Skip to main content

"I Think I Signed Something."

Nobody briefs the director before an ISO 27001 audit. Then the auditor asks about the management review. The six questions, the rules for the room, and the tricks that actually work.

Christophe MazzolaChristophe Mazzola· Practicing CISO · Founder of Cyber Academy8 min read
"I Think I Signed Something."

Two directors this week. Same question from me: tell me about your last management review.

First one: "The what?"

Second one: "I think I signed something in March."

My team at Cresco Cybersecurity, part of the Integrity360 group, is taking both organisations through to ISO 27001 certification. Both go into Stage 2 within the month. Both ISMSs are in good shape. Scope written, risk assessment done, SoA justified line by line, internal audit closed and actions tracked. Nine months of solid work by people who knew what they were doing.

And both of them were about to walk their most senior person into a room with an auditor, cold.

Nobody tells the director they're on the schedule

Go and look at your audit plan. Top management has a slot. It's usually early, often before the auditor has looked at anything else, and it exists because ISO/IEC 17021-1 requires Stage 2 to evaluate management responsibility. You can't evaluate management responsibility by reading a policy. You have to talk to management.

So the first real impression of your ISMS comes from the one person in the building who's never read a clause of the standard.

And here's the maths nobody does. A missing control gets you a minor. A missing owner gets you Clause 5. One of those you close with a screenshot. The other says the whole system belongs to nobody, and it changes how the auditor reads every piece of evidence for the rest of the week.

Your director doesn't need to know what TLS is. If they start explaining it, that's worse, not better. They need to answer six questions.

The six

"What's the scope of your ISMS?"

The killer answer is "everything we do." The second killer is silence, then a glance at the security manager. Everybody in the room sees that glance.

Clause 4.3. Boundary, in business language. Which services, which teams, which sites. And one thing that's deliberately out, and why.

That last part matters more than the rest. Anyone can recite what's in. Only someone who sat in the conversation knows what got left out.

"What are your information security objectives?"

"To not get hacked." That's what I got this week. It's honest. It also tells the auditor nobody has ever measured anything.

Clause 6.2. Two or three, roughly, with a direction of travel. Nobody expects a director to quote figures. They do expect the director to know what the company decided to get better at, and whether it's working.

"What are your biggest risks?"

Watch this one. Nine times in ten the director repeats what IT told them, and what IT told them is a list of missing controls. No MFA. Behind on patching. No DR test since last year.

Those aren't risks. They're gaps. An auditor hears that and knows exactly what happened: the risk assessment was built by one technician, in a spreadsheet, alone, and it never left the security team.

"What resources have you provided?"

This is the one that catches them. Every single time.

"We fully support the programme." That's a sentence, not a resource. Clauses 5.1 and 7.1 want something you can count. A budget line. A hire. A tool you paid for. Days released so someone could actually run the internal audit. Training you signed off.

If your director can't name one, sit with the uncomfortable version of that: did you ever ask them for anything? A director who was never asked isn't unsupportive. They're uninformed. And that one is on you.

"Who's accountable for information security here?"

"Our CISO." Wrong, and it's a fast route to a 5.3 finding.

Responsibility gets delegated. Accountability doesn't move. The answer is "I am," followed by who runs it day to day and how often they hear from them.

"Tell me about your last management review."

The most revealing question in the whole interview, which is why I opened with it.

Three things, that's the bar. Roughly when. Who was in the room. One decision that came out of it.

One decision. That's it.

If they can't name one, the auditor concludes what you'd conclude in their chair: the management review happened on paper, a few days before the audit, and nobody made a decision because nobody was really there. Then they go and check. They're usually right.

And one nobody sees coming. Has anyone determined whether climate change is relevant to your ISMS? Amendment 1, February 2024, bolted one sentence onto Clause 4.1: the organisation shall determine whether climate change is a relevant issue. Auditors have been asking since surveillance audits picked it up that year.

"We looked at it, it hits availability at our Lisbon site, it's in the context analysis" works fine. So does "we looked at it, it's not relevant to our ISMS, here's where we wrote that down."

You're allowed to conclude no. You're not allowed to conclude nothing.

Rules for the room

Answer the question, then stop talking. Silence isn't a gap for your director to fill. It's a technique. Directors hate silence and they fill it with detail, and every detail is a door. Every door is a new line of enquiry, and it's on the record now.

"I don't know, [name] does" is a fine answer. Guessing is not. Nobody fails you because a director doesn't hold an operational detail. Every auditor chases a guess that turns out to be wrong, and now you've got a credibility problem sitting on top of a factual one.

Never say "always" or "never." Absolutes are an invitation to go sampling. Say "we always revoke access on the leaving date" and the auditor will go and find the one leaver you missed. "The process says X, and we review it quarterly" survives contact. Absolutes don't.

Don't answer for other people. "I think IT handles that" is a thread, and it will get pulled. "That sits with [name], who's available this afternoon" is not a thread.

Nothing gets promised for after the audit. Anything your director offers to send later goes straight into the notes. If it didn't exist during the audit, it didn't exist. Same trap with "we're working on that." If the work is already logged as an improvement action with an owner and a date, say precisely that. If it isn't, your director has just declared a nonconformity out loud.

Don't vent. Directors vent. "I ask for budget and never get it" is a Clause 7.1 finding, delivered voluntarily, by the one person in the building whose testimony carries the most weight.

Tricks that actually work

Send three highlighted lines, not the pack. Forty-eight hours out, the last management review minutes go to the director with exactly three things marked: the date, who attended, one decision. Nobody reads a twelve-page pack the night before. Everybody reads three highlighted lines.

Give them one number. Directors remember one number. Pick the one that proves engagement and make it theirs. The budget figure, the headcount, the days released for the internal audit. One. Not a dashboard.

Write the accountability sentence with them, in their words. Who's accountable, who runs it, how often they meet. Their phrasing, not yours. A sentence a director built themselves survives the follow-up question. A sentence you wrote for them falls apart on the second one.

Run the first rehearsal with the security manager out of the room. You find out very fast what the director actually holds versus what normally gets handed to them. Bring the ISM back for round two.

Put the records on the table. Policy, scope statement, objectives, last management review minutes. Reading from a record isn't cheating, it's the entire point. A director who says "let me check the minutes" and then checks the minutes has just proven the minutes get used.

Ask for a decent time slot. Not wedged between two board calls. A director in a hurry gives clipped answers, clipped answers read as disengaged, and the auditor extends the session to find out why. Twenty unhurried minutes are shorter than ten rushed ones.

Warn them the auditor may ask you to leave. Some do, and they're entitled to. If your director's face drops when it happens, that's information the auditor now has for free.

Whatever the rehearsal turns up, log it

This is the move most people miss.

You rehearse a week out and you surface three real gaps. The instinct is to go and quietly fix them so they never happened.

Do the opposite. Put them in the improvement log the same day, with an owner and a date.

A gap the auditor finds that you had already logged, owned and dated is evidence that Clause 10 works. The identical gap, unlogged, is a nonconformity. You get to choose which one it becomes, and that choice expires the moment the auditor sits down.

You're not briefing your director. You're auditing yourself.

Forty-five minutes, a week out. I don't present anything. I ask the six questions out loud, in order, and I let them answer badly.

Then we look at what they couldn't answer, and that's where it stops being a briefing.

Can't name a decision from the management review? The management review isn't real.

Can't name a resource? Nobody ever asked them for one.

Can't describe the scope? The scope belongs to whoever drafted it, and that wasn't them.

You didn't build a bad ISMS. You built it next to the business instead of inside it. The documents are fine. The system just doesn't run through the people the standard says it runs through. That's a Clause 5 nonconformity and an auditor would be right to write it.

Better you find it than them. A week is enough to make it true. It's nowhere near enough to make it presentable.

If your audit is on Monday

Three things, in this order.

One decision from the last management review. One number that proves a resource. One sentence on who's accountable.

Get those three and your director walks in with something real to say. Everything else on this page is for next time.

Both companies I sat with this week changed something in the days after. Neither change was a document.

So go and ask your director one question today. Name one decision from the last management review.

Whatever comes back, that's your answer.

Christophe Mazzola is Head of GRC Practice Development at Cresco Cybersecurity, part of the Integrity360 group, and a practising CISO.

Our ISO/IEC 27001 Lead Implementer and Lead Auditor courses cover Clause 5 and Clause 9.3 the way they get audited, not the way they get summarised. Five days, PECB certification, €2,499. Fail the exam twice and you get your money back.

Upcoming dates

Want the next field note in your inbox?

The GRC Brief newsletter. Five links and one short take, every Monday at 8am CET. Three-minute read.

"I Think I Signed Something." · Cyber Academy