article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Rather than implementing controls as a checkbox activity, risk-driven organizations proactively choose controls that best mitigate their risks. Your primary reference points will be ISO/IEC 27001:2013, ISO/IEC 27002:2013, and ISO/IEC 27000:2018. Form a Project Team. You must first pick a project leader to oversee the project.

Audit 52
article thumbnail

7 mistakes that ISO 27001 auditors make

IT Governance BC

However, there may still be room to improve your practices, and it might even be the case that your activities aren’t necessary. A version of this blog was originally published on 18 February 2013. Organisations are liable to see that a requirement has been ticked off and assume that it’s ‘mission accomplished’.

Audit 64