Skip to content
GitHubLinkedIn

ISO/IEC 27001 readiness

This page helps structure our documentation if we decide to pursue ISO/IEC 27001 certification. It is not a claim of certification.

What ISO 27001 typically expects (documentation artifacts)

Section titled “What ISO 27001 typically expects (documentation artifacts)”

The exact set depends on scope and auditor expectations, but a typical ISO 27001 program needs:

  • An ISMS scope statement and governance (roles, responsibilities).
  • An information security policy and measurable objectives.
  • A risk assessment approach (methodology) and an active risk register.
  • A Statement of Applicability (SoA) and risk treatment decisions.
  • Documented policies/procedures for relevant control areas (people, access, operations, continuity, suppliers, etc.).
  • Control of documented information (document control).
  • Evidence of internal audits, management review, and corrective actions.

This is a navigation map to the policies we already have.

AreaCurrent canonical docsNotes / gaps
ISMS scopeISMS scope (draft)
Information security policyInformation security policy (draft)
Information security objectivesInformation security objectives (draft)
Risk managementRisk management
Document controlDocument control (draft)
Internal auditISMS internal audit (draft)
Management reviewISMS management review (draft)
Corrective actionNonconformity and corrective action (draft)
Access controlAccess control policy
Information handlingInformation classification policy
Retention & deletionData retention and deletion policy
Incident managementIncident response procedure
Vulnerability managementVulnerability management procedure
Backup & recoveryBackup and recovery policy
Business continuityBCDR plan
Supplier securitySuppliers
Secure developmentSecure development (draft)
Change managementChange management (draft)
Compliance positioningCompliance & alignmentThis page is for external questions; ISO readiness work should live here.
Confidentiality agreementsNDA defaults

These are common policy/evidence areas teams usually need to add when preparing for ISO 27001: