“Security is a process, not a product. Products provide some protection, but the only way to effectively do business in an insecure world is to put processes in place that recognize the inherent insecurity in the products.”Bruce Schneier · The Process of Security · 2000 · Bruce Schneier, «The Process of Security», revista Information Security, aprilie 2000 — paragraful de deschidere
The certificate is a photograph, and security is the film it was cut from.
Schneier's sentence is a quarter of a century old and still the best objection to compliance treated as a destination. A certificate says that, on the audit days, a sample of evidence matched the requirements. The system that produced that evidence can be abandoned the next morning and the certificate stays valid until the next surveillance visit. The certificate is a photograph; security is the film it was cut from. Hence the practical test for any compliance programme: if a control only works when an audit approaches, the control does not exist, only audit preparation does. The signs are easy to spot: a year of access reviews all performed in the same week; logs collected retroactively; training completed by everyone in three days. ISO/IEC 27001 is built against exactly this pattern, because it requires measurement (9.1), internal audit (9.2), management review (9.3) and corrective action (10.2). That is cadence, not an event.
Why it matters The surveillance auditor looks for traces of rhythm, and evidence crammed into the final week tells its own story.