Skip to content

ISO 27001

Stop asking how important your server is

It is the wrong question, and it is the first question almost every asset register asks.

You end up with a spreadsheet where someone has typed "high" next to a database because it felt important, and "medium" next to a file share because it felt less so. Nobody can defend a single one of those numbers, because they were never derived from anything.

The hard part of ISO 27001 is not the policies

Every template pack on the internet gives you the same thing: a folder of Word documents with your company name find-and-replaced into them. Information Security Policy, Access Control Policy, seventeen more. They look like progress.

They are the easy half. The hard half is proving, on a Tuesday in month nine, that requirement 6.1.3(d) is met and pointing at the thing that meets it.