ACloud.Solutions

ISO 27001 and compliance

The ISO 27001 surveillance audit nobody warns you about

The certificate arrived, the deal closed, and the ISMS went quiet. Not neglected exactly. It is just that the risk register was last opened in November, the supplier reviews were a certification-week activity nobody repeated, and the training records cover the people who were here a year ago.

Then the iso 27001 surveillance audit is booked for six weeks' time, and it samples precisely the twelve months you were not thinking about it.

What the iso 27001 surveillance audit actually samples

Certification runs on a three-year cycle. Year one is the initial audit, Stage 1 and Stage 2. Years two and three are surveillance audits, shorter than the original and narrower in scope. Year four is recertification, which is a full audit again.

Surveillance is not a lighter version of Stage 2 across the whole system. It samples, and the sampling is not random. Expect four things every time:

Anything the previous audit raised. Findings and observations from last time are checked first. A minor you closed with a corrective action plan will be tested to see whether the preventive part worked, not just whether the correction happened.

The mandatory annual activities. Internal audit, management review, risk register review. These have to have happened in the intervening year, on the schedule you documented. This is the most common source of year two findings and the easiest to avoid.

A sample of controls, weighted toward whatever is highest risk in your own register and whatever changed in your business.

Changes. New systems, new suppliers, headcount growth, a scope change. The auditor reads your own change records and asks whether the ISMS kept up.

Recertification in year four differs by being comprehensive again, and by looking at the whole three-year arc: has the system improved, have findings recurred, has the risk assessment evolved as the business did.

The controls that lapse first

There is a pattern, and it is entirely predictable, because the controls that lapse are the ones with an annual or quarterly cadence and no operational trigger.

Access reviews. Quarterly in your documented process, performed twice in the year, both times in the fortnight before something. Nothing breaks when a review is missed, so nothing prompts it. The RBAC review note covers the mechanics; the failure here is diary rather than method.

Supplier reviews. Done thoroughly during certification because the auditor was going to ask, then not again. Meanwhile you onboarded three new SaaS tools on somebody's company card, which is the supplier review problem.

Training and awareness records. The gap is joiners. Everyone who was here at certification was trained. The four people who joined since may not have been, and joiner training is exactly what an auditor samples because it is easy to check against a starter list.

Internal audit. The single most common year two major, because it requires scheduling somebody who is not you and nothing prompts it until it is too late. The internal audit note says book it early, and that applies to year two on the day you finish year one.

Management review. Frequently happens as a conversation without minutes, so it did happen and cannot be evidenced. Decisions with owners and dates, or it did not occur.

Business continuity testing. An annual commitment in most plans, and an easy one to defer indefinitely. A two-hour tabletop satisfies it and takes less effort than the deferral costs.

Notice what these have in common. None of them are technical controls, and none of them fail visibly. The technical controls mostly keep working because something breaks when they do not.

A calendar instead of heroics

The fix is not effort, it is a recurring calendar with owners, set up in the week after certification while you still remember what you committed to.

Monthly    Evidence exports: access lists, MFA coverage,
           device compliance, backup outcomes, credential expiry
Quarterly  Access review, with the four-line decision record
           Risk register review, recorded even when nothing changed
Half year  Supplier review for tier one suppliers
Annually   Internal audit (book 6 months ahead)
           Management review, minuted with decisions
           Policy review cycle
           BC/DR exercise
           Full supplier register review
           Training refresh, plus joiner training on start
Per event  New supplier assessment, scope change,
           incident post-mortem, leaver process

Two properties make this work. Every line has a named owner, which for most of them is you and for management review is not. And every line produces an artefact with a date, because the calendar entry is not the evidence.

The monthly line is the one worth automating rather than remembering, per scheduled evidence collection. If those exports run themselves, the quarterly and annual activities become five-minute reviews of data that already exists rather than half-day collection exercises, and that difference is what determines whether they happen.

Carried-over findings

A finding that recurs is treated very differently from a new one.

The same lapse in consecutive years suggests the corrective action was cosmetic, which raises a question about the management system rather than about the control. That can escalate a minor into a major, and it is the mechanism by which a certificate gets genuinely threatened.

So when closing a finding, the preventive action has to be structural. Not "the review has now been done", but "the review had no owner and no calendar entry, both are now assigned to a named role with a recurring reminder, and the management review agenda includes a check that it happened". That is what stops it recurring, and it is also what the auditor is looking for in the wording.

The honest version of year two

Certification is a project with a deadline and adrenaline. Maintenance is neither, and it competes with everything else on your list against a deadline eleven months away.

The companies that find surveillance uneventful are not the ones with better documentation. They are the ones where the recurring activities have owners and calendar entries, and where the monthly evidence collection happens without anybody deciding to do it.

Setting that up takes an afternoon in the month after certification. Not doing it costs a fortnight next year, at a time you will not have chosen.

The book has a chapter on year two specifically, because it was the part that surprised me most, and the security and compliance work covers maintenance as well as implementation, which is generally the less glamorous and more useful half. The ISO 27001 standard sets out the clause 9 and 10 requirements the surveillance audit is testing.