Hi,
I'm looking to contract with entities that require ISO27001 self-certification in the short term and full certification later. I'm aware of consultants etc who will do the audit/certification but in the short term I'm looking to be able to self-certify without overspending time or money. I've seen a number of toolkits online ranging from free (crowdsourced) to ~$1,500 which say they offer the templates etc to work from. I'm aware it won't be a cut and paste exercise but I would appreciate any feedback from those who have gone down this route on what works/what to avoid etc. Thanks in advance.
Weird question… is there a need to be ISO27001 compliant? Can you outsource it?