ISO 27001 evidence from your servers – and the templates to go with it
An ISO 27001 audit asks for two things: proof that the technical controls work, and the policies and records that show how you run them. Z9 Monitor collects the first automatically and gives you 29 ready-to-edit templates for the second.
Evidence collected automatically
For 35 Annex A controls that an IT team owns, Z9 Monitor checks what it already monitors and shows each control as met, needing attention, or to be confirmed. Organisational points (policies, training, supplier reviews) are confirmed by an administrator with a note on where the document is kept – the PDF report shows who confirmed what and when.
- Asset inventory and owners
- Supported operating systems (end of support)
- Security updates and pending reboots
- Antivirus status on Windows servers
- Host firewall
- Members of the local Administrators group
- Critical services, SQL Server, IIS
- Server backups (Veeam, Synology)
- Availability and outages
- Capacity and "full in N days"
- Monitoring and alerting
- Audit log of sign-ins and changes
- Two-factor sign-in
- User access review
- Encryption in transit and certificate expiry
- Clock synchronisation
- Hardware health (iDRAC / iLO)
29 templates, linked to the controls
Every control on the Compliance page lists its templates and free guidance from NIST, NCSC, CIS and the data protection authorities. Word documents come with yellow fields to fill in and your company name already in place; Excel registers have dropdowns and example lines. The asset register and the access review come filled in from what Z9 Monitor knows – every server and host with its owner, and every portal user and local administrator. Where a template adds nothing (clock synchronisation is checked automatically), the control links to guidance instead.
| Template | Type | Annex A |
|---|---|---|
| Information Security Policy | Word | A.5.1 |
| Acceptable Use Policy | Word | A.5.10 |
| Access Control Policy | Word | A.5.15, A.5.18, A.8.2, A.8.3 |
| Joiners, Movers and Leavers Procedure | Word | A.5.16 |
| Password and Authentication Standard | Word | A.5.17, A.8.5 |
| Incident Response Procedure | Word | A.5.24, A.5.25 |
| Evidence Collection and Chain of Custody Form | Word | A.5.28 |
| IT Continuity and Disaster Recovery Plan | Word | A.5.29, A.5.30, A.8.14 |
| Standard Operating Procedure | Word | A.5.37 |
| Malware Protection Standard | Word | A.8.7 |
| Patch and Vulnerability Management Procedure | Word | A.8.8 |
| Backup and Restore Policy | Word | A.8.13 |
| Logging and Monitoring Standard | Word | A.8.15, A.8.16 |
| Network Security Standard | Word | A.8.20 |
| Cryptography and Key Management Standard | Word | A.8.24 |
| Change Management Procedure | Word | A.8.32 |
| Capacity Review Record | Word | A.8.6 |
| Asset Register | Excel · filled in | A.5.9 |
| User and Privileged Access Review | Excel · filled in | A.5.15, A.5.18, A.8.2 |
| Supplier and Cloud Service Register | Excel | A.5.19, A.5.23 |
| Legal, Regulatory and Contractual Requirements Register | Excel | A.5.31 |
| Personal Data Register (Record of Processing) | Excel | A.5.34 |
| Security Event and Incident Log | Excel | A.5.24, A.5.25 |
| Restore and Disaster Recovery Test Record | Excel | A.5.30, A.8.13 |
| Security Awareness Training Record | Excel | A.6.3 |
| Supporting Utilities Test Record | Excel | A.7.11 |
| Equipment Maintenance Log | Excel | A.7.13 |
| Configuration Baseline (Standard Build Checklist) | Excel | A.8.9 |
| Change Log | Excel | A.8.32 |
Free sample templates
Three of the templates, exactly as Z9 Monitor produces them (without your company name). The full set comes with the ISO 27001 module.
Free guidance we link to
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022 – the standards themselves (sold by ISO).
- NCSC 10 Steps to Cyber Security, CIS Critical Security Controls, NIST Cybersecurity Framework.
- NIST special publications on incident response, contingency planning, patching, logging, malware, configuration, TLS and key management.
- Data protection authorities: Malaysia, Singapore, European Union.
Which edition?
The ISO/IEC 27001 evidence report and the templates are part of the Enterprise and Custom editions. The 14-day free trial includes everything, so you can open the report on your own servers first. See editions and prices.
Z9 Monitor supports an audit or a self-assessment; it is not a certification and not legal advice. ISO/IEC 27001 is a standard of ISO and IEC; Z9 Systems is not affiliated with them. The templates are our own wording and do not reproduce the standard.