When a company starts looking at ISO 27001, the first question is usually how to get certified. But before that audit, there are months of internal work nobody mentions during the sales pitch. Before an outside auditor ever walks through your door, someone on your team has already had to decide what gets protected, what […]