ISO/IEC 27001, explained without the hype
What an ISMS is, how the standard is built, the 93 Annex A controls, the certification process, honest timelines and cost lines. An informational guide, not a sales pitch.
- Certifies a management system (the ISMS), not a single product.
- Whoever prepares you cannot certify you: an accredited body issues the certificate.
- Typical preparation 3-6 months; certificate valid for 3 years.