Cyber Horizon
All articles

Topic

Audit

8 guides on Audit — practical, audit-tested, and honest about the hard parts.

ISO 27001Risk ManagementAudit

SoA vs Risk Treatment Plan: Two Documents Teams Always Confuse

The Statement of Applicability and the Risk Treatment Plan are both required by ISO 27001 and constantly muddled. What each is for, how they connect, and how to keep them in sync.

6 min read · 17 July 2026

AuditEvidenceCompliance

Audit Evidence: What Auditors Actually Accept (and Reject)

Most audit pain is evidence pain. Point-in-time vs operating effectiveness, what makes a screenshot admissible, how sampling works, and how to collect evidence continuously.

8 min read · 12 July 2026

ISO 27001Internal AuditAudit

ISO 27001 Internal Audits: How to Run One That Actually Helps

Clause 9.2 requires internal ISMS audits — done well, they’re your best pre-certification dress rehearsal. The programme, auditor independence, and turning findings into improvement.

8 min read · 4 July 2026

ISO 27001SoAAudit

The Statement of Applicability: ISO 27001’s Most Important Document

The SoA links your risk assessment to the 93 Annex A controls — and it’s the first document your auditor opens. What it must contain and the mistakes that cause findings.

7 min read · 1 July 2026

SOC 2AuditCompliance

SOC 2 Type I vs Type II: Which Do You Need?

Type I tests control design at a point in time; Type II tests how controls operate over months. The real difference, which to get first, and how to plan the observation window.

7 min read · 9 May 2026

SOC 1AuditFinancial

SOC 1 vs SOC 2: When You Need a Financial-Controls Report

SOC 2 is about security; SOC 1 is about controls that affect your customers’ financial reporting. When you need a SOC 1, how it differs, and how to prepare for both.

7 min read · 8 June 2026

ComplianceAutomationAudit

Continuous Compliance: Moving Beyond Point-in-Time Audits

Annual audits prove you were compliant on one day. Continuous compliance proves you stay compliant every day — here is what it means and how to get there.

8 min read · 24 April 2026

ISO 27001ImplementationAudit

ISO 27001:2022 Implementation Guide: From Zero to Certified

A practical step-by-step guide to implementing ISO 27001:2022 — the updated Annex A controls, the Statement of Applicability, and how to prepare for certification audit.

12 min read · 25 March 2026