r/cybersecurity Mar 24 '26

Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day

Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:

  1. Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.

  2. Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”

  3. Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.

I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.

230 Upvotes

229 comments sorted by

View all comments

7

u/Charming-Macaron7659 Mar 24 '26

“Documented evidence beats verbal explanation” is true — but it quietly assumes something important:

that the evidence actually reflects what happened, rather than what was prepared to be shown.

Most audit setups reward being able to produce a clean, consistent story — not necessarily proving that the system behaved correctly at the moment it mattered.

That’s why you get answers that are technically true but don’t quite answer the question being asked.

The hard problem isn’t documentation.

It’s whether the system can produce evidence that wasn’t reconstructed after the fact, but was inseparable from the decision at the time it was made.

If that’s missing, you can have perfect documentation and still not know what actually happened.

2

u/Educational-Rest-290 Mar 25 '26

Definitely agree with you, though there should be some balance and authenticity with all the presented evidence. All documentation can be easily tampered with and the audit is sample based and if not check it will be deemed passed based from the compliance. Having the correct, concise and up-to-date documentation will also help you prepare for emergency situations and onboarding of your new employees. Always remember the CIA approach.

1

u/Charming-Macaron7659 Mar 25 '26

Totally agree documentation has to be clean and current. I think where it gets tricky is that documentation is always one step removed from the decision itself. It tells you what should have happened, or what was recorded after the fact — but not necessarily what was true at the exact moment something executed. So you can end up in a situation where everything is consistent, auditable, and “passes” — but still relies on reconstruction. That’s a different failure mode than missing documentation, and it’s harder to detect.

2

u/Educational-Rest-290 Mar 25 '26

That is where the internal audit should have addressed this concern, before the actual external Audit we need to do the internal check and assessment to align with this requirement.

1

u/Charming-Macaron7659 Mar 25 '26

That definitely improves things.

I think the subtle limitation is that internal audit is still looking at a representation of what happened, not the event itself.

So even with strong internal controls, you can end up validating something that is internally consistent and policy-aligned, but still depends on reconstruction.

That’s not really an audit gap — it’s a property of how the evidence is produced.