Before you buy

Shopping with GRC Solutions

Choosing between a book and a toolkit Books suit people who want to understand a standard such as ISO 27001, GDPR or NIST CSF before acting. Toolkits are better if you are implementing a management system and want ready-made documentation to adapt, which the store positions as a way to cut implementation costs and reduce errors.

Self-assessment before you buy If you are unsure where your gaps lie, the self-assessment tools cover topics including GDPR, ISO 27001 and Cyber Essentials. Running one first can help you decide whether you need a toolkit, a training course or outside help.

Training and staff awareness The training range runs from foundation to advanced level, and the e-learning courses focus on staff habits. These are most useful when a compliance project depends on people following consistent practice, not only on policy documents.

Cyber Essentials packages The Cyber Essentials Get A Little Help package is aimed at organisations that understand the scheme's five controls but need support with the self-assessment questionnaire. Choose the package that matches your organisation size, as the listing specifies. Check the listed terms before buying, as the subscription renews annually.