If you’re preparing for ISO 27001 certification, shift your focus from asking “How do we prepare the evidence?” to “Are our security processes actually working?” When risks are properly assessed, controls are appropriate, people know their responsibilities, and controls are consistently performed and monitored, the evidence will largely already exist. Build and strengthen the security processes first, and let the evidence follow - because security is about becoming more secure, not about creating documentation for its own sake.

LINK FROM THE VIDEO
► ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange | EP36 https://www.youtube.com/watch?v=4HNwmgCiKyU

  • (00:00) - Stop Preparing Evidence for Your ISO 27001 Audit
  • (00:17) - How ISO 27001 Certification Audit Works
  • (01:35) - How Auditors Collect Evidence
  • (02:27) - Three Things Companies Get Wrong
  • (04:04) - “Push” vs “Pull” Approach
  • (04:30) - Evidence Does Not Improve Your Security
  • (05:01) - Build Security Processes Not Evidence
  • (06:14) - Let The Evidence Follow

Podden och tillhörande omslagsbild på den här sidan tillhör Dejan Kosutic. Innehållet i podden är skapat av Dejan Kosutic och inte av, eller tillsammans med, Poddtoppen.