Search by standard, objective, sector, risk or expected outcome.
More standards, one governance model: find the right pathway and bring it straight into the workspace.
The ISOPILOT catalogue organizes management systems, statutory organisational models, practices, frameworks, verification pathways and guidance by technical function, governance area and expected output. Search helps you choose; the workspace then turns the reference into actions, documents, evidence and revisions.
Distinguish certifiable systems, statutory models, verification, guidance and competence requirements.
Bring the reference into the workspace and build the operational pathway.
For complex cases, add support from a UESE consultant.
Strategic pathways, immediately understandable.
A selection of references for governance, Legislative Decree 231 compliance, sustainability, equality, information security and privacy, with technical function and expected outputs already clarified.
Compliance management system
Map obligations, compliance risks, responsibilities, controls, reporting, monitoring and compliance culture.
Open entry →Legislative Decree 231 Organisational, Management and Control Model
Pathway to design, implement and maintain a tailored Legislative Decree 231 model: General Part, process and sensitive-activity mapping, predicate-offence risk assessment, Special Part and protocols, Code of Ethics, disciplinary system, Supervisory Body and information flows, whistleblowing, training, third-party controls, registers, forms and update plan. Regulatory framework updated to 2026.
Open entry →Gender equality management system
Structure policy, governance and KPIs covering culture, leadership, HR processes, career opportunities, pay equity and parenthood.
Open entry →Organizational GHG inventory
Define boundaries, sources and removals, methods, data quality, uncertainty, reporting and verification readiness for the inventory.
Open entry →Information security management system
Specialist ISMS Workspace with context and scope, functions and RACI, Asset Register, risk assessment and treatment, Annex A, Statement of Applicability, objectives/KPIs, suppliers, incidents, evidence, audits, management review and improvement.
Open entry →Privacy information management system
Manage accountability, controller and processor roles, privacy risks, PII controls, records, third parties and continual improvement.
Open entry →We distinguish certifiable systems, statutory models, verification and guidance.
The platform does not present every publication as a “certification”: it correctly identifies its technical function and builds a documentation set consistent with the project objective.
Certifiable systems
Manual, policies, processes, procedures, records, audits, KPIs and management review.
Verifiable inventories and statements
Boundaries, methods, data, calculations, uncertainty, evidence and validation or verification readiness.
Guidance and technical series
Playbooks, implementation plans, matrices, checklists and specialist controls integrated into the main system.
Statutory organisational models
Risk assessment, sensitive activities, predicate offences, General and Special Parts, protocols, Supervisory Body, reporting flows, disciplinary system and updates.
Requirements for bodies and competence
Impartiality, competence, assurance processes, resource qualification and decision control.
Management systems and governance
Standards for quality, environment, safety, energy, continuity, services, compliance, assets and artificial intelligence.
Quality management system
Govern processes, responsibilities, risks, indicators, nonconformities and continual improvement through a verifiable documentation framework.
Environmental management system
Structure environmental aspects and impacts, compliance obligations, operational controls, emergencies and environmental performance.
Occupational health and safety
Integrate leadership, worker consultation, risk assessment, operational controls, incidents and OH&S improvement.
Energy management system
Organize energy review, baselines, EnPIs, significant energy uses, objectives and improvement plans.
Medical-device quality management
Manage regulatory requirements, design, suppliers, production, traceability, complaints and post-market surveillance.
Food safety management
Integrate PRPs, hazard analysis, control plans, supply-chain communication, traceability and emergency management.
Business continuity management
Build BIAs, continuity strategies, response and recovery plans, exercises and resilience metrics.
IT service management
Govern service portfolios and catalogues, SLAs, changes, configurations, incidents, problems, suppliers and service improvement.
Anti-bribery management system
Address bribery risk, due diligence, financial and non-financial controls, reporting, investigations and monitoring.
Compliance management system
Map obligations, compliance risks, responsibilities, controls, reporting, monitoring and compliance culture.
Artificial intelligence management system
Govern lifecycle, impacts, risks, data, suppliers, transparency, human oversight and improvement of AI systems.
Asset management system
Align asset value, risk, cost and performance across the lifecycle through traceable plans and decisions.
Event sustainability management
Integrate environmental, social and economic impacts into event design, procurement, delivery and review.
Organisational models and compliance
Statutory organisational models, risk assessment, protocols, control systems, Supervisory Body, information flows and compliance safeguards.
Legislative Decree 231 Organisational, Management and Control Model
Pathway to design, implement and maintain a tailored Legislative Decree 231 model: General Part, process and sensitive-activity mapping, predicate-offence risk assessment, Special Part and protocols, Code of Ethics, disciplinary system, Supervisory Body and information flows, whistleblowing, training, third-party controls, registers, forms and update plan. Regulatory framework updated to 2026.
Gender equality, decent work and social accountability
Frameworks for equality policies, KPIs, workers’ rights, social due diligence and continual improvement of working conditions.
Gender equality management system
Structure policy, governance and KPIs covering culture, leadership, HR processes, career opportunities, pay equity and parenthood.
Standard for decent work and social accountability
Integrate workers’ rights, health and safety, fair recruitment, non-discrimination, hours, wages, privacy and grievance mechanisms.
GHG, carbon footprint and climate transition
Inventories, reduction projects, validation, verification, competence, product carbon footprint and carbon neutrality.
Organizational GHG inventory
Define boundaries, sources and removals, methods, data quality, uncertainty, reporting and verification readiness for the inventory.
GHG reduction and removal projects
Govern baselines, additionality, sources/sinks/reservoirs, monitoring, quantification and reporting of climate projects.
Validation and verification of GHG statements
Prepare verification programmes, materiality thresholds, risk assessments, evidence plans, conclusions and assurance statements.
Application guidance for ISO 14064-1
Deepen organizational and reporting boundaries, direct and indirect emissions, factors, methods, transparency and uncertainty.
Remote GHG validation and verification techniques
Plan remote activities, risk assessment, evidence collection, interviews, tests, reconciliations and limits of remote assurance.
Environmental validation and verification bodies
Define impartiality, competence, validation/verification processes, information management and quality control for bodies.
Competence of validation and verification teams
Map competence, qualifications, experience, evaluation and maintenance of capabilities for teams, technical experts and independent reviewers.
Product carbon footprint
Quantify product carbon footprint using lifecycle principles, functional units, boundaries, data, allocation, quality and reporting.
Carbon neutrality and net-zero transition
Build a hierarchy of reduction, removal and offsetting, credible targets, a transition plan and transparent communications.
GHG emissions from transport chains
Quantify and report passenger and freight emissions across transport-chain elements, hubs and logistics activities.
ISO/IEC 27000, cybersecurity, privacy and digital resilience
Requirements, controls, risk, audits, cloud, incidents, suppliers, digital evidence, ICT continuity and security governance.
ISMS family overview
Navigate the architecture, concepts, relationships and selection of standards across the ISO/IEC 27000 family.
Information security management system
Specialist ISMS Workspace with context and scope, functions and RACI, Asset Register, risk assessment and treatment, Annex A, Statement of Applicability, objectives/KPIs, suppliers, incidents, evidence, audits, management review and improvement.
Information security controls
Select and implement organizational, people, physical and technological controls with attributes and implementation guidance.
ISMS implementation guidance
Translate ISO/IEC 27001 requirements into an implementation programme with governance, activities, evidence and responsibilities.
ISMS monitoring and measurement
Define metrics, collection methods, criteria, analysis and reporting for security performance and ISMS effectiveness.
Information security risk management
Design criteria, identification, analysis, evaluation, treatment, acceptance, communication and monitoring of cyber risk.
Bodies auditing and certifying ISMS
Govern competence, impartiality, audit duration, decision processes and consistency of ISO/IEC 27001 certification bodies.
ISMS auditing
Plan audit programmes, conduct internal or external audits, evaluate evidence and assess ISMS auditor competence.
Assessment of information security controls
Define criteria and techniques for reviewing implementation, operation and technical compliance of controls.
Sector-specific application of ISO/IEC 27001
Design additional requirements and controls for sector profiles without altering the base ISMS structure.
Inter-sector and inter-organizational communications security
Govern sensitive information exchange among organizations, communities of trust, authorities and critical infrastructures.
Security controls for telecommunications
Adapt ISO/IEC 27002 controls to telecommunications operators, networks, services and processes.
Integrated ISO/IEC 27001 and 20000-1 implementation
Integrate ISMS and IT service management while reducing duplication across governance, risks, controls, audits and improvement.
Governance of information security
Align security, business objectives, accountability, investment, executive oversight and reporting to governing bodies.
Cloud security controls
Integrate cloud-specific responsibilities and controls for customers, providers, virtualized environments and service administration.
Protection of PII in public clouds
Strengthen transparency, purpose limitation, return/deletion, subcontracting and controls for public-cloud PII processors.
Security controls for the energy utility industry
Adapt controls to industrial control systems, generation, transmission, distribution and energy-utility processes.
Competence of ISMS professionals
Define competence profiles, knowledge and capabilities for professionals implementing, managing, assessing and improving security systems.
ISMS process guidance
Model and govern ISMS processes, interactions, inputs/outputs, owners and operational evidence.
ICT readiness for business continuity
Integrate ICT resilience, recovery priorities, capacity, dependencies, testing and response with business continuity.
Internet security guidelines
Govern risks and controls for Internet services, collaboration, information sharing and stakeholder coordination.
Network security series
Design architectures, gateways, VPNs, segmentation, inter-domain communications and network-security scenarios.
Application security series
Integrate governance, risk assessment, application controls, secure lifecycle, validation and security profiles.
Information security incident management
Prepare for, detect, report, assess, respond to and learn from incidents using plans, roles, playbooks and improvement.
Supplier relationship security series
Govern third-party risk, contractual requirements, ICT supply chains, monitoring, assurance and relationship termination.
Digital evidence identification and acquisition
Define principles, roles, chain of custody, identification, collection, acquisition and preservation of digital evidence.
Organizational economics of information security
Support investment decisions, priorities, trade-offs and resource allocation by linking information risk and economic consequences.
Secure digital redaction
Define techniques, tool requirements and tests for irreversibly removing sensitive information from digital documents.
Intrusion detection and prevention systems
Guide the selection, deployment, configuration, operation, monitoring and improvement of IDPS solutions.
Suitability of incident investigation methods
Demonstrate that digital investigation methods and processes are fit for purpose, validated and supported by reviewable evidence.
Analysis and interpretation of digital evidence
Govern analytical methods, repeatability, reproducibility, records, competence and independent scrutiny of digital evidence.
Incident investigation principles and processes
Structure preparation, initiation, acquisition, analysis, reconstruction, reporting and closure of digital incident investigations.
Trusted connections between devices and services
Define security recommendations for identity, authentication, trust and protection of connections between devices and services.
PKI practices and policy framework
Govern certificate policies, certification practice statements, risks, controls and certificate life cycles for PKI trust services.
Cybersecurity overview and concepts
Align terminology, context, boundaries and relationships across cybersecurity, information security, data protection and resilience.
ISO/IEC 27001 and cyber insurance
Integrate cyber insurance into risk treatment, information sharing and management of cyber-incident impacts.
Cybersecurity framework development
Design the structure, principles, governance, content and maintenance of coherent, reusable cybersecurity frameworks.
Information security controls in health
Apply ISO/IEC 27002 to healthcare organizations, clinical data, electronic records, medical software, devices and remote care services.
Storage security
Design protection for data, devices, media, storage networks, administration, secure deletion and end of life.
Electronic discovery series
Govern identification, preservation, collection, processing, analysis and production of electronically stored information.
Privacy information management system
Manage accountability, controller and processor roles, privacy risks, PII controls, records, third parties and continual improvement.
Using ISO/IEC standards in cybersecurity frameworks
Map ISO/IEC standards and controls into a coherent, scalable and risk-linked cybersecurity framework.
Change the filters or use a broader search term.
Combine multiple standards without duplicating processes and documents.
ISOPILOT reuses context, leadership, risks, competence, documented information, audits and review while keeping the specific requirements of each pathway separate.
Request an integrated configuration →How to read and use the catalogue.
Are all catalogue entries certifiable?
No. ISOPILOT distinguishes certifiable management systems, statutory organisational models, verifiable inventories or statements, guidance, technical series and requirements for bodies or competence.
Can I integrate multiple standards in one project?
Yes. The platform can reuse common processes, context, risks, competence, audits and review while keeping specific requirements separate.
Does the catalogue guarantee certification?
No. The catalogue organises the documentation and operational pathway. Compliance depends on real data, implementation, evidence, human validation and the decisions of the competent body.
How do I choose the correct entry?
Use search and filters by objective, sector and type. For integrated systems or complex cases, you can request an assisted configuration.
Is a Legislative Decree 231 model the same for every organisation?
No. A Legislative Decree 231 model must be built and updated around the organisation: sensitive activities, applicable predicate offences, processes, delegated powers and proxies, controls, Supervisory Body reporting flows and residual risk. ISOPILOT supports assessment, documentation planning, protocols, evidence and review with professional validation.
How is ISO/IEC 27001 managed?
ISO/IEC 27001 includes a native ISMS Workspace: functions and RACI, context and scope, Asset Register, Risk Register and treatment, 93 Annex A controls, Statement of Applicability, registers, evidence, audits and management review. Workspace data feeds the document engine and remains traceable.
ISOPILOT supports design, documentation, risk assessment, internal verification and pathway readiness. It does not issue certifications, accreditations or verification statements and does not replace the competent body or professional.
GDPR è ora uno schema di progetto ISOPILOT
Attivabile nei piani Starter, Professional ed Enterprise secondo i relativi entitlement. Registro trattamenti, DPIA, data breach, responsabili, trasferimenti, cookie, evidenze e aggiornamento documentale controllato.
Scopri il Workspace GDPR →Nuovo schema e nuovo abbonamento NIS2 Governance
D.Lgs. 138/2024, specifiche ACN, rischio, asset, supply chain, incidenti, continuità e 73 documenti governati con generazione automatica iniziale.
