ISO 27001 · ISMS reality check
Does your ISMS work, or does it mostly exist on paper?
ISO 27001 tests whether your management system exists. This check tests two things per control point: is it documented, and has it been demonstrably executed in the past twelve months. That difference determines what stays standing during an incident.
Developed by practitioners
This ISMS reality check was developed and validated by senior cybersecurity and GRC architects. Based on ISO/IEC 27001:2022 and focused on the twelve control points where paper and practice diverge the furthest.
Our architect team collectively holds certifications including:
Two axes, twelve control points
Documented and demonstrably executed. After twelve questions, every control point sits in one of these four boxes.
The result appears straight on screen. An email address is only needed if you want the summary sent to you.
Start with your situation
Certification status determines how strict the yardstick is. That is why this is step one.
Trusted by organisations including
Twelve questions · seven minutes
Your quadrant picture, instantly
Two axes per control point: documented and demonstrably executed. The result appears on screen, no email required.
Per point needing attention
Evidence and first step
Not a twenty-page report. Per control point: what it is about, what evidence an auditor wants to see, and the step to start with.
Forwardable
A summary for your leadership
One page, written for someone who did not fill in the check themselves. View it instantly and forward it.
ISO/IEC 27001:2022
The difference between a certificate and a working ISMS
An ISO 27001 certificate demonstrates that a management system for information security exists: policy, a risk assessment, a Statement of Applicability, audits and a management review. The certificate tests the system, not whether every control is executed in practice. That is exactly where the gap arises: a continuity plan that was never tested and an access review that was never performed can both hide behind a valid certificate.
This check measures that gap per control point, on two axes: documented and demonstrably executed in the past twelve months. The twelve points were chosen for where document and execution diverge the furthest in audit practice, from risk assessment and management review to restore tests and alert follow-up. The outcome is not a score but a work list: what sits on paper and does not run is the first place an incident breaks through.
Standard references: ISO/IEC 27001:2022, clauses 4 through 10 and Annex A. Since 1 November 2025, certificates against the 2013 version are no longer valid.
01Risk assessment current
Standard referenceClause 6.1.2 and 8.2
The standard requires a documented risk assessment process, performed at planned intervals and upon significant change, producing consistent and comparable results.
The risk assessment determines where the rest of the ISMS directs its attention. Once it ages, the system protects last year’s organisation.
What counts as evidenceA revised risk assessment no older than twelve months that names this year’s changes.
02Statement of Applicability
Standard referenceClause 6.1.3
The standard requires a Statement of Applicability listing the necessary controls, the justification for inclusion and for every exclusion, and the implementation status.
The Statement of Applicability is the bridge between the standard and your reality: which controls apply, which do not, and why. Once reality drifts away, the document steers nothing.
What counts as evidenceA statement covering today’s systems and suppliers, with a justification per exclusion that holds up.
03Management review with decisions
Standard referenceClause 9.3
The standard requires leadership to review the ISMS at planned intervals, with decisions on improvement and on required resources as the outcome.
The management review is where leadership steers the system: checking whether it works, deciding what must change, and attaching resources. Without decisions it is a presentation.
What counts as evidenceMinutes from the past year with decisions, owners and allocated resources.
04Internal audit, performed independently
Standard referenceClause 9.2
The standard requires internal audits at planned intervals, performed by auditors who safeguard objectivity and impartiality, with reported results.
The internal audit is the function that keeps the system honest: someone without a stake tests whether it works as described. Whoever audits their own work finds little.
What counts as evidenceAn audit report from the past year, performed by someone who does not manage the subject themselves, with findings followed up.
05Corrective actions
Standard referenceClause 10.2
The standard requires that nonconformities are corrected, the cause is removed, and the effectiveness of the correction is evaluated and recorded.
Corrective actions separate a management system from an archive: nonconformities are not just noted, but removed at the cause. Repeat findings prove the opposite.
What counts as evidenceA findings register in which last year’s items are demonstrably closed, with the cause attached.
06Access rights review
Standard referenceAnnex A 5.18
The standard requires access rights to be reviewed at regular intervals and adjusted or revoked upon role change or departure.
Access rights grow by themselves: people change roles, leave, and the rights remain. The review is the mechanism that prunes that growth back.
What counts as evidenceA performed review from the past year with a date and actually removed rights, including admin accounts.
07Supplier assessment
Standard referenceAnnex A 5.19 through 5.22
The standard requires processes to manage information security risk with suppliers: agreements up front, monitoring and assessment during the relationship, and management of change.
Part of your security sits with parties you do not direct but do let in. The assessment makes that part visible and discussable.
What counts as evidenceAn assessment per critical supplier from the past year, with an outcome and a follow-up action.
08Incident response rehearsed
Standard referenceAnnex A 5.24 through 5.26
The standard requires a planned and prepared incident management process with roles, response and evaluation. Preparation that was never put to the test does not demonstrably meet it.
An incident is not the moment to get to know your plan. The exercise moves the learning curve to a moment when it costs nothing.
What counts as evidenceAn exercise report from the past year with the people who must act during a real incident, and the lessons that came out.
09Restore test and continuity
Standard referenceAnnex A 8.13 and 8.14
The standard requires backups periodically tested against the agreed recovery requirements, and ICT readiness for continuity based on those requirements.
A backup only truly exists once it has been restored. The test with the clock running turns an assumption into a number.
What counts as evidenceA test report from the past year with a measured recovery time for a critical system.
10Logging with alert follow-up
Standard referenceAnnex A 8.15 and 8.16
The standard requires that logs are produced, protected and analysed, and that networks and systems are monitored for anomalous behaviour with follow-up of signals.
Collecting logs is storage; detection only exists once someone looks and something happens with an alert. The lead time from alert to action is the real number.
What counts as evidenceA demonstrable daily review of alerts, with, per alert, who saw it and what happened.
11Vulnerability management with deadlines
Standard referenceAnnex A 8.8
The standard requires that information on technical vulnerabilities is obtained in time, exposure is assessed, and appropriate measures are taken within an appropriate timeframe.
Scanning without deadlines is taking inventory. Management begins when each risk class has a fix deadline and someone measures whether it is met.
What counts as evidenceFix deadlines per risk class plus a monthly figure on the percentage closed within the deadline.
12Asset register with ownership
Standard referenceAnnex A 5.9
The standard requires an inventory of information and supporting assets, kept current, with an owner for each asset.
Every policy, review and control leans on the overview of what you have. An outdated register makes the rest of the ISMS partly fictional.
What counts as evidenceA register that matches a current network scan or cloud inventory, with an owner per critical system.
Frequently asked questions
What is an ISMS?
An ISMS (Information Security Management System) is the whole of policy, processes, roles and controls with which an organisation makes information security governable. ISO/IEC 27001 is the international standard that sets requirements for an ISMS, with seven system clauses and 93 controls in Annex A.
Is an ISO 27001 certificate a guarantee that security works?
No. The certificate demonstrates a working management system at the moment of the audit, within the chosen scope. It does not test whether every control is executed continuously. An outdated risk assessment, an untested backup or a never-performed access review all fit within a valid certificate.
What does this check measure that an ISO 27001 checklist does not?
A checklist asks whether something exists. This check also asks, per control point, whether it has been demonstrably executed or tested in the past twelve months. That yields four quadrants, of which paper ISMS (documented, not executed) is the most important: it is the part that holds up in an audit but not in an incident.
How does this check relate to the internal audit?
The check does not replace an internal audit. It is a self-diagnosis of twelve points in about seven minutes, meant to surface the biggest gaps between paper and practice and to sharpen the internal audit. An internal audit tests deeper, with evidence, and is itself one of the twelve control points.
Prefer to talk directly?







