Checklist d'audit ISO 27001
Preparation a la certification ISO 27001 couvrant le perimetre ISMS, l'evaluation des risques, les 93 controles de l'Annexe A et le choix de l'organisme de certification.
Preparez-vous systematiquement a votre audit ISO 27001.
Obtenez votre checklist gratuite
Pas de carte bancaire requise. Téléchargement instantané.
Nous envoyons le lien de téléchargement une seule fois à l'adresse fournie. Les e-mails marketing sont envoyés uniquement si la case ci-dessus est cochée.
Contenu inclus
Tout ce dont vous avez besoin pour évaluer, planifier et exécuter votre parcours de conformité.
Conçu pour les services financiers réglementés dans l'UE
Questions fréquemment posées
How long does ISO 27001 certification typically take?
For most organizations, ISO 27001 certification takes 6-12 months from start to certification audit. This includes ISMS design and implementation (3-6 months), a mandatory operating period to demonstrate effectiveness (typically 3 months), the Stage 1 audit (documentation review), and the Stage 2 audit (implementation assessment). With Matproof, teams typically cut this timeline in half.
What is the difference between ISO 27001:2013 and ISO 27001:2022?
ISO 27001:2022 restructured Annex A from 114 controls in 14 domains to 93 controls across 4 themes: organizational (37), people (8), physical (14), and technological (34). It also introduced 11 new controls covering threat intelligence, cloud security, ICT readiness, and data masking. Existing certificates must transition by October 2025.
Do we need an external auditor for ISO 27001?
Yes, certification requires an accredited third-party certification body to conduct Stage 1 and Stage 2 audits. However, internal audits (which you conduct yourself or with consultants) are also a mandatory requirement of the standard. This checklist covers preparation for both internal and external audits.
How does ISO 27001 relate to SOC 2?
Both ISO 27001 and SOC 2 address information security, but ISO 27001 is a certifiable management system standard (international), while SOC 2 is an attestation report (primarily US market). There is significant overlap in controls - roughly 70% of SOC 2 Trust Services Criteria map to ISO 27001 Annex A controls. Matproof helps you manage both simultaneously with shared evidence.