Passing an exam is not the same as running a management system an auditor will trust. This post looks at how to move from awareness to audited capability in ISO/IEC 27001 — scope, risk assessment, the Statement of Applicability, and the evidence a Stage 2 audit actually asks for.

Leave a Reply