Home DienstenServices Cyber Security & RisicoCyber Security & RiskGovernance, Risk & ComplianceBusiness Continuity & CrisisInterim & CISO-as-a-ServiceBusiness Continuity Management TrainingenBusiness Continuity Management Training AanpakApproach OverAbout Insights Contact
Plan een kennismakingBook an introduction Prepare. Respond. Recover.
Wetgeving zonder ruisRegulation without noise

De vijf duurste misverstanden over ISO 27001The five most expensive misconceptions about ISO 27001

ISO 27001-trajecten lopen zelden stuk op de norm zelf. Ze lopen stuk op wat mensen dénken dat de norm vraagt. Dit zijn de vijf misverstanden die wij het vaakst tegenkomen, en die stuk voor stuk tijd, geld en draagvlak kosten.

ISO 27001 projects rarely fail on the standard itself. They fail on what people think the standard demands. These are the five misconceptions we encounter most, each one costing time, money and support.

7 min leestijd7 min read · Contendr Insights

1. “Het certificaat betekent dat we veilig zijn”1. “The certificate means we are secure”

Het certificaat betekent dat je een werkend managementsysteem hebt: je kent je risico's, je hebt maatregelen gekozen en je controleert of ze werken. Dat is waardevol, maar het is iets anders dan veiligheid. Wie het certificaat als eindpunt behandelt, koopt een fotolijstje en vergeet de foto.

The certificate means you have a working management system: you know your risks, you have chosen measures and you check whether they work. That is valuable, but it is not the same as security. Treat the certificate as the finish line and you have bought a picture frame while forgetting the picture.

2. “We moeten alle maatregelen implementeren”2. “We must implement all the controls”

De bijlage van de norm bevat 93 beheersmaatregelen, als menukaart, niet als verplichte kost. De norm vraagt je te kiezen op basis van je eigen risicoanalyse en uit te leggen wat je weglaat. Organisaties die alles implementeren “omdat het erin staat”, bouwen precies de papieren werkelijkheid waar auditors doorheen prikken en medewerkers omheen werken.

The standard's annex lists 93 controls, as a menu, not as mandatory fare. The standard asks you to choose based on your own risk analysis and to explain what you leave out. Organisations that implement everything “because it is in there” build exactly the paper reality auditors see through and employees work around.

3. “Dit is iets van IT”3. “This is an IT thing”

Informatiebeveiliging gaat over informatie, niet over computers. Personeelsdossiers, contracten, klantdata: de risico's zitten in processen en gedrag, en de belangrijkste keuzes (welk risico accepteren we, wat mag beveiliging kosten) zijn directiekeuzes. Een ISO-traject dat bij IT wordt geparkeerd, levert een systeem op dat de rest van de organisatie niet kent en niet draagt.

Information security is about information, not computers. Personnel files, contracts, client data: the risks live in processes and behaviour, and the key choices (which risk do we accept, what may security cost) are board choices. An ISO project parked at IT produces a system the rest of the organisation neither knows nor owns.

4. “We hebben een dik handboek nodig”4. “We need a thick manual”

De norm schrijft nergens dikke documenten voor. Elk beleid dat langer is dan nodig, wordt minder gelezen, slechter onderhouden en trager aangepast. De beste managementsystemen die wij zien passen in een handvol korte, actuele documenten die mensen daadwerkelijk gebruiken. Documentatie is een middel; het doel is dat afspraken bekend zijn en nageleefd worden.

Nowhere does the standard prescribe thick documents. Every policy longer than necessary gets read less, maintained worse and updated slower. The best management systems we see fit in a handful of short, current documents people actually use. Documentation is a means; the goal is that agreements are known and followed.

5. “Na de certificering zijn we klaar”5. “After certification we are done”

De audit komt elk jaar terug, en belangrijker: je risico's veranderen sneller dan je certificeringscyclus. Nieuwe systemen, nieuwe leveranciers, nieuwe dreigingen. Een managementsysteem dat na de certificering stilvalt, is bij de eerstvolgende audit een probleem en bij het eerstvolgende incident een gemiste kans. Reken op een bescheiden maar structurele inspanning. Dat is geen bureaucratie, dat is de bedoeling.

The audit returns every year, and more importantly: your risks change faster than your certification cycle. New systems, new suppliers, new threats. A management system that stalls after certification is a problem at the next audit and a missed opportunity at the next incident. Budget for a modest but structural effort. That is not bureaucracy, that is the point.

De rode draad: ISO 27001 is geen papieren horde maar een manier om aantoonbaar in control te zijn. Wie de norm licht inricht en echt gebruikt, haalt het certificaat er gratis bij.

The common thread: ISO 27001 is not a paper hurdle but a way to be demonstrably in control. Set it up light and actually use it, and the certificate comes free.

Verder lezen & doenRead on & act
Gerelateerde dienst:Related service: Governance, Risk & Compliance Alle insightsAll insights
KennismakenGet acquainted

Benieuwd hoe voorbereid jouw organisatie is?Curious how prepared your organisation really is?

Plan een vrijblijvende kennismaking van 30 minuten. Je krijgt geen verkooppraatje, wel drie concrete observaties over je huidige weerbaarheid.

Book a free 30-minute introduction. No sales pitch: you will leave with three concrete observations about your current resilience.