Browser-local readiness check
ISO 27001 readiness check
20 verifiable questions on scope, risk, governance and improvement. The evaluation stays local in your browser.
- 01
Context
Are internal and external issues that affect the ISMS documented?
Expected evidence: Context analysis with review date
- 02
Context
Are relevant interested parties and their requirements captured?
Expected evidence: Requirements register
- 03
Context
Is the ISMS scope approved, including services, sites and interfaces?
Expected evidence: Scope statement
- 04
Leadership
Has leadership defined roles, mandate and resources for the ISMS?
Expected evidence: Decision and role description
- 05
Leadership
Is an information security policy approved and communicated?
Expected evidence: Policy and communication evidence
- 06
Planning
Are risk criteria bindingly defined before the assessment?
Expected evidence: Risk methodology
- 07
Planning
Are information security risks assessed, with owners assigned?
Expected evidence: Current risk register
- 08
Planning
Are the treatment plan and residual risk formally approved?
Expected evidence: Approvals per risk
- 09
Planning
Is the SoA maintained with justifications and implementation status?
Expected evidence: Current SoA
- 10
Support
Are the necessary competences determined and evidenced?
Expected evidence: Competence matrix and evidence
- 11
Support
Are awareness objectives and target groups defined on a risk basis?
Expected evidence: Awareness plan
- 12
Support
Are controlled documents versioned, reviewed and approved?
Expected evidence: Document control
- 13
Operation
Are operational security processes established with owners and evidence?
Expected evidence: Process evidence
- 14
Operation
Are changes to scope, assets and threats fed back into the risks?
Expected evidence: Change and review records
- 15
Evaluation
Are measurable security objectives defined with owners?
Expected evidence: Objectives and metrics sheet
- 16
Evaluation
Is the ISMS covered by a risk-based audit programme?
Expected evidence: Audit programme
- 17
Evaluation
Does a complete management review take place?
Expected evidence: Minutes with decisions
- 18
Improvement
Are nonconformities handled with cause and correction?
Expected evidence: Corrective action register
- 19
Improvement
Is the effectiveness of completed actions reviewed?
Expected evidence: Evidence of effectiveness
- 20
Improvement
Is continual improvement visible in the backlog and in reviews?
Expected evidence: Improvement backlog