ISO/IEC 27001
Information security management alignment covering risk based controls, access responsibility, asset and information handling, incident paths, supplier interfaces and continual review.
Engagement evidence: access matrix, control ownership, risk and issue records, change history and review cadence.
