Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
ISO 27001 Readiness Checklist

A practical first-pass checklist for SaaS and technology companies.

Use this to identify obvious readiness gaps before deciding whether you need a gap assessment, readiness project or internal audit.

ISMS foundation

  • A defined ISMS scope and boundaries
  • Relevant interested parties and security requirements identified
  • Information-security policy approved
  • Security roles and responsibilities assigned

Risk management

  • Documented risk assessment method
  • Current risk register
  • Risk treatment decisions and owners
  • Statement of Applicability maintained

Identity and access

  • MFA coverage understood
  • Privileged access identified and reviewed
  • Joiner, mover and leaver process operating
  • Guest, service and dormant accounts governed

Operations

  • Asset inventory maintained
  • Vulnerability and patch process operating
  • Backups tested, not merely scheduled
  • Logging and monitoring responsibilities defined
  • Change control evidence retained

Suppliers and people

  • Critical suppliers identified and reviewed
  • Security requirements included in supplier process
  • Security awareness and competence records retained
  • Confidentiality obligations defined

Assurance

  • Internal audit programme planned and executed
  • Management review performed with recorded decisions
  • Nonconformities and corrective actions tracked
  • Evidence can be produced for control operation, not only policy existence

What the checklist cannot tell you.

A checklist does not establish whether evidence is sufficient, whether a control is effective, or whether the selected scope and risk treatment are appropriate.

Use it for triage. Use an assessment for evidence-based conclusions.