Do not panic. Start with this checklist of 10 essential evidence documents. Stage 1 is not a formality. If you fail here, you cannot move to Stage 2. Key documents you must have: Statement of Applicability (SoA) Risk Assessment and Risk Treatment Plan Internal Audit Report Asset Inventory Roles and Responsibilities Legal and Regulatory Register Training Records and Logs Controls Matrix Communication Plan Management Review Minutes (most commonly missed) Auditors mainly check alignment: SoA → Policies → Actual implementation evidence How Azpirantz helps: Information Security Management System (ISMS) setup Continuous monitoring and periodic review Incident management support
Comments