ISO 27001 evidence should be a by-product of your IT operations
Most SMEs experience ISO 27001 as a documentation project: a few intense months of writing policies, collecting screenshots and chasing colleagues for confirmations, followed by eleven months of hoping nothing drifts.
It does not have to work that way. A large part of the evidence an auditor asks for is simply a report from a well-run environment.
What auditors actually ask for
Strip away the annexes and the recurring requests look like this:
- Who has access to what, and who approved it.
- Are devices managed, encrypted and up to date.
- Are changes recorded, with an owner and a date.
- Are backups running, and have restores been tested.
- Are incidents logged, triaged and closed.
- Is there evidence that this happened continuously, not once in March.
Every one of these is an operational fact before it is a compliance artefact.
The difference between a policy and a control
A policy says what should happen. A control is the mechanism that makes it happen, and evidence is the trace it leaves.
| Policy statement | Operational control | Evidence produced |
|---|---|---|
| Accounts are removed when staff leave | Offboarding workflow triggered from HR | Timestamped task log per leaver |
| Laptops are encrypted | Device management policy enforced | Live compliance report per device |
| Critical patches applied promptly | Patch rings with a defined SLA | Coverage percentage over time |
| Data can be recovered | Scheduled backups with test restores | Restore test results with dates |
If your controls only exist as sentences in a Word document, evidence collection is manual forever. If they exist as configuration in the platforms you already pay for, evidence is a report.
Design for the report, not for the audit
Three habits make the difference:
- One source of truth per domain. Identity in one place, devices in one place, infrastructure in one place. Evidence stitched from four overlapping tools is where audit fatigue comes from.
- Automate the lifecycle events. Joiners, movers and leavers are the highest-frequency control in a growing company and the easiest to get wrong under time pressure.
- Review quarterly with leadership. Continuous evidence is worthless if nobody looks at it until the auditor does.
Where the remaining work sits
Operations will not write your scope statement, your risk assessment or your statement of applicability. Those are genuinely yours, and they should be — they encode business decisions.
What operations can do is remove the part of certification that consumes the most calendar time and produces the most drift: proving, month after month, that the controls are still on.
That is how we set environments up for clients — the operational baseline is designed so the compliance evidence falls out of it.