Ziemtinel Cyberdefense Partner · Chile

Documentation and Specialist Consulting
in ISO 27001, Law 21,663 and Law 21,719

100% editable DOCX templates and expert consultancy for ISO 27001/27002:2022 ISMS, Cybersecurity Framework Law (21,663) and Personal Data Protection Law (21,719). Plus specialist programmes in ISO 27701, ISO 42001, ISO 9001, ISO 22301 and ISO/IEC 20000-1.

Framework Law 21,663 ISO 27001/27002:2022 Data Law 21,719
 Integrated compliance

ISO 27001, Law 21,663 and Law 21,719

An ecosystem for information security, cybersecurity and personal data protection

All three share governance, risk analysis, incident management and access control. Implementing them on a single management system means building the information asset inventory once and evidencing each control once, even though it satisfies all three frameworks.

ISO/IEC 27001:2022 Law 21,663 · Cybersecurity Law 21,719 · Personal Data
92
Days until Law 21,719 becomes enforceable
1.154
Organisations already designated as Operators of Vital Importance by the ANCI
8
Regulations and programmes we implement
307
Documents written against the requirement
Our Products and Services

Dos Ways to Reach Compliance

The documentation that backs it up y the consultancy that implements it.

Kit Docs Base

Pre-written DOCX documents · One-off payment
  • Policies and matrices ready to personalise
  • Organised by regulation
  • Download access for 30 days
  • Single payment, no subscription
US$199
$185.000 · live
from / pack · one-off payment
See catalogue

Regulatory Consulting

Gap assessment and implementation · By standard or all of them
  • Gap assessment with evidence and a closure plan
  • Implementation supported by senior consultants
  • Specialist programmes ISO 27701, ISO 42001 and ISO 9001
  • Up to 36% saving when contracted together
Quote in 2 minutes
proposal within 24 business hours, in UF
See Consulting
Build my quote
 National regulation

Cybersecurity Framework Law
(Law 21,663)

Cybersecurity Framework Law requires institutions of vital importance to implement documented technical and administrative measures. The absence of documentary evidence is the most frequent risk in ANCI audits.

Critical Asset Register

Identification and classification of assets before the ANCI with a formal methodology.

Documented Risk Management

Risk matrices with a recognised methodology and a treatment plan.

Incident Reporting to the ANCI

Mandatory communication protocols within the established deadlines.

Operational Continuity

Business continuity and disaster recovery plan.

ANCI
Law 21,663
Continuity
 National regulation

Personal Data Protection Law
(Law 21,719)

 Enforceable in 92 days · 1 de diciembre de 2026

Unlike Law 21,663, this one draws no distinction by size or sector: it reaches any organisation that processes personal data. And it shifts the burden of proof — in an incident, it is the controller who has to show that the security measures existed and worked.

Public processing policy

Article 14 ter requires twelve items to be published and kept on view, from letter a) to letter l). It is the heaviest documentary obligation in the law and the first one an inspector can review without having to ask anyone for anything.

Derechos en 30 días corridos

Six rights —access, rectification, erasure, objection, portability and blocking— with acknowledgement of receipt, a reply within 30 days extendable once, and the record that proves the sending, its date and its full content.

Breaches without undue delay

It is not 72 hours: that deadline is the GDPR's. Article 14 sexies requires reporting «by the most expeditious means possible», and also notifying each data subject when the data is sensitive, belongs to children under fourteen or is economic in nature.

Impact assessment, beforehand

Mandatory before processing starts in four cases: profiling with legal effects, large-scale processing, monitoring of public areas and sensitive data without consent.

 International standard

ISO 27001/27002:2022 — Complete ISMS

The leading international standard in information security management. Our templates cover every clause and every Annex A control.

Statement of Applicability (SoA)

The master document mapping each Annex A control to its implementation status.

ISO Risk Matrix

Risk identification, analysis and evaluation following the ISO 31000 + 27005 methodology.

Internal Audit Programme

Annual plan, checklists by domain and forms for findings and non-conformities.

Information Security Policy

Governance framework aligned with clauses 5 and 6 of the standard.

ISO 27001/27002:2022 Pack
Complete ISMS

Complete ISMS documentation, ready to present to your international certification body.

  • Statement of Applicability (SoA)
  • ISO 27005 Risk Matrix
  • Internal Audit Programme
  • 15+ policies and procedures
  • Management review templates
US$549
$509.000
Buy now
Tip: ISO 27001/27002:2022 and Cybersecurity Framework Law are complementary — implementing them together maximises your regulatory compliance.
Start today

Ready to secure your
regulatory compliance?

There are 92 days left until Law 21,719 becomes enforceable. A serious implementation takes three to six months.

Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?