ISO 27001 · · Cybervisory

The first step is usually a readiness review, sometimes called a gap assessment. The purpose of the review is two-fold: Firstly, to check whether you have all the necessary policies, procedures and other requirements of the Standard in place; and secondly, to check whether all of that paperwork matches reality.

Start with the way your business works

This is where a consultant can save you a lot of time (and money). A skilled consultant will assess where your business is at today, then identify any gaps between what you have and what the Standard requires. At Cybervisory, our consultants are also experienced auditors who know exactly what documentation and evidence will be accepted for certification, and what won’t cut the mustard.

Look at the system and the evidence

For the Stage 1 Audit, the auditor will focus on the system itself – Have you clearly defined the scope – what functions, systems and sites will the certification cover? Have you developed the necessary policies and procedures? Have you performed a risk assessment and developed risk treatment plans? Have the management clauses been fully addressed? Have you identified which of the 93 Annex A controls are applicable, and provided justifications?

The Stage 2 (Certification) Audit is where the rubber meets the road, and where the auditor needs to verify that the system has been effectively implemented. A policy by itself does not indicate compliance – the auditor will look for evidence that it’s actually being followed. For example, you may have an Access Control Policy, but can you provide evidence of user access reviews, access request approvals, and timely removal of access during offboarding?

Leave with clear priorities

During the readiness review, the consultant will look at your policies, procedures and records to verify that they are complete, consistent with your business operations and meet both the requirements of the Standard, and the evidentiary requirements of the audit.

The output should be a practical gap list, an agreed scope and a sequence of next steps. Some actions may be quick improvements; others may need planning, budget or input from a supplier. Action items should be agreed and ownership of tasks allocated and managed to track progress.

Key points

  • Confirm the key objectives and the required scope of certification before building out the management system.
  • Review how controls work in practice as well as what policies say, and make sure that policies and procedures reflect your business reality.
  • The gap assessment is a great opportunity to improve your security controls and processes. Make sure key people are involved, and turn gaps into owned, prioritised actions.

Need help applying this to your organisation? Talk to Cybervisory.

← Back to News & insights