ISO 27001 at thirty people
A customer has asked for ISO 27001 and you have no security team. What the standard actually requires, and what it does not.
- ISO 27001
- Compliance
What we have learned doing this work, written for the person who has to decide rather than the person who has to implement. No vendor comparisons, no predictions.
A customer has asked for ISO 27001 and you have no security team. What the standard actually requires, and what it does not.
Manual work rarely appears on a budget line, so it survives for years. Here is how to put a defensible number against it.
Most AI pilots do not fail on the technology. They stall because nobody agreed what "working" meant before the build started.