ISO27001 Internal Audits – the basics

By |2023-01-07T11:56:08+00:00January 7th, 2023|Internal Audit|

We have been doing some internal audits as part of the ISO27001 certification for our clients. We are undertaking the audits on behalf of clients. Clients frequently do not have the skills, knowledge or time to do the internal audits in-house. It also means that they are getting an experienced internal auditor who understands what's required by the standard. Each internal audit has the potential to pick up areas of nonconformity and areas for improvement. Internal audits are a requirement of the ISO27001 standard and you [...]

Let’s talk policies and procedures

By |2024-02-23T13:10:31+00:00May 7th, 2022|ISO27001 Implementation, policies and procedures|

Let’s talk policies and procedures I often get asked why organisations should bother with policies and procedures. My response is that it creates a uniform structure by which the organisation works, saving time and resources. For larger organisations it shows a fairness in the way it operates as everyone has the same procedure to follow. What usually goes wrong is that the person writing the policy struggles to be able to put into words what needs to happen. Believe me, we have seen some policies which [...]

ISO27001 Implementation – Daunting isn’t it?

By |2024-02-23T13:11:27+00:00March 7th, 2022|ISO27001 Implementation|

One of the first questions we get asked is "What does ISO27001 require us to do as an organisation in order to get certification?". We have had a number of clients who have been told they need to get ISO27001 certified so that a particular client will continue to work with them. When you first start looking at ISO27001, there are a number of elements to it, all of which appear to need completing at the same time. There is also specific terminology used as part [...]

Go to Top