ISO 27001:2013 – It doesn’t have to be difficult
We’ve been working in and around ISO27001 quite a bit lately. Several new clients are working toward implementation, and it’s always interesting to see how differently organisations interpret and implement the standard. This has coincided with our own annual audit for both 27001 and 9001 (both passed, one observation for improvement, which is always welcome). Talking to the various clients, consultants and auditors involved, it seems that the same common mistakes are made time and again:
1. Rushed certification attempts