Skip to content

Browser-local readiness check

ISO 27001 readiness check

20 verifiable questions on scope, risk, governance and improvement. The evaluation stays local in your browser.

Back to ISO 27001

  1. 01

    Context

    Are internal and external issues that affect the ISMS documented?

    Expected evidence: Context analysis with review date

  2. 02

    Context

    Are relevant interested parties and their requirements captured?

    Expected evidence: Requirements register

  3. 03

    Context

    Is the ISMS scope approved, including services, sites and interfaces?

    Expected evidence: Scope statement

  4. 04

    Leadership

    Has leadership defined roles, mandate and resources for the ISMS?

    Expected evidence: Decision and role description

  5. 05

    Leadership

    Is an information security policy approved and communicated?

    Expected evidence: Policy and communication evidence

  6. 06

    Planning

    Are risk criteria bindingly defined before the assessment?

    Expected evidence: Risk methodology

  7. 07

    Planning

    Are information security risks assessed, with owners assigned?

    Expected evidence: Current risk register

  8. 08

    Planning

    Are the treatment plan and residual risk formally approved?

    Expected evidence: Approvals per risk

  9. 09

    Planning

    Is the SoA maintained with justifications and implementation status?

    Expected evidence: Current SoA

  10. 10

    Support

    Are the necessary competences determined and evidenced?

    Expected evidence: Competence matrix and evidence

  11. 11

    Support

    Are awareness objectives and target groups defined on a risk basis?

    Expected evidence: Awareness plan

  12. 12

    Support

    Are controlled documents versioned, reviewed and approved?

    Expected evidence: Document control

  13. 13

    Operation

    Are operational security processes established with owners and evidence?

    Expected evidence: Process evidence

  14. 14

    Operation

    Are changes to scope, assets and threats fed back into the risks?

    Expected evidence: Change and review records

  15. 15

    Evaluation

    Are measurable security objectives defined with owners?

    Expected evidence: Objectives and metrics sheet

  16. 16

    Evaluation

    Is the ISMS covered by a risk-based audit programme?

    Expected evidence: Audit programme

  17. 17

    Evaluation

    Does a complete management review take place?

    Expected evidence: Minutes with decisions

  18. 18

    Improvement

    Are nonconformities handled with cause and correction?

    Expected evidence: Corrective action register

  19. 19

    Improvement

    Is the effectiveness of completed actions reviewed?

    Expected evidence: Evidence of effectiveness

  20. 20

    Improvement

    Is continual improvement visible in the backlog and in reviews?

    Expected evidence: Improvement backlog