Free self-assessment · about 2 minutes

How ready are you for ISO 27001?

Ten quick questions. No email needed, and nothing you answer leaves your browser.

0 of 10 answered
  1. 01Do you know why you need ISO 27001, and by when?A customer, tender or board deadline.
  2. 02Have you defined what’s in scope: which parts of the business, locations and systems?
  3. 03Is someone in top management sponsoring it and able to approve your policy?
  4. 04Do you have an approved information security policy?
  5. 05Have you identified your information security risks and decided how to treat them?
  6. 06Do you have a Statement of Applicability covering the 93 Annex A controls?
  7. 07Do you have your core policies in place: access control, acceptable use, backup, incident response and suppliers?
  8. 08Are you keeping evidence that your controls actually operate, such as access reviews, restore tests and training records?
  9. 09Have you run an internal audit?
  10. 10Have you held a management review?

This is a quick self-assessment to help you plan. It isn’t an audit, and it can’t tell you whether you’ll pass one.