ISO 27001, finished by agents.
All 93 Annex A controls of the 2022 standard, seeded across the four themes, with the eight required policies drafted and the evidence behind them collected on a schedule.
93
controls
4
control themes
93
cross-mappings
8
policies
Your SOC 2 work already counts here.
ISO 27001 carries 93 cross-mappings into the other eleven frameworks. Fifteen land on SOC 2, fifteen on Thailand PDPA, fifteen on ISO 9001. Where a control overlaps, the evidence transfers with it and the residual gap is spelled out, so the second certification is not a second collection.
The policies, already drafted.
The policy writer drafts each document against the systems you connected, a second agent reviews it, and you approve. ISO 27001 needs 8.
Information Security Policy
The top-level policy establishing security direction and management commitment.
Access Control Policy
Controls for user access management, authentication and system access.
Asset Management Policy
Defines inventory, classification and handling of organizational assets.
Cryptographic Controls Policy
Specifies encryption standards, key management and cryptographic controls.
Incident Response Policy
Procedures for managing and responding to information security incidents.
Business Continuity Policy
Ensures information security continuity and redundancy.
Supplier Relationships Policy
Controls for managing information security across supplier relationships.
Human Resources Security Policy
Security requirements for hiring, employment and termination.
Before you start.
- Which version of the standard?
- ISO/IEC 27001:2022. All 93 Annex A controls are seeded across the organizational, people, physical and technological themes.
- We already have SOC 2. How much of this is done?
- Fifteen ISO 27001 controls map directly onto SOC 2 controls you already run. Zero2Do shows the mapping, moves the evidence across and lists what each pairing still leaves open.
- Do we still need a certification body?
- Yes. Zero2Do prepares the Statement of Applicability inputs, the policies and the control evidence; an accredited body runs the stage 1 and stage 2 audits and issues the certificate.
From zero to audit-ready in 30 days
Connect your systems and the ISO 27001 controls start filling in on the first heartbeat.
- 01
Connect
Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.
- 02
Agents run
On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.
- 03
Approve
You review what the agents produced and answer the few questions only you can answer.