before I can get certified? What is the purpose of the Statement of
Applicability (SOA)and what should it contain? Why you should ignore Annex A when
doing ISO27001 what a risk register could contain ISO27001 without metrics and without KPIs ISO27001 without documentation The two tribes of ISO27001. Which tribe are you? Why you should ignore the
Statement of Applicability You do not need an Information Asset
Register for ISO27001 What are “interested parties” and
why do I have to identify them? What parts of ISO27002 must we
comply with to be compliant with
ISO27001? How long does it take to implement
ISO27001? What is it that is mandatory to
implement in ISO27001? What are the mandatory documents
in ISO27001?
See answers to these questions and many many more in Chris Hall's ISO27001 Blog, Articles and Frequently Asked Questions.