
If you already have SOC 2
Most of the work carries over. The same policies serve both, and the evidence you collect for SOC 2 (access reviews, change records, incident logs, vendor reviews) is the evidence an ISO auditor samples too. The additions are the management-system records above and the uncovered controls on this page. For the SOC 2 side, see the SOC 2 controls list and the full security policy templates index.
Frequently asked questions
- Are these ISO 27001 policy templates free?
- Yes. The 22 policies are Apache-2.0 licensed, and you can read every one on this site or generate the full set edited for your company without signing up. The Annex A mapping on this page is free to download as a CSV.
- How many policies does ISO 27001 require?
- The standard requires one information security policy at the top (clause 5.2) and expects topic-specific policies where your risk assessment and Statement of Applicability call for them. There is no fixed number. Most small companies end up with somewhere between 10 and 25 documents; the 22 here are split by owner and review cadence so each one stays maintainable.
- Do I need all 93 Annex A controls?
- No. Annex A is a reference list you compare your risk treatment against. Every control must appear in your Statement of Applicability, but you may exclude a control if you justify why it does not apply, for example cabling security when you have no premises of your own. What you cannot do is leave a control out without saying why.
- What changed between ISO 27001:2013 and 2022 Annex A?
- The 2013 edition had 114 controls in 14 domains. The 2022 edition regrouped them into 93 controls in four themes (organizational, people, physical and technological), merged many of the old controls and added 11 new ones, including threat intelligence, cloud services, ICT readiness for business continuity, configuration management, data masking, data leakage prevention, web filtering and secure coding. Certificates against the 2013 edition expired at the end of the transition period in October 2025.
- Can I use the same policies for SOC 2 and ISO 27001?
- Yes, and most companies that need both do exactly that. The controls overlap heavily, so one policy set mapped to both frameworks is easier to maintain than two. ISO 27001 adds management-system requirements that SOC 2 does not ask for in the same form, such as the Statement of Applicability, internal audit and management review, and those need their own records.
ISO and ISO/IEC 27001 are standards published by the International Organization for Standardization and the International Electrotechnical Commission. Policyseed is not affiliated with either. Control names are cited for reference; the summaries are our own.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.