2. Policies and your responsibilities
Why policies matter in an audit, and who owns what
It is tempting to treat policies as documents you accept on day one and never open again. Under ISO 27001 that approach carries real risk, for you and for the organisation.
Policies are audit evidence
Auditors do not only read the policies. They test whether the policies are known, followed, and enforced. That can mean checking training and acknowledgement records, sampling access requests to see whether the approval process was followed, walking the floor to see whether desks are clear and screens are locked, and asking staff members directly what they would do in a given situation. If the written rule says one thing and observed behaviour says another, that gap is a finding. Enough gaps, or serious ones, threaten the certification itself.
So "I signed it but never read it" is a genuinely bad position. You are expected to know the policies that apply to your role, and the organisation is expected to be able to show that you were trained on them. Both halves matter.
Asset ownership
ISO 27001 expects information and the systems that hold it to have named owners. An asset owner is the person accountable for a system, dataset, or process: they decide who should have access, how the information is classified, and how it should be protected. This is usually a role-based responsibility, the head of HR owning the HR system for example, rather than a technical job.
Why does this matter to you? Two reasons. First, if you need access to something, the owner (or the process they have approved) is the route, not a colleague who happens to have credentials. Second, you may be an owner yourself without the title: if you created and manage a spreadsheet, a shared folder, or a small tool that the team depends on, you are the person who knows who should see it. Treat that responsibility deliberately: restrict access to those who need it, and review it when people change roles or leave.
› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement
Putting it into practice