ISO 27001 in two different companies
Certificationisrarelyabouttickingboxesinisolation.IntwoseparateorganizationsIhelpedsteerthejourneytowardISO27001:mappingrealriskstoactualprocesses,turningpoliciesintosomethingteamscouldrundaytoday,andmakingtheaudittrailaby-productofgoodengineeringânotascrambletheweekbeforetheauditorarrives.
Thehardpartwasalignment:security,product,andopspullinginthesamedirection.Webuiltevidencefromhowwealreadyworked,closedgapswheretheyhurt,andrepeatedthecycleuntil"securebydesign"stoppedbeingasloganandbecamehowweshipped.



