ISO 27701 alongside ISO 27001: privacy in the same ISMS
Privacy and security belong in one management system. How to avoid duplicate documentation and satisfy GDPR and audit?
Read article: ISO 27701 alongside ISO 27001: privacy in the same ISMS →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams, educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base, from vendor management to processor agreements.
Free tool: Vendor & processor document generator, GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
Privacy and security belong in one management system. How to avoid duplicate documentation and satisfy GDPR and audit?
Read article: ISO 27701 alongside ISO 27001: privacy in the same ISMS →
Awareness is more than annual e-learning. How to link behaviour, phishing tests and management review to ISO 27001?
Read article: Security awareness for SMEs: measurable and audit-ready in 2026 →
Privileged access and orphaned accounts are surveillance favourites. How to organise reviews per cloud app with an auditable trail.
Read article: Access reviews in SaaS: quarterly rhythm without Excel chaos →
Ransomware remains the dominant threat for Dutch SMEs. What belongs in your playbook, and what do auditors and customers want to see?
Read article: Ransomware playbook for SMEs: first hours and audit evidence →
Internal audit is not a paper exercise. How to choose samples, train auditors and deliver evidence certification bodies accept.
Read article: ISO 27001 internal audit in 2026: planning that prepares surveillance →
Essential and important entities must report incidents on time. How to organise triage, chain communication and documentation without panic?
Read article: NIS2 incident notification: practical timelines and evidence in 2026 →
CIS is practical for technical teams; ISO for the management system. How to avoid duplicate documentation.
Read article: CIS Controls alongside ISO 27001: when it helps, and when it does not →
More logs are not automatically better. Focus on sources, retention, alerting and who monitors.
Read article: Logging and SIEM: what auditors actually want to see in 2026 →
NIS2, DORA and large customers send longer surveys. Build one source of truth for security answers.
Read article: Supplier security questionnaires in 2026: answer faster without copy-paste →
Ransomware puts business continuity back on the board agenda. How to connect continuity plans with incident response and ISO 27001.
Read article: BCM and ISO 22301 linked to cybersecurity incidents →
Zero trust does not have to be enterprise-only. Start with identity, device posture and least privilege per cloud app.
Read article: Zero trust with SaaS: a realistic roadmap for SMEs →
A report alone is not enough. Which scope, remediation and re-test do certification bodies expect in 2026?
Read article: Penetration tests as audit evidence: what auditors accept, and reject →isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)