By Boris Pustilnik, founder of Art of CyberPublished September 29, 20262 min read
In an ISO 27001 audit, "we have a policy" is only the start of the conversation.
What interests me more is what actually happened.
A policy says access to systems is reviewed from time to time. When did you last review permissions, and what changed because of that review?
A document says backups are tested. When did you actually restore something, and how long did it take?
It says security incidents are reported. Who received the last report, and what did you do afterward?
These questions are not meant to catch anyone out. They help show whether security is alive in the organization or only in an audit folder.
When someone comes to me with a stack of policies but I see no record of decisions, tests, and improvements, I know there is more work to do. Not necessarily another document.
If you are preparing for ISO 27001, start with the routine: who does what, how you know it happened, and what you fix when it does not work. Then make sure the policies describe that reality.
A certificate is a nice goal. A system that works the day after the audit is what matters.