Cyber Horizon
All articles

Topic

ISO 27001

6 guides on ISO 27001 — practical, audit-tested, and honest about the hard parts.

ISO 27001Risk ManagementAudit

SoA vs Risk Treatment Plan: Two Documents Teams Always Confuse

The Statement of Applicability and the Risk Treatment Plan are both required by ISO 27001 and constantly muddled. What each is for, how they connect, and how to keep them in sync.

6 min read · 17 July 2026

Access ControlSOC 2ISO 27001

User Access Reviews That Actually Pass Audits

The most-sampled control in SOC 2 and ISO 27001 audits — and the most rubber-stamped. Cadence, scope, reviewers, evidence, and how auditors catch box-ticking.

7 min read · 8 July 2026

ISO 27001Internal AuditAudit

ISO 27001 Internal Audits: How to Run One That Actually Helps

Clause 9.2 requires internal ISMS audits — done well, they’re your best pre-certification dress rehearsal. The programme, auditor independence, and turning findings into improvement.

8 min read · 4 July 2026

ISO 27001SoAAudit

The Statement of Applicability: ISO 27001’s Most Important Document

The SoA links your risk assessment to the 93 Annex A controls — and it’s the first document your auditor opens. What it must contain and the mistakes that cause findings.

7 min read · 1 July 2026

ISO 27001SOC 2Strategy

ISO 27001 vs SOC 2: Which Certification Should You Pursue First?

Both prove you take security seriously — but they serve different buyers and audits differently. Here is how to choose the right one first, and how to run them together without doubling the work.

9 min read · 19 April 2026

ISO 27001ImplementationAudit

ISO 27001:2022 Implementation Guide: From Zero to Certified

A practical step-by-step guide to implementing ISO 27001:2022 — the updated Annex A controls, the Statement of Applicability, and how to prepare for certification audit.

12 min read · 25 March 2026