Discussion about this post

User's avatar
Stephan's avatar

Thank you for the informative blog post. Is there any chance to see a ISO 27001 Lead Auditor course from you in the future? That would be amazing.

Expand full comment
Anand's avatar

Very insightful article. Although seemingly apparent, it is true that most people do not begin with risk. Another confusion I came across is regarding whether one should include clauses too, alongside 93 reference controls, in the SOA for a 2nd line guy, or in an RCM if s/he is an internal auditor performing compliance check. Clause-6 clearly states we should pick and choose from the 93, but this question still pops up from someone or the other. I mean the 93 controls are meant to cover all the clauses right.

Expand full comment

No posts