ISO 27001

ISO 27001: from certification to a living ISMS (2022 Annex A)

The 2022 Annex A moves from 114 to 93 controls, themed as organisational, people, technological and physical.

Certification is just a snapshot. The ISMS must live: management review, gap handling, technical and organisational measures (TOMs), and continuous improvement. MiliSec helps scope, map risk, write the PSSI and prepare the certification audit, then runs the gap follow-up continuously.

The MiliSec method

What we run for our Virtual CISO clients:

  • Certification is a snapshot, run the ISMS.
  • Management review drives improvement.
  • Treat Annex A as living measures.

Going further

Certification is just a snapshot, the ISMS must live day to day.

Management review and gap treatment make the difference over time.

Besoin d'un RSSI Virtuel ?

Notre veille alimente nos recommandations de conformité. Contactez-nous pour un diagnostic.

Demander un audit