Notes
Working notes on Azure cost and security, Microsoft 365, automation and ISO 27001. Written from running all of it for one small company.
All notes
The ISO 27001 Statement of Applicability: 93 controls and justified exclusions
What the SoA is for, how to exclude a control cleanly, and keeping it in sync with the risk register and the evidence.
Microsoft 365, Entra and Intune
Conditional Access policies small business tenants need, and nothing more
A defensible minimum set, report-only mode first, and the policy named TEST DO NOT ENABLE that has been enabled for two years.
An ISO 27001 risk assessment an auditor will actually accept
Method before scoring, owners who are real people, linking risks to Annex A through the SoA, and what gets asked at Stage 2.
Azure managed disk pricing: you are paying for the tier, not the gigabytes
Why a 100 GB and a 128 GB Premium SSD cost exactly the same, and why per-GB estimates understate the bill by roughly 3.7x.
ISO 27001 scope statement: you do not have to certify the whole company
Clause 4.3, what interfaces and dependencies mean in practice, and how scope shapes the risk assessment and the SoA.
Sentinel analytics rules you have not tested are rules you do not have
Copied KQL fails quietly. What to validate before deployment, and the two detection categories worth having first on a small estate.
ISO 27001 implementation small business guide for the volunteered
What the standard asks for, a realistic timeline alongside a day job, and the three things that consume most of the effort.