ISO 27001 is a management system standard: auditors look for a working Information Security Management System (ISMS) that is risk-driven, repeatable, measurable, and improving. The most common failures happen when organisations treat certification as a one-off project with paperwork, rather…