§ 08 The dossier
The dossier
Four files on penetration testing inside the ISO/IEC 27001 certification cycle. Each is sourced to primary documents, and none of them claims the standard requires a test.
All guides
All files
- File 01 Does ISO 27001 require a penetration test? No, and the pages telling you otherwise are wrong. Here is the exact chain from your risk assessment to the test report your auditor expects, and what to do if you genuinely do not need one. Open file
- File 02 How to scope an ISO 27001 penetration test Scope written from your Statement of Applicability, not from a vendor package. The five inputs, the exclusions you can defend, the wording of the scope statement, and when in the three-year cycle to run it. Open file
- File 03 What an ISO 27001 penetration test report must contain The ten sections that let an auditor trace a finding from discovery to closure, why CVSS alone is not enough for clause 6.1.2, and how to produce a customer-shareable summary without circulating exploit detail. Open file
- File 04 Who can certify your ISMS, and why it cannot be your consultant Accredited certification, the ISO/IEC 17021-1 impartiality rule, what an outsourced internal audit under clause 9.2 legitimately is, how to choose a certification body, and what a mock Stage 2 actually buys. Open file