Paperback & Kindle · 130 pages
Somebody decided the company needs ISO 27001. That somebody was not you.
The work is now yours, on top of the job you already had. This is the book for that situation: not a restatement of the standard, and not a consultancy pitch.
It is a field guide written by one person who took a 40-person SaaS company through ISO 27001:2022 certification alone, and who kept notes on everything that went wrong.
Prices and availability on Amazon.co.uk. Also sold on other Amazon marketplaces.
What is inside
The parts of certification that cost time and nobody documents properly.
- Scoping without certifying the whole company by accident. The single decision that determines how much work the rest of it becomes.
- A risk assessment an auditor will accept and you can actually maintain. Not a spreadsheet you fill in once and never open again.
- What Stage 1 and Stage 2 really test. They are different audits with different failure modes, and being ready for one is not being ready for the other.
- What a minor nonconformity actually costs. In time, in evidence, and in what it does to your certification timeline.
- The year two surveillance audit nobody warns you about. Certification is not the finish line, and the second year catches people who treated it as one.
Written from one certification, done alone, with the mistakes left in rather than tidied out.
Who it is for
If any of these is you, the book was written for your situation.
The accidental compliance lead
You are IT, or ops, or engineering, and ISO 27001 landed on you because there was nobody else to give it to.
The SME with no budget for a consultancy
A certification body is already expensive. Paying a consultancy on top is not happening, so you need to do the work yourself.
The person who has read the standard
And found it tells you what must be true without telling you how to make it true, or what an auditor will actually ask for.
Anyone facing surveillance
You got certified, the pressure came off, and now year two is coming. This is the part most people are least ready for.
Details
| Formats | Paperback and Kindle |
|---|---|
| Print length | 130 pages |
| Publisher | Independently published |
| Published | 6 September 2026 |
| Language | English |
| ISBN-13 | 979-8172091605 |
| ASIN | B0HJ267BXT |
| Dimensions | 15.24 × 0.79 × 22.86 cm |
| Standard covered | ISO/IEC 27001:2022 |
Need more than a book?
The book is the do-it-yourself route. If you would rather have help, or want the tooling that came out of the same work, both are here.
Access reviews, audit evidence and remediation tracking are part of the consulting work, and the AzClean tools cover the Azure side of the evidence an auditor asks for.
Notes
Read a sample of the thinking
Four of the notes on this site cover the same ground as the book's central chapters. They are the honest preview: if the approach reads useful, the book is the longer version.
- ISO 27001 on your own a realistic plan for the person who was volunteered
- A risk assessment an auditor will accept method before scoring, and the six questions asked at Stage 2
- Stage 1 and Stage 2 what each audit actually tests, and what evidence means
- The year two surveillance audit the controls that lapse, and why nothing prompts them
The rest of the ISO 27001 notes cover scope, the Statement of Applicability, policies, internal audit independence, compliance platforms, evidence on a schedule and documentation.
Get the book
Paperback and Kindle, on Amazon.co.uk and other marketplaces.
1 of 93 down… 92 to go… keep going