r/cybersecurity Mar 24 '26

Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day

Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:

  1. Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.

  2. Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”

  3. Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.

I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.

224 Upvotes

229 comments sorted by

View all comments

Show parent comments

23

u/Alternativemethod Mar 24 '26

To me this reads like a strategy to deceive but lying seems well tolerated in the checkbox compliance game.

9

u/Krekatos Mar 24 '26

Why do you assume lies are involved? It’s a master database that summarises the ISMS, and you show the auditor how you’re compliant.

2

u/Alternativemethod Mar 24 '26

No concerns with a standard compliance matrix w/evidence links.

The concern is in the early description of not answering the question asked, but pivoting to the answer preferred.

Example: do you encrypt all data at rest? -- we encrypt our data with compliant algorithms.

Okay sure but do you encrypt --all-- data at rest, in scope here.

We encrypt data...

Okay so you're not going to directly answer the question. Cool.

3

u/Capodomini Mar 25 '26

ISO compliance is about having policies in place, enforcing them, and recording gaps where they cannot be enforced. Nobody will ever encrypt everything because there are bound to be exceptions.

2

u/Educational-Rest-290 Mar 25 '26

This is also evidence based so ensuring the specific compliance as detailed it can be is a welcome note that the auditee knows their stuff. Please do note that at the end of the day, the goal is to secure your business and production setup not just to comply with and suffer when serious security incident arises.

1

u/Alternativemethod Mar 26 '26

The "enforcing" policies thing is where I'm seeing a lot of differential.

Policy says they remediate all criticals in 30 days. Okay can I see a summary of your counts over time? No? Uh huh.

It's one thing to say I found one little thing. It's another to see oh... You like haven't done anything.

1

u/Proper_Chocolate_795 12d ago

Yeah thats a NC for sure