Digital platform by UESE ITALIA S.p.A.ISO governance and audit-ready documents
Trust CentreSupport
ISOPILOT ISO Management Workspace
STANDARDS, MODELS, PRACTICES AND FRAMEWORKS CATALOGUE

More standards, one governance model: find the right pathway and bring it straight into the workspace.

The ISOPILOT catalogue organizes management systems, statutory organisational models, practices, frameworks, verification pathways and guidance by technical function, governance area and expected output. Search helps you choose; the workspace then turns the reference into actions, documents, evidence and revisions.

✓ Classification by technical function✓ Search and combinable filters✓ Integrable pathways✓ Human support available
01
Find

Search by standard, objective, sector, risk or expected outcome.

02
Understand

Distinguish certifiable systems, statutory models, verification, guidance and competence requirements.

03
Start

Bring the reference into the workspace and build the operational pathway.

04
Get support

For complex cases, add support from a UESE consultant.

FEATURED PATHWAYS

A selection of references for governance, Legislative Decree 231 compliance, sustainability, equality, information security and privacy, with technical function and expected outputs already clarified.

ISO 37301:2021Certifiable scheme

Compliance management system

Map obligations, compliance risks, responsibilities, controls, reporting, monitoring and compliance culture.

Open entry →
D.Lgs. 231/2001 · MOG 231Statutory organisational model

Legislative Decree 231 Organisational, Management and Control Model

Pathway to design, implement and maintain a tailored Legislative Decree 231 model: General Part, process and sensitive-activity mapping, predicate-offence risk assessment, Special Part and protocols, Code of Ethics, disciplinary system, Supervisory Body and information flows, whistleblowing, training, third-party controls, registers, forms and update plan. Regulatory framework updated to 2026.

Open entry →
UNI/PdR 125:2022Certifiable scheme

Gender equality management system

Structure policy, governance and KPIs covering culture, leadership, HR processes, career opportunities, pay equity and parenthood.

Open entry →
ISO 14064-1:2018Verifiable statement / inventory

Organizational GHG inventory

Define boundaries, sources and removals, methods, data quality, uncertainty, reporting and verification readiness for the inventory.

Open entry →
ISO/IEC 27001:2022 + Amd 1:2024Certifiable scheme · Native ISMS Workspace

Information security management system

Specialist ISMS Workspace with context and scope, functions and RACI, Asset Register, risk assessment and treatment, Annex A, Statement of Applicability, objectives/KPIs, suppliers, incidents, evidence, audits, management review and improvement.

Open entry →
ISO/IEC 27701:2025Certifiable scheme

Privacy information management system

Manage accountability, controller and processor roles, privacy risks, PII controls, records, third parties and continual improvement.

Open entry →
ONE CATALOGUE, MULTIPLE LEVELS OF USE

We distinguish certifiable systems, statutory models, verification and guidance.

The platform does not present every publication as a “certification”: it correctly identifies its technical function and builds a documentation set consistent with the project objective.

01

Certifiable systems

Manual, policies, processes, procedures, records, audits, KPIs and management review.

02

Verifiable inventories and statements

Boundaries, methods, data, calculations, uncertainty, evidence and validation or verification readiness.

03

Guidance and technical series

Playbooks, implementation plans, matrices, checklists and specialist controls integrated into the main system.

04

Statutory organisational models

Risk assessment, sensitive activities, predicate offences, General and Special Parts, protocols, Supervisory Body, reporting flows, disciplinary system and updates.

05

Requirements for bodies and competence

Impartiality, competence, assurance processes, resource qualification and decision control.

OPERATIONAL CATALOGUE

Search, compare and start the pathway best suited to your objective.

Search covers code, title, summary and area. Combine filters to quickly narrow the catalogue to entries relevant to your case.

68 entries availableTip: press / to focus search quickly.
01

Management systems and governance

Standards for quality, environment, safety, energy, continuity, services, compliance, assets and artificial intelligence.

13
ISO 9001:2015Certifiable scheme

Quality management system

Govern processes, responsibilities, risks, indicators, nonconformities and continual improvement through a verifiable documentation framework.

Manual and policiesProcedures and recordsAudits and review
ISO 14001:2015Certifiable scheme

Environmental management system

Structure environmental aspects and impacts, compliance obligations, operational controls, emergencies and environmental performance.

Manual and policiesProcedures and recordsAudits and review
ISO 45001:2018Certifiable scheme

Occupational health and safety

Integrate leadership, worker consultation, risk assessment, operational controls, incidents and OH&S improvement.

Manual and policiesProcedures and recordsAudits and review
ISO 50001:2018Certifiable scheme

Energy management system

Organize energy review, baselines, EnPIs, significant energy uses, objectives and improvement plans.

Manual and policiesProcedures and recordsAudits and review
ISO 13485:2016Certifiable scheme

Medical-device quality management

Manage regulatory requirements, design, suppliers, production, traceability, complaints and post-market surveillance.

Manual and policiesProcedures and recordsAudits and review
ISO 22000:2018Certifiable scheme

Food safety management

Integrate PRPs, hazard analysis, control plans, supply-chain communication, traceability and emergency management.

Manual and policiesProcedures and recordsAudits and review
ISO 22301:2019Certifiable scheme

Business continuity management

Build BIAs, continuity strategies, response and recovery plans, exercises and resilience metrics.

Manual and policiesProcedures and recordsAudits and review
ISO/IEC 20000-1:2018Certifiable scheme

IT service management

Govern service portfolios and catalogues, SLAs, changes, configurations, incidents, problems, suppliers and service improvement.

Manual and policiesProcedures and recordsAudits and review
ISO 37001:2025Certifiable scheme

Anti-bribery management system

Address bribery risk, due diligence, financial and non-financial controls, reporting, investigations and monitoring.

Manual and policiesProcedures and recordsAudits and review
ISO 37301:2021Certifiable scheme

Compliance management system

Map obligations, compliance risks, responsibilities, controls, reporting, monitoring and compliance culture.

Manual and policiesProcedures and recordsAudits and review
ISO/IEC 42001:2023Certifiable scheme

Artificial intelligence management system

Govern lifecycle, impacts, risks, data, suppliers, transparency, human oversight and improvement of AI systems.

Manual and policiesProcedures and recordsAudits and review
ISO 55001:2024Certifiable scheme

Asset management system

Align asset value, risk, cost and performance across the lifecycle through traceable plans and decisions.

Manual and policiesProcedures and recordsAudits and review
ISO 20121:2024Certifiable scheme

Event sustainability management

Integrate environmental, social and economic impacts into event design, procurement, delivery and review.

Manual and policiesProcedures and recordsAudits and review
02

Organisational models and compliance

Statutory organisational models, risk assessment, protocols, control systems, Supervisory Body, information flows and compliance safeguards.

1
03

Gender equality, decent work and social accountability

Frameworks for equality policies, KPIs, workers’ rights, social due diligence and continual improvement of working conditions.

2
UNI/PdR 125:2022Certifiable scheme

Gender equality management system

Structure policy, governance and KPIs covering culture, leadership, HR processes, career opportunities, pay equity and parenthood.

Manual and policiesProcedures and recordsAudits and review
SA8000:2026Certifiable scheme

Standard for decent work and social accountability

Integrate workers’ rights, health and safety, fair recruitment, non-discrimination, hours, wages, privacy and grievance mechanisms.

Manual and policiesProcedures and recordsAudits and review
04

GHG, carbon footprint and climate transition

Inventories, reduction projects, validation, verification, competence, product carbon footprint and carbon neutrality.

10
ISO 14064-1:2018Verifiable statement / inventory

Organizational GHG inventory

Define boundaries, sources and removals, methods, data quality, uncertainty, reporting and verification readiness for the inventory.

Inventory or statementMethodology and calculationsVerification evidence
ISO 14064-2:2019Verifiable statement / inventory

GHG reduction and removal projects

Govern baselines, additionality, sources/sinks/reservoirs, monitoring, quantification and reporting of climate projects.

Inventory or statementMethodology and calculationsVerification evidence
ISO 14064-3:2019Specialist guidance

Validation and verification of GHG statements

Prepare verification programmes, materiality thresholds, risk assessments, evidence plans, conclusions and assurance statements.

Implementation planChecklists and matricesSpecialist controls
ISO/TS 14064-4:2025Specialist guidance

Application guidance for ISO 14064-1

Deepen organizational and reporting boundaries, direct and indirect emissions, factors, methods, transparency and uncertainty.

Implementation planChecklists and matricesSpecialist controls
ISO 14064-5:2026Specialist guidance

Remote GHG validation and verification techniques

Plan remote activities, risk assessment, evidence collection, interviews, tests, reconciliations and limits of remote assurance.

Implementation planChecklists and matricesSpecialist controls
ISO 14065:2020Requirements for bodies

Environmental validation and verification bodies

Define impartiality, competence, validation/verification processes, information management and quality control for bodies.

Assurance processesImpartiality and competenceDecision control
ISO 14066:2023Competence requirements

Competence of validation and verification teams

Map competence, qualifications, experience, evaluation and maintenance of capabilities for teams, technical experts and independent reviewers.

Competence profilesResource qualificationEvidence and records
ISO 14067:2018Verifiable statement / inventory

Product carbon footprint

Quantify product carbon footprint using lifecycle principles, functional units, boundaries, data, allocation, quality and reporting.

Inventory or statementMethodology and calculationsVerification evidence
ISO 14068-1:2023Verifiable statement / inventory

Carbon neutrality and net-zero transition

Build a hierarchy of reduction, removal and offsetting, credible targets, a transition plan and transparent communications.

Inventory or statementMethodology and calculationsVerification evidence
ISO 14083:2023Verifiable statement / inventory

GHG emissions from transport chains

Quantify and report passenger and freight emissions across transport-chain elements, hubs and logistics activities.

Inventory or statementMethodology and calculationsVerification evidence
05

ISO/IEC 27000, cybersecurity, privacy and digital resilience

Requirements, controls, risk, audits, cloud, incidents, suppliers, digital evidence, ICT continuity and security governance.

42
ISO/IEC 27000:2026Specialist guidance

ISMS family overview

Navigate the architecture, concepts, relationships and selection of standards across the ISO/IEC 27000 family.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27002:2022Specialist guidance

Information security controls

Select and implement organizational, people, physical and technological controls with attributes and implementation guidance.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27003:2017Specialist guidance

ISMS implementation guidance

Translate ISO/IEC 27001 requirements into an implementation programme with governance, activities, evidence and responsibilities.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27004:2016Specialist guidance

ISMS monitoring and measurement

Define metrics, collection methods, criteria, analysis and reporting for security performance and ISMS effectiveness.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27005:2022Specialist guidance

Information security risk management

Design criteria, identification, analysis, evaluation, treatment, acceptance, communication and monitoring of cyber risk.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27006-1:2024Requirements for bodies

Bodies auditing and certifying ISMS

Govern competence, impartiality, audit duration, decision processes and consistency of ISO/IEC 27001 certification bodies.

Assurance processesImpartiality and competenceDecision control
ISO/IEC 27007:2020Specialist guidance

ISMS auditing

Plan audit programmes, conduct internal or external audits, evaluate evidence and assess ISMS auditor competence.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC TS 27008:2019Specialist guidance

Assessment of information security controls

Define criteria and techniques for reviewing implementation, operation and technical compliance of controls.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27009:2020Specialist guidance

Sector-specific application of ISO/IEC 27001

Design additional requirements and controls for sector profiles without altering the base ISMS structure.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27010:2015Specialist guidance

Inter-sector and inter-organizational communications security

Govern sensitive information exchange among organizations, communities of trust, authorities and critical infrastructures.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27011:2024Specialist guidance

Security controls for telecommunications

Adapt ISO/IEC 27002 controls to telecommunications operators, networks, services and processes.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27013:2021 + Amd 1:2024Specialist guidance

Integrated ISO/IEC 27001 and 20000-1 implementation

Integrate ISMS and IT service management while reducing duplication across governance, risks, controls, audits and improvement.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27014:2020Specialist guidance

Governance of information security

Align security, business objectives, accountability, investment, executive oversight and reporting to governing bodies.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27017:2015Specialist guidance

Cloud security controls

Integrate cloud-specific responsibilities and controls for customers, providers, virtualized environments and service administration.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27018:2025Specialist guidance

Protection of PII in public clouds

Strengthen transparency, purpose limitation, return/deletion, subcontracting and controls for public-cloud PII processors.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27019:2024Specialist guidance

Security controls for the energy utility industry

Adapt controls to industrial control systems, generation, transmission, distribution and energy-utility processes.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27021:2017 + Amd 1:2021Competence requirements

Competence of ISMS professionals

Define competence profiles, knowledge and capabilities for professionals implementing, managing, assessing and improving security systems.

Competence profilesResource qualificationEvidence and records
ISO/IEC TS 27022:2021Specialist guidance

ISMS process guidance

Model and govern ISMS processes, interactions, inputs/outputs, owners and operational evidence.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27031:2025Specialist guidance

ICT readiness for business continuity

Integrate ICT resilience, recovery priorities, capacity, dependencies, testing and response with business continuity.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27032:2023Specialist guidance

Internet security guidelines

Govern risks and controls for Internet services, collaboration, information sharing and stakeholder coordination.

Implementation planChecklists and matricesSpecialist controls
Serie ISO/IEC 27033Technical series

Network security series

Design architectures, gateways, VPNs, segmentation, inter-domain communications and network-security scenarios.

Series mapCoordinated modulesIntegration plan
Serie ISO/IEC 27034Technical series

Application security series

Integrate governance, risk assessment, application controls, secure lifecycle, validation and security profiles.

Series mapCoordinated modulesIntegration plan
Serie ISO/IEC 27035:2023Technical series

Information security incident management

Prepare for, detect, report, assess, respond to and learn from incidents using plans, roles, playbooks and improvement.

Series mapCoordinated modulesIntegration plan
Serie ISO/IEC 27036Technical series

Supplier relationship security series

Govern third-party risk, contractual requirements, ICT supply chains, monitoring, assurance and relationship termination.

Series mapCoordinated modulesIntegration plan
ISO/IEC 27037:2012Specialist guidance

Digital evidence identification and acquisition

Define principles, roles, chain of custody, identification, collection, acquisition and preservation of digital evidence.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC TR 27016:2014Technical report

Organizational economics of information security

Support investment decisions, priorities, trade-offs and resource allocation by linking information risk and economic consequences.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27038:2014Technical specification

Secure digital redaction

Define techniques, tool requirements and tests for irreversibly removing sensitive information from digital documents.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27039:2015Specialist guidance

Intrusion detection and prevention systems

Guide the selection, deployment, configuration, operation, monitoring and improvement of IDPS solutions.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27041:2015Forensic guidance

Suitability of incident investigation methods

Demonstrate that digital investigation methods and processes are fit for purpose, validated and supported by reviewable evidence.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27042:2015Forensic guidance

Analysis and interpretation of digital evidence

Govern analytical methods, repeatability, reproducibility, records, competence and independent scrutiny of digital evidence.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27043:2015Forensic guidance

Incident investigation principles and processes

Structure preparation, initiation, acquisition, analysis, reconstruction, reporting and closure of digital incident investigations.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27071:2023Cybersecurity guidance

Trusted connections between devices and services

Define security recommendations for identity, authentication, trust and protection of connections between devices and services.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27099:2022Specialist framework

PKI practices and policy framework

Govern certificate policies, certification practice statements, risks, controls and certificate life cycles for PKI trust services.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC TS 27100:2020Conceptual framework

Cybersecurity overview and concepts

Align terminology, context, boundaries and relationships across cybersecurity, information security, data protection and resilience.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27102:2019Specialist guidance

ISO/IEC 27001 and cyber insurance

Integrate cyber insurance into risk treatment, information sharing and management of cyber-incident impacts.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC TS 27110:2021Framework guidance

Cybersecurity framework development

Design the structure, principles, governance, content and maintenance of coherent, reusable cybersecurity frameworks.

Implementation planChecklists and matricesSpecialist controls
ISO 27799:2025Sector guidance

Information security controls in health

Apply ISO/IEC 27002 to healthcare organizations, clinical data, electronic records, medical software, devices and remote care services.

Implementation planChecklists and matricesSpecialist controls
ISO/IEC 27040:2024Specialist guidance

Storage security

Design protection for data, devices, media, storage networks, administration, secure deletion and end of life.

Implementation planChecklists and matricesSpecialist controls
Serie ISO/IEC 27050Technical series

Electronic discovery series

Govern identification, preservation, collection, processing, analysis and production of electronically stored information.

Series mapCoordinated modulesIntegration plan
ISO/IEC 27701:2025Certifiable scheme

Privacy information management system

Manage accountability, controller and processor roles, privacy risks, PII controls, records, third parties and continual improvement.

Manual and policiesProcedures and recordsAudits and review
ISO/IEC TS 27103:2026Specialist guidance

Using ISO/IEC standards in cybersecurity frameworks

Map ISO/IEC standards and controls into a coherent, scalable and risk-linked cybersecurity framework.

Implementation planChecklists and matricesSpecialist controls
INTEGRATED SYSTEMS

Combine multiple standards without duplicating processes and documents.

ISOPILOT reuses context, leadership, risks, competence, documented information, audits and review while keeping the specific requirements of each pathway separate.

Request an integrated configuration →
ISO 9001 + ISO 14001 + ISO 45001ISO/IEC 27001 + ISO/IEC 27701 + NIS2ISO 14064 + ISO 14067 + ISO 14068-1MOG 231 + ISO 37301 + ISO 37001UNI/PdR 125 + SA8000 + governance ESG
FAQ

How to read and use the catalogue.

Are all catalogue entries certifiable?

No. ISOPILOT distinguishes certifiable management systems, statutory organisational models, verifiable inventories or statements, guidance, technical series and requirements for bodies or competence.

Can I integrate multiple standards in one project?

Yes. The platform can reuse common processes, context, risks, competence, audits and review while keeping specific requirements separate.

Does the catalogue guarantee certification?

No. The catalogue organises the documentation and operational pathway. Compliance depends on real data, implementation, evidence, human validation and the decisions of the competent body.

How do I choose the correct entry?

Use search and filters by objective, sector and type. For integrated systems or complex cases, you can request an assisted configuration.

Is a Legislative Decree 231 model the same for every organisation?

No. A Legislative Decree 231 model must be built and updated around the organisation: sensitive activities, applicable predicate offences, processes, delegated powers and proxies, controls, Supervisory Body reporting flows and residual risk. ISOPILOT supports assessment, documentation planning, protocols, evidence and review with professional validation.

How is ISO/IEC 27001 managed?

ISO/IEC 27001 includes a native ISMS Workspace: functions and RACI, context and scope, Asset Register, Risk Register and treatment, 93 Annex A controls, Statement of Applicability, registers, evidence, audits and management review. Workspace data feeds the document engine and remains traceable.

Technical note

ISOPILOT supports design, documentation, risk assessment, internal verification and pathway readiness. It does not issue certifications, accreditations or verification statements and does not replace the competent body or professional.

Compare plans →
GDPR · PRIVACY GOVERNANCE

GDPR è ora uno schema di progetto ISOPILOT

Attivabile nei piani Starter, Professional ed Enterprise secondo i relativi entitlement. Registro trattamenti, DPIA, data breach, responsabili, trasferimenti, cookie, evidenze e aggiornamento documentale controllato.

Scopri il Workspace GDPR →
NIS2 · CYBERSECURITY GOVERNANCE

Nuovo schema e nuovo abbonamento NIS2 Governance

D.Lgs. 138/2024, specifiche ACN, rischio, asset, supply chain, incidenti, continuità e 73 documenti governati con generazione automatica iniziale.

Scopri NIS2 Governance →