TL,DR: ISO 27001 policy templates help document security expectations and risk-management responsibilities. Common templates cover access control, incident response, asset management, and business continuity. Each policy should define purpose, scope, roles, risk treatment, and training expectations. Implementing ISO 27001 can feel like staring at a blank page with a looming deadline. Defining security controls, documenting…
TL;DR Your ISO 27001 scope is the boundary of your information security management system (ISMS): the products, services, people, locations, and systems your certificate covers, and what it leaves out. The scope statement is the short, documented version of that boundary, and it appears on your certificate for auditors and customers to read. This guide…
TL;DR Identity theft is not a joke, Jim. Millions of people suffer every year! Remember this dialogue from the popular TV show The Office? As compliance experts, we believe these are golden words to live by. Identity theft in a business environment ranges from wide net phishing attempts to targeted spear phishing attempts. And this…
TL;DR The Statement of Applicability is the document auditors use to connect your information security risks, selected Annex A controls, implementation status, and supporting evidence. This guide explains what an ISO 27001 SoA must contain, how to build one against the 2022 control set, and includes a free template to help you get started. What…
When disaster strikes, your business may lose critical data, and all the functions may have to stop suddenly. However, your business doesn’t have to be at the mercy of chaos – a carefully crafted disaster recovery plan becomes integral to running your business environment smoothly and efficiently. But getting started with a plan isn’t always…
TL;DR An ISO 27001 surveillance audit is a required follow-up audit conducted by your certification body to confirm that your Information Security Management System (ISMS) continues to operate effectively after certification. Unlike the initial certification audit, a surveillance audit does not usually review every part of the business. It focuses on whether key processes still…