Free guide · no jargon
The ISO 27001 starter checklist
What a first certification actually involves, in the order you'll meet it, written in plain English by a certified lead auditor. Useful whether you end up using Sentinel42 or not — and handy for sanity-checking a consultant's quote.
What's inside
- 1Decide what is in scopeWhich parts of the business, people, sites and systems the certificate covers.
- 2Get leadership genuinely involvedWhat your auditor will expect from the people at the top.
- 3List what could go wrongHow to write a risk assessment that stands up, in ordinary language.
- 4Decide which safeguards applyHow to work through the 93 controls and record your reasoning.
- 5Write policies people followThe short set of rules you actually need, not a shelf of documents.
- 6Train your people and record itWhat has to be evidenced, and how much is enough.
- 7Run it and keep the proofAccess reviews, supplier checks, restore tests, incidents, patching.
- 8Audit yourself firstWhy finding problems before the auditor does is the point.
- 9Hold a management reviewThe meeting that turns activity into a decision trail.
- 10Stage 1 and stage 2What each visit looks for, and what happens after you pass.