Artifacts

GRC Artifact Index

Find the right page for your regulation, framework, or control program. Filter by topic, search by keyword, and open the artifact that matches your scope.

Explore artifacts
EU AI Act timeline artifact preview
GLOBAL
Read

ISO/IEC 42001 AI Management System Guide

ISO/IEC 42001:2023 guide to AIMS scope, Clauses 4-10, AI risk and impact assessment, Annex controls, operating evidence, certification, and framework comparisons.

Sorena AIArtifactsGlobalISO 42001
Read ISO/IEC 42001 AI Management System Guide
GLOBAL
Read

ISO 22301 Implementation Guide

Plan BCMS scope, BIA, disruption risk, recovery strategy, exercises, conformity evidence, and optional certification under ISO 22301:2019.

Sorena AIArtifactsGlobalISO 22301
Read ISO 22301 Implementation Guide
GLOBAL
Read

ISO/IEC 27001 Implementation Guide

Plan ISMS scope, risk treatment, the Statement of Applicability, Annex A evidence, internal audits, management review, and certification.

Sorena AIArtifactsGlobalISO 27001
Read ISO/IEC 27001 Implementation Guide
GLOBAL
Read

ISO/IEC 27005 Risk Management Guide

ISO/IEC 27005:2022 guidance for risk criteria, scenario-based assessment, treatment, residual-risk decisions, and reviewable ISMS evidence.

Sorena AIArtifactsGlobalISO 27005
Read ISO/IEC 27005 Risk Management Guide
GLOBAL
Read

ISO/IEC 27017 Cloud Security Controls Guide

ISO/IEC 27017:2015 guidance for provider/customer roles, cloud contracts, control ownership, operations, evidence, and certification boundaries.

Sorena AIArtifactsGlobalISO 27017
Read ISO/IEC 27017 Cloud Security Controls Guide
GLOBAL
Read

ISO/IEC 27018 Cloud Privacy Controls Guide

Apply ISO/IEC 27018:2025 when a public-cloud provider processes PII for customers, including contracts, subprocessors, disclosure, deletion, breaches, and evidence.

Sorena AIArtifactsGlobalISO 27018
Read ISO/IEC 27018 Cloud Privacy Controls Guide
GLOBAL
Read

ISO/IEC 27035 Incident Response Guide

Use ISO/IEC 27035 to prepare for, detect, report, assess, respond to, recover from, and learn from information security incidents.

Sorena AIArtifactsGlobalISO 27035
Read ISO/IEC 27035 Incident Response Guide
GLOBAL
Read

ISO/IEC 27036 Supplier Security Guide

Manage acquirer-supplier roles, relationship agreements, ICT supply chains, cloud services, assurance, monitoring, change, and exit under the ISO/IEC 27036 series.

Sorena AIArtifactsGlobalISO 27036
Read ISO/IEC 27036 Supplier Security Guide

Guidance tailored to your needs

Get guidance tailored to your organisation, systems, and deadlines, with specific actions for the teams responsible.

Talk to an expert