
ISO 27001 Toolkit for Law Firms
17 editable ISO/IEC 27001:2022 policies written for legal practices — including a Client Confidentiality & Information Barriers Policy — plus a law-firm risk register (BEC wire fraud, privilege, lateral hires) and the 93-control Statement of Applicability.
New to ISO/IEC 27001:2022? Read our ISO/IEC 27001:2022 guide →
What's inside — 17 documents + 3 workbooks
- Information Security Policy (.docx)
- Information Security Roles and Responsibilities (.docx)
- Risk Assessment and Treatment Procedure (.docx)
- Acceptable Use Policy (.docx)
- Access Control Policy (.docx)
- Asset Management and Information Classification Policy (.docx)
- Physical and Environmental Security Policy (.docx)
- Human Resources Security Policy (.docx)
- Remote Working and Mobile Device Policy (.docx)
- Supplier and Cloud Services Security Policy (.docx)
- Client Confidentiality and Information Barriers Policy (.docx)
- Information Security Incident Response Procedure (.docx)
- Business Continuity and ICT Readiness Plan (.docx)
- Backup and Recovery Policy (.docx)
- Logging and Monitoring Policy (.docx)
- Security Awareness and Training Procedure (.docx)
- AI Acceptable Use Policy (.docx)
Excel workbooks
- Risk Register (Excel)
- Statement of Applicability — all 93 Annex A controls (Excel)
- Audit Evidence Checklist (Excel)

See the real content before you buy
We publish genuine excerpts — not marketing mockups. Read the opening sections of the Information Security Policy exactly as you'll receive it:
Read the free previewFrequently asked questions
- Does this ISO 27001 toolkit include the Statement of Applicability?
- Yes. Every ISO 27001 toolkit includes an editable Excel Statement of Applicability covering all 93 Annex A controls of ISO/IEC 27001:2022, alongside the Word policies and, where listed, a risk register.
- Will these templates make my company ISO 27001 certified?
- No document set alone grants certification. An accredited certification body issues ISO 27001 certification after a Stage 1 and Stage 2 audit of a working ISMS. This toolkit gives you the complete, professionally structured documentation auditors expect — the longest part to prepare.
- Is it aligned to ISO 27001:2022 or the older 2013 version?
- It is written to ISO/IEC 27001:2022, including the restructured Annex A of 93 controls across four themes. When the standard changes materially we update the documents and offer affected customers a free re-download.
- What format are the files and how are they delivered?
- Editable Microsoft Word (.docx) and Excel (.xlsx) files, delivered as an instant download immediately after checkout. Organization-specific values are amber [bracketed placeholders] you replace with find-and-replace.
- What licence do I get?
- A single-organization licence. If you are a consultant or MSP intending to reuse the documents across multiple clients, contact us first for a fair multi-client arrangement.
