Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
Internal audit and management review, the two steps everyone underestimates
Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.
The 93 Annex A controls, grouped the way you will actually work through them
ISO groups the 93 controls into four themes. That is a filing system, not a work plan. Here is the grouping that matches how a company without a security team actually gets through them.
Scope and Statement of Applicability, explained without the jargon
Two documents decide how much ISO 27001 costs you and whether the certificate answers your customer's question. Here is what scope and the Statement of Applicability actually are, and how small companies get them wrong.