ISO 27001-trajecten lopen zelden stuk op de norm zelf. Ze lopen stuk op wat mensen dénken dat de norm vraagt. Dit zijn de vijf misverstanden die wij het vaakst tegenkomen, en die stuk voor stuk tijd, geld en draagvlak kosten.
ISO 27001 projects rarely fail on the standard itself. They fail on what people think the standard demands. These are the five misconceptions we encounter most, each one costing time, money and support.
Het certificaat betekent dat je een werkend managementsysteem hebt: je kent je risico's, je hebt maatregelen gekozen en je controleert of ze werken. Dat is waardevol, maar het is iets anders dan veiligheid. Wie het certificaat als eindpunt behandelt, koopt een fotolijstje en vergeet de foto.
The certificate means you have a working management system: you know your risks, you have chosen measures and you check whether they work. That is valuable, but it is not the same as security. Treat the certificate as the finish line and you have bought a picture frame while forgetting the picture.
De bijlage van de norm bevat 93 beheersmaatregelen, als menukaart, niet als verplichte kost. De norm vraagt je te kiezen op basis van je eigen risicoanalyse en uit te leggen wat je weglaat. Organisaties die alles implementeren “omdat het erin staat”, bouwen precies de papieren werkelijkheid waar auditors doorheen prikken en medewerkers omheen werken.
The standard's annex lists 93 controls, as a menu, not as mandatory fare. The standard asks you to choose based on your own risk analysis and to explain what you leave out. Organisations that implement everything “because it is in there” build exactly the paper reality auditors see through and employees work around.
Informatiebeveiliging gaat over informatie, niet over computers. Personeelsdossiers, contracten, klantdata: de risico's zitten in processen en gedrag, en de belangrijkste keuzes (welk risico accepteren we, wat mag beveiliging kosten) zijn directiekeuzes. Een ISO-traject dat bij IT wordt geparkeerd, levert een systeem op dat de rest van de organisatie niet kent en niet draagt.
Information security is about information, not computers. Personnel files, contracts, client data: the risks live in processes and behaviour, and the key choices (which risk do we accept, what may security cost) are board choices. An ISO project parked at IT produces a system the rest of the organisation neither knows nor owns.
De norm schrijft nergens dikke documenten voor. Elk beleid dat langer is dan nodig, wordt minder gelezen, slechter onderhouden en trager aangepast. De beste managementsystemen die wij zien passen in een handvol korte, actuele documenten die mensen daadwerkelijk gebruiken. Documentatie is een middel; het doel is dat afspraken bekend zijn en nageleefd worden.
Nowhere does the standard prescribe thick documents. Every policy longer than necessary gets read less, maintained worse and updated slower. The best management systems we see fit in a handful of short, current documents people actually use. Documentation is a means; the goal is that agreements are known and followed.
De audit komt elk jaar terug, en belangrijker: je risico's veranderen sneller dan je certificeringscyclus. Nieuwe systemen, nieuwe leveranciers, nieuwe dreigingen. Een managementsysteem dat na de certificering stilvalt, is bij de eerstvolgende audit een probleem en bij het eerstvolgende incident een gemiste kans. Reken op een bescheiden maar structurele inspanning. Dat is geen bureaucratie, dat is de bedoeling.
The audit returns every year, and more importantly: your risks change faster than your certification cycle. New systems, new suppliers, new threats. A management system that stalls after certification is a problem at the next audit and a missed opportunity at the next incident. Budget for a modest but structural effort. That is not bureaucracy, that is the point.
De rode draad: ISO 27001 is geen papieren horde maar een manier om aantoonbaar in control te zijn. Wie de norm licht inricht en echt gebruikt, haalt het certificaat er gratis bij.
The common thread: ISO 27001 is not a paper hurdle but a way to be demonstrably in control. Set it up light and actually use it, and the certificate comes free.
Plan een vrijblijvende kennismaking van 30 minuten. Je krijgt geen verkooppraatje, wel drie concrete observaties over je huidige weerbaarheid.
Book a free 30-minute introduction. No sales pitch: you will leave with three concrete observations about your current resilience.