This document provides implementation guidance and potential metrics for ISO/IEC 27001 & 27002. It was created by an international community of ISO27k implementers to help others with information security management standard implementation. The guidance covers risk assessment, security policies, asset management, access control, and other areas. Suggested metrics include policy coverage, risk treatment status, user access changes, and security incident trends. The document is meant to be tailored to individual organizational needs.