ipfour

Toolkit · Compliance · about 5 minutes

ISO 27001 Readiness Check

Twenty-one questions across the clauses that decide a Stage 1 audit. Most organisations that fail do so on the management system, not the technology — this shows you which side you are on.

21 questions. Nothing is sent anywhere as you answer — the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.

0 of 21 answered0%

Scope and context

What the management system covers, and why.

Is there a documented ISMS scope stating which parts of the business, locations and systems are covered?

The first thing an auditor asks for. Without it there is nothing to audit against.

Have you identified interested parties and their requirements — customers, regulators, insurers?

Are the boundaries with outsourced services and cloud providers clearly defined?

Leadership and policy

Ownership sits with management, not with one person in IT.

Is there an approved information security policy signed off by top management?

Has management formally reviewed the ISMS in the last 12 months, with a record of that review?

Management review is a clause requirement, not a nice-to-have.

Are information security roles and responsibilities assigned and documented?

Are there defined, measurable security objectives?

Risk management

Risks are identified, assessed and treated in a repeatable way.

Is there a documented risk assessment methodology, applied to produce a current risk register?

Is there a Statement of Applicability listing every Annex A control with a justification for inclusion or exclusion?

The SoA is mandatory. Its absence is the single most common Stage 1 failure.

Is there a risk treatment plan with owners and target dates?

Have risk owners accepted the residual risk in writing?

Operational controls

The technical and organisational controls actually run.

Is there an asset inventory covering information, systems and suppliers?

Is access reviewed periodically, with joiners, movers and leavers handled through a defined process?

Is there an incident response process that has been tested or genuinely used?

Are backups taken, held offline or immutably, and restore-tested?

Backups that have never been restored are an assumption, not a control.

Are suppliers assessed for security before onboarding, with security terms in contracts?

Is security awareness training delivered and recorded?

Audit and improvement

The system checks and corrects itself.

Has an internal audit covering the ISMS been completed in the last 12 months?

Are nonconformities recorded with root cause analysis and corrective actions tracked to closure?

Do you measure whether controls are effective, rather than only that they exist?

Are documents version-controlled with a defined retention period?

More in the toolkit