Already using OrcaComply?Existing customer login →New customer registration →
Resources

Practical ISO 27001 guidance you can actually use.

Detailed, plain-English guides covering the decisions behind an ISMS — from first implementation through risk, controls, evidence and internal audit.

OrcaComply knowledge centre
Knowledge centre

Understand the reason behind the requirement, then build a system that works.

ISO 27001 becomes much easier to operate when people understand what the requirements are trying to achieve. These guides go further than a checklist. They explain the management thinking behind common ISMS activities, the mistakes that make them harder than they need to be and the practical connections between risks, policies, controls, evidence and assurance.

Use them as implementation guidance, as refreshers for control owners or as a way to explain the ISMS to colleagues who do not work in compliance every day.

Latest guidance

Explore the OrcaComply guides.

Each topic opens into a full article with practical context, examples and links to the relevant area of the platform.

Getting started

What is ISO 27001 and what does certification involve?

A practical explanation of ISO 27001, what an ISMS is, what certification actually tests and how to approach the work without turning it into a paperwork exercise.

Read the guide →
Getting started

ISO 27001 implementation roadmap for SMEs

A staged route from initial scoping through risk assessment, controls, evidence, internal audit, management review and certification readiness.

Read the guide →
Documents

What policies do you actually need for ISO 27001?

Why the right policy set depends on your risks, controls and operating model — and how to avoid both over-documenting and leaving important behaviour undefined.

Read the guide →
Documents

How to control policy versions and approvals

A practical approach to ownership, review, approval, publication and evidence that prevents policy libraries becoming uncertain or stale.

Read the guide →
Risk

How to build an information security risk register

How to create a risk register that supports decisions rather than becoming a long list of generic threats with no clear ownership or treatment.

Read the guide →
Risk

Risk treatment: reduce, avoid, transfer or accept

What the main treatment choices really mean, how controls support them and why risk acceptance needs explicit ownership.

Read the guide →
Controls

What is a Statement of Applicability?

Why the SoA is one of the most important documents in an ISO 27001 ISMS and how it connects risk treatment to Annex A controls.

Read the guide →
Controls

Applicable does not mean implemented

A simple but important distinction that helps avoid misleading Statements of Applicability and weak certification readiness.

Read the guide →
Evidence

What counts as ISO 27001 evidence?

Examples of useful evidence, what makes it credible and how to build an evidence model that supports control assurance throughout the year.

Read the guide →
Evidence

Why screenshots alone are not a sustainable evidence strategy

Screenshots can be useful, but relying on them for every control creates stale evidence, manual effort and weak traceability.

Read the guide →
Audit

How to plan an ISO 27001 internal audit programme

How to turn internal audit into useful management assurance by planning scope, frequency, independence, evidence and follow-up properly.

Read the guide →
Connected assurance

Continuous compliance versus annual evidence collection

Why an ISMS is stronger when control assurance happens throughout the year instead of becoming a once-a-year audit preparation exercise.

Read the guide →

Ready to move this out of spreadsheets?

Bring policies, risks, controls, evidence and audit activity into one connected workspace with clear ownership and practical next actions.