ISO 27001
ISO 27001: from certification to a living ISMS (2022 Annex A)
The 2022 Annex A moves from 114 to 93 controls, themed as organisational, people, technological and physical.
Certification is just a snapshot. The ISMS must live: management review, gap handling, technical and organisational measures (TOMs), and continuous improvement. MiliSec helps scope, map risk, write the PSSI and prepare the certification audit, then runs the gap follow-up continuously.
The MiliSec method
What we run for our Virtual CISO clients:
- Certification is a snapshot, run the ISMS.
- Management review drives improvement.
- Treat Annex A as living measures.
Going further
Certification is just a snapshot, the ISMS must live day to day.
Management review and gap treatment make the difference over time.
Besoin d'un RSSI Virtuel ?
Notre veille alimente nos recommandations de conformité. Contactez-nous pour un diagnostic.
Demander un audit