Description
All ISO documents are designed under the guidance of experienced ISO consultants.
Content of EU GDPR Integrated with ISO 27001 ISMS Documentation Kit
The EU GDPR and ISO 27001 integrated documents are editable and many organizations and ISO 27001 consultants are using these documents. The contents of the documentation kit, which we offer, include more than 155 editable files as listed below. These are written in easy to understand language and available in editable format.
- ISMS Manual: A sample ISO 27001:2013 manual is given, which explains macro-level management strategy and commitment and how the information security system is implemented.
- ISMS and GDPR Policy: 23 ISMS policies and 06 GDPR policies are given in this module, which helps to frame the information security controls and GDPR implementation.
- ISO 27001 and GDPR Procedures: It includes 12 information security and 7 ISMS system related procedures as well as 6 GDPR procedures to implement the effective system in the organization.
- Standard Operating Procedures: There are 9 SOPs given to establish controls for information security.
- Process Flow Charts: Total 06 Process flow charts that cover process flow activities of all the main and critical processes with an input-output matrix for a manufacturing organization.
- Forms for record-keeping: A set of 45 ISMS templates and 16 GDPR templates, which are sample forms to demonstrate the implementation of the integrated EU GDPR and ISMS systems.
- Filled forms: It includes a total of 9 filled forms for an asset register, risk assessment, risk treatment, scope document for quick record keeping as well as 6 job descriptions filled formats.
- ISO 27001 Audit checklist: It includes more than 500 audit questions for auditing implemented systems.
- Audit questions to verify mandatory system implementation points
- ISMS controls related to ISO 27001:2013 audit checklist
- Good information security related to best practice verification questions.
- Document Compliance Matrix: It includes a 01 Excel file with GDPR as well as an information security management system document compliance matrix.
The entire integrated EU GDPR and ISO 27001:2013 documents listed above are editable. Users can easily modify the name of the company, its logo, and other required parameters to prepare its organizational GDPR and information security system based documents quickly and economically.
The integrated system implementation of the General Data Protection Regulation(GDPR) and Information Security Management System(ISMS) to develop data protection and information security-related controls are necessary for every IT operational organization. Our EU GDPR – ISO 27001 Documents kit gives more than 155 different types of sample templates to establish a well-integrated system as per GDPR and ISMS requirements.
Documentation: –
Our documentation kit contains sample documents required for system certification as listed below. All documents are in MS-Word/Excel files and you can edit them. You can make changes as per your organization’s need and within few days your entire documents with all necessary controls will be ready. In the ISO 27001:2022, documented information (procedures, SOPs, etc.) are required a few places only. But for making the system better, we have provided many editable templates from which a user can select templates as per their own requirement and make some minor changes in them to make own system. Two types of documented information are provided in this kit, as listed below:
- Maintain documented information (Scope, Manual, etc.)
- Retain documented information (Forms / Templates)
Under the main directories, further files are provided in MS Word document as per the details given below.
1. ISMS Manual:
It covers sample copy of information security management system manual and clause wise details for how ISMS systems are implemented. It covers list of procedures as well as overview of organization and covers tier1 of ISMS documents.
(A) Table of Contents
4 to 10 – Detail chapters explaining management commitment and at macro level how system is implemented to comply requirements
2. GDPR & Information Security Policies
2.1 Information security Policies (29 policies)
It covers guideline for controls applied as per ISMS guidelines. The policy document templates are provided to frame the information security controls as listed below.
List of policies
- Acceptable Use Policy-Information Services
- Infrastructure Policy
- Policy for Access Card
- Backup Policy
- Clear Desk and Clear Screen Policy
- Physical Media & Disposal Sensitive Data
- Electronic Devices Policy
- LAN Policy
- Training Policy
- Mobile Computing Policy
- Telework Policy
- Laptop Policy
- Internet acceptable user policy
- Messenger and E-mail
- Password Policy
- Patch Management
- User Registration Access Management
- Policy for Working in Secured Areas
- Visitor Policy
- Work Station Policy
- Cryptographic Policy
- IT Access Control Policy
- Change Control
- Cloud Security Policy
- Freeware and Shareware Policy
- Operation Security
- IT Incident Recording and Reporting Policy
- Personally identifiable information policy (PII)
- Data Protection Policy
2.2 GDPR Policies (06 policies)
It covers guideline applied as per GDPR guidelines. The policy document templates are provided to frame the GDPR implementation as listed below.
List of Policies
- Data Protection Policy
- Privacy by Design / by Default Policy
- Data Retention Policy
- Cross-border processing or transfers of personal data
- Data Classification Policy
- Cookies Policy
3. GDPR & Information Security Procedures
3.1 Information security procedures (20 procedures)
It covers sample copy of mandatory all the Information security management system procedures covering all the details as per ISMS requirements.
List of ISMS Procedures
- Procedure for Management Review
- Procedure for Documented Information Control
- Procedure for Corrective Action
- Procedure for Control of Record
- Procedure for Information Security Management System Internal Audit
- Procedure for Control of Nonconformity and Improvement
- Procedure for Personnel and Training
- Procedure for Scope Documentation for Implementation
- Approach Procedure for ISMS Implementation
- Procedure for Risk Assessment
- Procedure for ISMS change management
- Procedure for Organization Security
- Procedure for Assets Classification & Control
- Procedure for Human Resource Security
- Procedure for Physical and Environmental Security
- Procedure for Communication & Operational Management
- Procedure for Access Control
- Procedure for System Development and Maintenance
- Procedure for Business Continuity Management Planning
- Procedure for Legal Requirements
3.2 GDPR Procedures: (06 Procedures)
It covers sample copy of mandatory all the general data protection regulation procedures covering all the details as per GDPR requirements.
List of GDPR Procedures
- Data Inventory Procedures
- Obtaining Valid Consent
- Data Protection Impact Assessment
- Subject Access Request Procedure
- Data Breach notification & handling Procedures
- Procedure for handling GDPR Data Subject Rights
4. Standard Operating Procedures (09 SOPs)
It covers sample copy of SOPs to link with significant aspects issues in the organization. It takes care of all such issues and used as a training guide as well as to establish control and make system in the organization. The samples given are as a guide and not compulsory to follow and organization is free to change the same to suit own requirements.
List of SOPs
- SOP for Liaison with specialist organizations
- SOP for Group Internet and E-mail Usage
- SOP for Software configuration management
- SOP for Server hardening
- SOP for the Management of removable media
- SOP for the Handling of virus attacks
- SOP for Information security incident management
- SOP for Audit trails
-
SOP for Business Continuity Plan
5. Process Flow Charts (06 Process Flow Charts)
It covers guideline for processes, process model. It covers process flow chart activities of all the main and critical processes with input-output matrix for manufacturing organization. It helps any organization in process mapping as well as preparing process documents for own organization.
List of Process Flow Chart
- Tax Account Related BPO-Work
- Marketing
- Purchase
- Software Development
- HRD and Training
- Web Application
6. Blank Formats (61 Blank formats)
It covers sample copy of blank forms required to maintain records as well as establish control and make system in the organization. The samples given are as a guide and not compulsory to follow and organization is free to change the same to suit own requirements.
List of blank formats
- Visitor Entry Register
- Employee leaving/transfer/termination Checklist
- Employment confidentiality and Non-competition agreement
- Job Description and Specification
- Supplier confidentiality and Non-competition agreement
- Training Calendar
- Employees Competence Report
- Security incident Investigation Form
- Asset Identification and Classification
- Capacity Planning
- Business Continuity Test Report
- Key Activities Input and Output
- ISMS Objective Monitoring Report
- Induction Training Report
- Training Report
- Skills Matrix Sheet
- Purchase Order
- Material Inward / Outward Record
- Approved Supplier List
- Contract Review Checklist / Summery of Contract
- Customer Complaint Report
- Customer Feedback Form
- Service level agreement
- Statement of Applicability report
- Outsourced Service Details
- Implementation of Recommended Controls
- Change Note
- Breakdown History Card
- Preventive Maintenance Checklist
- Master List and Distribution List of Document
- Corrective Action Report
- Software Project Plan and Review Approval Register
- Master List of Record
- IS Objectives Plan
- Minutes of meeting
- Configuration Items List
- Change Request
- Asset Identification and Classification
- Risk Assessment and Treatment Plant
- New User Creation Form
- Media Disposal and Scrap Record
- Parent/legal guardian consent form
- Parental consent withdrawal form
- GDPR consent form
- DPIA Template
- Standard Contractual Clauses for Third Parties
- Data subject action request form
- Audit Plan / Program
- ISMS Internal Audit NCR Report
- ISO 27001:2022 Audit Checklist Report
- Minutes of meeting
- Continual Improvement Monitoring Log
- Change management request form
- Communication report
- List of licenses
- Data Breach notification &investigation from
- Inter Company Agreement
- Data Subject Right to erasure request form
- Data Subject Consent Withdrawal Form
- DPO appointment letter
- Access Request Confirmation Letter
7. Filled formats (34 Filled formats)
It covers sample copy of filled forms required to maintain records as well as establish control and make system in the organization. The filled samples given are as a guide and not compulsory to follow and organization is free to change the same to suit own requirements.
List of filled formats
- Asset Register and Evaluation – sample 1
- Asset Identification and Classification – sample 2
- New User Creation Form
- Media Disposal and Scrap record
- Security incident & investigation form
- Capacity Planning
- Business Continuity Test Report
- ISMS Objectives Monitoring Sheet
- Visitor Entry Register
- Customer Feedback Form
- Communication report
- Customer Complaint Report
- Employee Leaving/Transfer/Termination Checklist
- Approved Supplier List
- Supplier registration form
- Training Calendar
- Employees Competence Report
- Master List and Distribution List of Document
- Change Note
- Corrective Action Report
- Master List of Records
- Objective Plan
- Audit Plan / Program
- ISMS Internal Audit Non-Conformity Report
- ISO/IEC 27001:2022 Audit Checklist Report
- Induction Training Report
- Training Report
- Skills Matrix Sheet
- Preventive maintenance checklist
- Breakdown History Card
- Master Compliance Matrix
- Scope Document for ISMS Implementation
- People Assets
- Vulnerability Assessment Tools List
8. Audit Checklist (More than 500 Audit check list questions)
ISMS requirement wise as well as technical audit checklist and best practices are given.
- ISMS Good Practices Audit Checklist
- ISMS Clausewise
- Controls Audit Checklist
9. Job description (11 job description)
It covers sample copy of job descriptions. List given below;
List of job description
- Job description for Director
- Job description for Finance & Account manager
- Job description for HR Head
- Job description for IS Manager
- Job description for IT consultant
- Job description for Marketing & business development manager
- Job description for Networking Engineer
- Job description for DPO
- Job description for Project Manager
- Job description for QC Head
- Job description for Software Developer
10.Sample MRM
It covers sample copy management review meeting, agenda of management review meeting and objective review.
11.Filled sample risk sheet
It covers sample copy filled risk assessment and treatment plan as per information security management system requirements.
12.Filled Statement of applicability (SOA)
It covers sample copy filled statement of applicability (SOA) as per information security management system requirements.
13.GDPR along with ISO 27001 Compliance Matrix
This compliance matrix contains GDPR along with ISO 27001:2022 requirement wise list of documented information for easy reference of users and to understand how this system is made.
How useful?
- The total documents for ISMS – ISO 27001 certification and EU GDPR certification are ideal to be used by any individual or by a facilitator working with large groups to successfully implement it in their organizations.
- The integrated EU GDPR with ISMS documentation kit can be useful to accelerate the documentation process, which results in quick certification.
- The users can very easily modify the templates according to their products and create the documents for their organization quickly and economically.
- The GDPR policies and ISMS policies given in this kit help users to develop information security and data protection control effectively.
- Ready-made templates are provided, which can reduce your time in the preparation of documents and ISO 27001 audit checklists for quick certification.
- The kit takes to care of all the sections and sub-sections of information security management system requirements as well as EU GDPR requirements. We have cross-referred the requirements with our documents to give you better confidence in your system.
- This excellent set of ISO 27001 and GDPR documents gives complete help to the users in making an integrated system with EU GDPR. Many companies are implementing ISO 27001:2013 system and getting benefits of ISO 27001 certification as improved information security in their day-to-day business.
- We provide a complete demo as well as sample documents, with a quick BUY option, that helps the user to understand the list of all documents covered in the kit.
Reviews
There are no reviews yet.