Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
The security annex, clause by clause: what a prime contractor is really asking for
The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.
The risk register that survives an audit, and the one that does not
ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.
The security questionnaire you cannot answer, and what it is really asking
A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.
Doing ISO 27001 and NIS2 once instead of twice
Roughly 70 to 80 per cent of what NIS2 Article 21 asks for is already covered by an ISO 27001 ISMS. The remaining fifth is where the work is, and it is not the part anyone budgets for.
Evidence that assembles itself, and evidence you assemble the month before
Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.
Internal audit and management review, the two steps everyone underestimates
Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.
The 93 Annex A controls, grouped the way you will actually work through them
ISO groups the 93 controls into four themes. That is a filing system, not a work plan. Here is the grouping that matches how a company without a security team actually gets through them.
Scope and Statement of Applicability, explained without the jargon
Two documents decide how much ISO 27001 costs you and whether the certificate answers your customer's question. Here is what scope and the Statement of Applicability actually are, and how small companies get them wrong.