Policy, ownership and the paper trail
Security is a named responsibility with a named owner, not a shared intention. Policies are written, approved, versioned and reviewed on a cycle - and the audit that renews the certificate checks that the cycle actually ran.
- Documented ISMS with a Statement of Applicability covering every Annex A control we apply - and a recorded justification for any we don't
- Risk register maintained continuously, with treatment plans and residual risk accepted at a named level
- Supplier and sub-processor review before any third party touches a client environment
- Incident response with defined severities, escalation paths and client notification obligations