SHOW / EPISODE

EP011: ISO 27001 Is Not the Certificate on the Wall

Season 1 | Episode 11
15m | Sep 5, 2026

In EP011 of The InfoSec Control Room, I look at what happens after an organization earns its ISO/IEC 27001 certificate.

Certification can be valuable. It can bring structure, discipline, credibility, and a much clearer way to manage information security. But problems begin when the certificate becomes the objective instead of the result of a functioning management system.

This episode explores the difference between maintaining an ISMS because an audit is approaching and actually using it throughout the year. I discuss risk ownership that exists only in spreadsheets, Statements of Applicability that stop reflecting reality, internal audits treated as rehearsals for certification, corrective actions that close tickets without fixing problems, and management reviews where everybody says “noted” but no real decision is made.

I also look at the role of consultants, auditors, control owners, risk owners, and senior management in making ISO 27001 useful rather than ceremonial. A good ISMS should survive the consultant, adapt when the business changes, learn from incidents and findings, challenge old assumptions, and help people make better security decisions even when no auditor is watching.

One of the main ideas from EP011 is simple: there is a huge difference between an organization that documents how it manages information security and one that manages documents about information security.

The certificate matters, but the real value is underneath it: the decisions, ownership, corrections, useful findings, changing risks, and improvements that happen between audits.

Paused
Audio Player Image
The InfoSec Control Room
Loading...