Z9 Monitor by Z9 Systems Free trial
ISO/IEC 27001:2022

ISO 27001 evidence from your servers – and the templates to go with it

An ISO 27001 audit asks for two things: proof that the technical controls work, and the policies and records that show how you run them. Z9 Monitor collects the first automatically and gives you 29 ready-to-edit templates for the second.

Evidence collected automatically

For 35 Annex A controls that an IT team owns, Z9 Monitor checks what it already monitors and shows each control as met, needing attention, or to be confirmed. Organisational points (policies, training, supplier reviews) are confirmed by an administrator with a note on where the document is kept – the PDF report shows who confirmed what and when.

29 templates, linked to the controls

Every control on the Compliance page lists its templates and free guidance from NIST, NCSC, CIS and the data protection authorities. Word documents come with yellow fields to fill in and your company name already in place; Excel registers have dropdowns and example lines. The asset register and the access review come filled in from what Z9 Monitor knows – every server and host with its owner, and every portal user and local administrator. Where a template adds nothing (clock synchronisation is checked automatically), the control links to guidance instead.

TemplateTypeAnnex A
Information Security PolicyWordA.5.1
Acceptable Use PolicyWordA.5.10
Access Control PolicyWordA.5.15, A.5.18, A.8.2, A.8.3
Joiners, Movers and Leavers ProcedureWordA.5.16
Password and Authentication StandardWordA.5.17, A.8.5
Incident Response ProcedureWordA.5.24, A.5.25
Evidence Collection and Chain of Custody FormWordA.5.28
IT Continuity and Disaster Recovery PlanWordA.5.29, A.5.30, A.8.14
Standard Operating ProcedureWordA.5.37
Malware Protection StandardWordA.8.7
Patch and Vulnerability Management ProcedureWordA.8.8
Backup and Restore PolicyWordA.8.13
Logging and Monitoring StandardWordA.8.15, A.8.16
Network Security StandardWordA.8.20
Cryptography and Key Management StandardWordA.8.24
Change Management ProcedureWordA.8.32
Capacity Review RecordWordA.8.6
Asset RegisterExcel · filled inA.5.9
User and Privileged Access ReviewExcel · filled inA.5.15, A.5.18, A.8.2
Supplier and Cloud Service RegisterExcelA.5.19, A.5.23
Legal, Regulatory and Contractual Requirements RegisterExcelA.5.31
Personal Data Register (Record of Processing)ExcelA.5.34
Security Event and Incident LogExcelA.5.24, A.5.25
Restore and Disaster Recovery Test RecordExcelA.5.30, A.8.13
Security Awareness Training RecordExcelA.6.3
Supporting Utilities Test RecordExcelA.7.11
Equipment Maintenance LogExcelA.7.13
Configuration Baseline (Standard Build Checklist)ExcelA.8.9
Change LogExcelA.8.32

Free sample templates

Three of the templates, exactly as Z9 Monitor produces them (without your company name). The full set comes with the ISO 27001 module.

⇩ Information Security Policy (.docx) ⇩ Incident Response Procedure (.docx) ⇩ Backup and Restore Policy (.docx)

Free guidance we link to

Which edition?

The ISO/IEC 27001 evidence report and the templates are part of the Enterprise and Custom editions. The 14-day free trial includes everything, so you can open the report on your own servers first. See editions and prices.

Z9 Monitor supports an audit or a self-assessment; it is not a certification and not legal advice. ISO/IEC 27001 is a standard of ISO and IEC; Z9 Systems is not affiliated with them. The templates are our own wording and do not reproduce the standard.

Start the 14-day free trialAsk a question
More:Backup monitoringVMware monitoringAll features