# ISO/IEC 27001 Lead Implementer interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you set the scope of our ISMS? | Context, interested parties, locations, processes and interfaces, with exclusions justified. | |
| 2 | How do you get real leadership commitment? | A policy signed by top management, roles assigned, resources given, and security in management meetings. | |
| 3 | Walk me through risk assessment and the Statement of Applicability. | Risk criteria, risks with owners, treatment, controls chosen with reasons, and the Statement of Applicability that records them. | |
| 4 | How do you choose Annex A controls? | From the risk treatment, not a checklist, and justify every inclusion and exclusion. | |
| 5 | What documented information do we really need? | What the standard requires plus what the organization needs to run controls, and no more. | |
| 6 | How do you run the ISMS without drowning in paperwork? | Controls built into normal work, owners who run them, and evidence that comes from the work itself. | |
| 7 | How will we know the ISMS works? | Measures and monitoring, an internal audit program, and management review that changes things. | |
| 8 | How do you prepare us for the certification audit? | Documents ready for stage 1, evidence of operation for stage 2, and an internal audit and management review done first. | |

Source: https://credentialpress.com/guides/iso-27001-lead-implementer-interview-questions
