Certification is straightforward when the management system reflects how the business actually runs. Here is how to avoid a paper ISMS.
ISO/IEC 27001:2022 rewards organisations that build a management system around real operations. It punishes those who write an ISMS for the auditor and then run the business a different way.
Scope decides everything
A narrow, honest scope certifies faster and survives surveillance audits. An overreaching scope creates findings in areas the business never intended to control.
Get the risk assessment right
Assets, threats, owners, treatment decisions and residual risk acceptance — recorded, dated and approved. The Statement of Applicability should follow from that assessment, not from a template.
Annex A in 2022 terms
The 93 controls are grouped into organisational, people, physical and technological themes. New additions such as threat intelligence, cloud service security, secure coding and data leakage prevention reflect how organisations now operate.
Evidence over intent
Auditors test operation, not authorship. Internal audit, management review, corrective actions, competence records and metrics need a visible history. Three weeks of logs before Stage 2 is a familiar and avoidable finding.
Extending the certificate
ISO/IEC 27701 adds privacy information management for GDPR alignment. ISO/IEC 42001 adds AI management. Both sit on the same clauses 4 to 10 spine, so the incremental effort is far smaller than a standalone programme.
Build the system you actually use, and certification becomes a by-product.
- ISO 27001
- ISO 27701
- certification