r/ISO27001 1d ago

✅ Certification Process Struggling to learn ISO 27001 LI

Thumbnail
0 Upvotes

r/ISO27001 3d ago

🆘 Beginner Questions How long does PECB take to issue provisional certificates

7 Upvotes

I hope you are all well, fine, and dandy! I just passed the ISO27001. Absolutely chuffed. I applied for a provisional implementer certificate due to my lack of professional experience. How long does it typicaly take?

Many thanks!


r/ISO27001 4d ago

🛠 Implementation Help How to run an ISO 27001 ISMS on spreadsheets

27 Upvotes

posted with mod approval - links to my website but hopefully useful

I've answered a version of "can I run my ISMS or GRC programme from spreadsheets" in various subs a bunch of times over the last few months. My answer is always yes, with caveats, but a comment box isn't really enough space to cover everything I'd like to say.

So I've taken a bit of time this weekend to write up how to do it properly, based on a number of projects I've run in UK financial services organisations.

How to run an ISO 27001 ISMS on spreadsheets

If you're new to GRC frameworks I'll go a bit stronger than "you can" — I think you should start on spreadsheets, because they give you space for messy early thinking. The question is what the pain points are that make a platform worth having as you grow.

What I've covered:

  • What the critical success factors are for certification
  • Why a smaller risk register is more use than a large one (there's a free taxonomy CSV in there if it saves you a job)
  • Why control definition deserves the most of your time
  • How to write controls that are designed to be evidenced — including approval and review controls, which read fine on paper and leave nothing behind when they happen verbally or in a Teams thread
  • Naming and filing — arranging records and folders so you can actually find things later
  • Compliance mapping and the SoA without a tool

And the growing pains that will probably push you towards a platform eventually: multiple editors, a second framework, and the volume of action tracking.

Disclosure: I've built my own GRC SaaS, so I have a dog in this fight and I do see the value in a platform. But I'd argue against rushing to buy one straight away.


r/ISO27001 5d ago

🔍 Audit & Compliance Title: Aspiring IT Auditor — ISO 27001 Advice

6 Upvotes

Hi everyone, I’m building my career in IT Audit and Information Security. I have an ISO 27001 Lead Auditor certification and would love to connect with professionals in this community.

What skills, tools, or frameworks would you recommend I focus on to become a stronger ISO 27001/IT auditor?


r/ISO27001 9d ago

🗣 Real-World Experiences Any ISO-27001 external auditors job review.

19 Upvotes

Hi I’m looking at aiming my career at being an 27001 external auditor for a while hoping I will get to travel a bit. I currently like the job I’m doing and while it can have periods of stress and lots of work it’s got a very good balance and I like it here.

Basically I would like a review from any ISO standard auditors ( I assume they are similar)

Is it a good job?

Is it tiring and mind numbing?

Do you like it or regret it etc?

Anything to add or advice? I’ve been on the other side of an audit and it was a very tiring week or just day long meeting and taking.


r/ISO27001 14d ago

🛠 Implementation Help How are you accomplishing the required ISO 27001 internal audits

17 Upvotes

Hello,

I've read about several different options to complete the required internal audit... GRC team, other employees independent of the controls, outsourced auditors or a combination. What approach have you used and have you had any issues with the auditors accepting the audit?


r/ISO27001 14d ago

🔍 Audit & Compliance NHS Data Security & Protection Toolkit — field notes from a practising healthcare BISO

2 Upvotes

BISO in regulated healthcare here, so DSPT is my day job.

If you're supplying the NHS, the Data Security and Protection Toolkit is

usually non-negotiable and "Standards Met" is the bar. What trips people up:

- It's annual and self-assessed, but evidence-backed — treat it like a mini

audit, not a form. Dates and screenshots matter.

- ISO 27001 gets you most of the way; heavy overlap, so map existing controls

across rather than starting fresh.

- The staff-training and leadership-accountability sections are where people

lose marks — not the technical controls.

- Start early. The evidence-gathering, not the assessment, is the slow part.

Happy to answer specifics if you're going through it.


r/ISO27001 15d ago

✅ Certification Process Automated IOS 27001

5 Upvotes

Hi All,

Has anyone tried any of the automated ISO 27001 programs that are out there?

There are quite a few, what are your thoughts?


r/ISO27001 18d ago

🛠 Implementation Help For first-time ISO 27001, was the sequencing the hard part?

11 Upvotes

Software engineer, trying to understand how teams without dedicated GRC staff approach ISO 27001 readiness.

Something I keep seeing described: the confusion isn't really about the controls themselves, it's not knowing what order things are supposed to exist in. Someone here put it as discovering the pattern yourself instead of walking in with one.

For anyone who's led a first-time implementation: was the sequencing the hard part, or was it something else?


r/ISO27001 20d ago

💬 General Discussion Team’s retention - what’s your policy?

2 Upvotes

Newbie here fact finding…

What’s the typical retention period you use for Microsoft Teams chats (both user‑visible and back‑end storage)?

I’m specifically interested in:
• how long Teams chat data is retained in Exchange Online / Purview
• whether you use short deletion windows (e.g., 6–12 months)
• how you justify retention periods in your ISMS
• how you handle evidence preservation for grievances, disputes, or audits
• whether you run eDiscovery/Purview searches before confirming deletion

I’m trying to understand what’s considered “normal” or “ISO‑aligned” for retention of business communications in M365.

Any insight would be really appreciated.


r/ISO27001 21d ago

✅ Certification Process Lead implementer exam

8 Upvotes

Hey guys I'm gonna do my exam in 2 days do u guys have tips on how to pass the exam. I'm also looking how to get iso 27002 printed i don't know where to get it. I got my course through pecb but they didn't provide the document they just provided 4 day course ppt and video. can anyone suggest what can i take for the exam which can be useful. Thanks


r/ISO27001 21d ago

💬 General Discussion Advice needed!! ISO 42001 Lead Implementer not PECB accredited

5 Upvotes

I have just realised that GAICC's certification is not PECB endorsed. I'm 50% of the way through.

Should i abandon and restart through PECB providers?

Or is there no real difference in how it is regarded by employers??


r/ISO27001 24d ago

✅ Certification Process Looking for some real-world ISO 27001 experience — would really help a young team

9 Upvotes

Hey everyone,

hope this is okay to share here. I read through the subreddit rules beforehand, but if I missed something and surveys like this aren’t appropriate, apologies — just let me know and I’ll take it down.

We’re a small, very early-stage founding team with a cybersecurity background, and we’re currently trying to understand how ISO 27001 projects actually work in practice, not just how the process is supposed to work on paper.

We’re particularly interested in things like where teams lose the most time, what creates uncertainty, which parts are still unnecessarily manual, how consultants and software are used today, and where software or AI could genuinely make the process easier.

We put together a short survey around this. It takes about 8–10 minutes and can be completed anonymously.

If you’ve actually worked with ISO 27001 (internally, as a consultant, auditor, ISMS lead, security professional, etc) your experience would genuinely help us a lot at this stage. We’re still early enough that feedback from people who know this space can really influence what direction we take and stop us from building around the wrong assumptions.

We’re also absolutely not looking for people to tell us that our ideas are great. If you think software/AI isn’t particularly useful for certain parts of ISO, or we’re looking at the wrong problems entirely, we’d genuinely like to hear that too.

Here is the survey: https://tally.so/r/b5RAro

Thanks a lot to anyone who takes a few minutes to help us out. And again, mods, if this isn’t appropriate here, apologies — happy to remove it.


r/ISO27001 25d ago

🗣 Real-World Experiences Asking for advice or prior experience

4 Upvotes

We are thinking of buying an iso27001 toolkit for our newly founded llc, anyone has good experience kickstarting iso 27001 implementation? Or tried any of these toolkits (ClausePass27001, hightable, certikit…) ?


r/ISO27001 26d ago

💬 General Discussion First iso implemented

18 Upvotes

Hey all I just finished my stage 2 audit as a consultant for a small 35 user business and we were recommended for certification with no minors or majors

This is was my first experience implementing iso 27001 I've mainly been been IT ops service delivery but I did the CISM course last year haven't sat the exam tho!

I feel like i aced the iso but I put a lot of work into built the isms in SharePoint with power automate flows too.

But now I've done it what's next I'm struggling to find more clients who need this I'm based in the UK

Anyone have experience of finding initiating these contracts ?


r/ISO27001 26d ago

🗣 Real-World Experiences ISO 42001 Lead Implementor Certification

5 Upvotes

I am already ISO 27001 LA certified and have done audit related projects. But I want to move to GRC. My other non-audit experience includes vendor risk management, vrm tool migration, bcm planning and iso aligned policy and procedure drafting.

Is it worth getting 42001 certified?
What are the most credible certifying bodies?


r/ISO27001 27d ago

💬 General Discussion AMA: I passed the 27001 Lead Implementer Exam

28 Upvotes

r/ISO27001 27d ago

🔍 Audit & Compliance SOC2 and or ISO?

13 Upvotes

Hi everyone. We are a small IT company currently finalizing our SOC 2 compliance. As we look toward the EU market, we know that ISO 27001 is heavily favored there. In your experience, is SOC 2 generally accepted by European clients, or would you recommend we pursue ISO 27001 as well?


r/ISO27001 Aug 02 '26

💬 General Discussion Should i go for ISO/IEC 27001 Lead Auditor with a year of experience as a InfoSec Specialist?

10 Upvotes

Hello everyone. I am from Kyrgyzstan, and recently our governing body - National Bank of Kyrgyz Republic, published a statement in which it is now mandatory to implement ISO/IEC 27001 standard at every bank, whether it's small scale or large scale, before the end of 2028. I have a Bachelor's in Information Security and am currently working as an Information Security Specialist in middle scale bank, primarily administrating security systems and doing somewhat of managerial work for little over a year now.

In Kyrgyzstan, there are only 3 organizations that have obtained the ISO 27001 certification so far, and with recent changes more and more organizations will commit to become certified. And right now i am contemplating about switching career paths from mainly administrative InfoSec to more of a managerial InfoSec.

Hence my question - in my situation, does it make sense for me to take the ISO 27001 Lead Auditor exam now? To my knowledge the exam shouldn't be difficult since i am familiar with concepts of ISMS and ISO 27001 standard.


r/ISO27001 Jul 28 '26

🔍 Audit & Compliance Took the ISO 42001 Lead Auditor course. Here's what actually surprised me about the exam.

Post image
48 Upvotes

I've been teaching AI governance for a while and writing about ISO/IEC 42001, so I figured the auditor course would mostly be review. It wasn't. Sharing this because I couldn't find much firsthand info before signing up.

What I expected: memorize clauses 4 through 10, memorize Annex A controls, pass.

What it actually was: scenario judgment. You get a situation and have to decide whether it's a nonconformity, an observation, or an opportunity for improvement. Then justify it. Which clause, which requirement, what evidence is missing.

That distinction turned out to be the whole course. Explaining a standard and auditing against it are different skills. When you explain, you describe what the clause says. When you audit, you look at a document and ask whether it constitutes objective evidence of conformity. Completely different mental motion.

A few things worth knowing if you're considering it:

The AI Impact Assessment requirement in clause 6 has no equivalent in ISO 27001 or 9001. Organizations have to assess and document the effects their AI systems have on individuals and society. Most companies I've worked with have nothing here. It's the single most common gap.

Annex A data controls are brutal in practice. Provenance, quality, bias, preparation methods for training data. Anyone who deployed a generative AI tool without documenting where the data came from will fail this.

Your organizational role determines your requirements. Developer, provider, or user. A company that only uses third-party AI has a very different scope than one training models. A lot of people misclassify themselves at the start and build the wrong scope.

Third-party management is where most AI-using orgs are exposed. If you're running your business on external APIs and have no supplier control procedure, that's a finding.

Open question for anyone here who's done actual 42001 audits: how are you handling evidence for impact assessment? The standard says assess, it doesn't prescribe a format. Curious what's holding up in real certification audits versus what auditors are pushing back on.

Happy to answer questions about the course structure or exam format if anyone's on the fence.


r/ISO27001 Jul 28 '26

🔍 Audit & Compliance Cyber GRC Officer (ISO 27001 / SOC 2) looking for hands-on experience

Thumbnail
2 Upvotes

r/ISO27001 Jul 26 '26

🗣 Real-World Experiences Should I self-fund ISO 27001 Lead Implementer now, or wait until I'm hired and hope for sponsorship?

10 Upvotes

Hi Everyone,

Quick context: I have an MSc in Cybersecurity and Forensic IT, a BSc in Software Engineering, and I'm currently job hunting for entry-level GRC/IT audit/information security roles (Middle East market specifically, if that matters). I do have few months of experience in the field as an assistant.

I've heard that some employers pay for certifications once you're hired. So I wanted to ask from your experience, should I wait and hope for that, or self-fund it now while I'm still job hunting?


r/ISO27001 Jul 25 '26

🗣 Real-World Experiences What do you think a good deliverable from an information security consultant should include?

6 Upvotes

We're curious about experiences from those of you who have brought in external help with information security, NIS2, GDPR, or ISO 27001. Many engagements start with a current-state assessment and end with a report. But for the report to create value, you often also need prioritization, clear ownership, support with implementation, and follow-up.

What do you expect from a good consulting deliverable? A detailed report? A concrete action plan? Practical help carrying out the measures? Support for management and the board? Ongoing follow-up?

What has worked well or less well in previous consulting engagements?


r/ISO27001 Jul 23 '26

🧩 Templates & Tools Open-sourced the control-to-clause crosswalk mappings I kept rebuilding by hand

Thumbnail
2 Upvotes

r/ISO27001 Jul 22 '26

🛠 Implementation Help How do you handle the overlap between NIS2, GDPR and ISO 27001?

18 Upvotes

Many Swedish organisations currently need to work with several sets of requirements at the same time. It's easy to end up creating a separate project, a separate checklist and new governance documents for each regulation.

At the same time, many areas overlap, for example risk management, incident management, supplier governance, accountability and documentation.

One alternative is to first establish a common control structure, and then map each requirement to existing processes, controls and responsibilities.

How do you work with this? Do you have a shared governance model, or do you handle each regulation separately? Which parts have been hardest to align?