The risk assessment is where nearly every ISO 27001 project stalls out, and it’s also where you can tell whether the management system was actually built or just written up on paper. Plenty of companies spend weeks filling out a giant spreadsheet packed with dozens of theoretical threats and scores pulled out of thin air, […]