- Maintain the statement of applicability with a justification against every Annex A control
- Keep the information security risk assessment and treatment plan on their review dates
- Operate the selected controls on cadence and file the evidence against each
- Run the internal audit programme and the management review
- Carry nonconformities to verified closure
ISO/IEC 27001:2022
The information security management standard. The management system clauses set the discipline, and Annex A supplies the control set you select from and justify.
- 4Context of the organization1
- 5Leadership1
- 6.1.2Information security risk assessment1
- 6.1.3Information security risk treatment2
- 9Performance evaluation1
- 10Improvement2
- A.5Organizational controls3
- A.6People controls1
- A.7Physical controls1
- A.8Technological controls3
ISO 27001, in practice.
Information security, cybersecurity and privacy protection. Information security management systems. Requirements.
Organisations holding data somebody else cares about, usually driven by a customer requirement, a regulator, or the wish to answer security questionnaires once instead of forty times.
The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.
Every month, on a schedule you can check.
This is the running work for this standard specifically. The general shape is the same across all of them.
- Statement of applicability with inclusion and exclusion reasoning
- Risk assessment and risk treatment plan with owners
- Access control, joiner and leaver records
- Internal audit reports covering the management system clauses
- Security incident records and their corrective actions
Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.
Standards that share the structure.
ISO 9001:2015
The quality management standard most certified organisations start with, and the one most other management system standards borrow their structure from.
ISO 22301:2019
The continuity standard, built around one question: when the thing you deliver stops, how quickly does it come back, and who decided that was fast enough.
SOC 2 (TSC 2017, rev. 2022)
Not a certification but an attestation. An independent auditor reports on whether your controls were designed properly, and for Type II, whether they operated over a period.
Name a clause in ISO 27001 and we will open it.
The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.
