ISO 27001 Is a Risk Program With a Certificate Attached
Auditors can smell a checklist ISMS. Building the Statement of Applicability and risk treatment plan from quantified risk — and surviving stage 2 with evidence, not binders. A SaaS company we worked with (around 120 people, series B, selling into European enterprises) came to us with a Statement of Applicability their previous consultant had handed over. All 93 Annex A controls were marked "applicable." Every one. When I asked the CISO why control A.5.7, threat intelligence, applied to a company that had no threat intelligence function and no plans to build one, he shrugged and said the consultant told him it was safer to include everything. That SoA was going to get torn apart in the stage 2 audit, and it did the first time before we got involved. This is the most common way ISO 27001 goes wrong. People treat it as a checklist of 93 controls to implement, when the standard is actually built around a management system for information security risk. Clauses 4 through 10, the ones that don't get talked about at conferences, are where certification is won or lost. Annex A is a menu you select from based on the risks you've identified, not a mandatory bill of materials. The risk assessment is the load bearing wall Clause 6.1.2 requires you to define and apply a risk assessment process, and clause 6.1.3 requires risk treatment. Everything downstream, includ