ISA 6 to ISA2027: Preparing for the Transition
A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.
We use essential cookies to run this site. With your permission we also use analytics cookies to understand which guidance is useful. Nothing non-essential loads until you choose. Cookie details
Resources
Written for information security managers, ISMS managers, internal auditors and the people who actually have to produce the evidence. Every article separates official framework information from good practice and from our own recommendations.
A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.
The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.
New guidance when we publish it. Double opt-in, one-click unsubscribe, and we do not claim a schedule we have not committed to.
The free self-assessment covers every theme in these articles and returns an indicative readiness view with prioritised next steps.
A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.
What counts as evidence, what makes a record usable, and a theme-by-theme list of the records that typically demonstrate each readiness activity.
A gap assessment should end with a small number of owned, dated findings and a defensible sequence. Here is how to run one that does.
Writing a policy is the visible part of readiness work. Making it operate, and producing the record that shows it operated, is the part that decides how an assessment goes.
The recurring mistakes in readiness programmes are structural rather than technical. Here are the ones that cost the most time, and what to do instead.
Evidence that exists but cannot be found is evidence you will reconstruct. A practical structure for organising records so retrieval takes minutes rather than days.
A risk register that nobody acts on is an expensive spreadsheet. What makes information security risk management produce decisions instead of documentation.
Your scope does not stop at your perimeter. How to identify third parties that matter, assess them proportionately, and — the part most organisations skip — follow findings to closure.