Anders Krogh is CISO at Meridian Nordic, an energy group with entities in Denmark, Sweden and Germany and an ISO 27001 certificate that has to survive an audit every year. Winning the certificate was never the hard part. Proving twelve months later that the controls behind it had actually been performed was, because the evidence sat in mail threads and on a shared drive, and every audit was preceded by two weeks of reconstruction. Now the controls sit under ISO 27001 with the standard's own numbering, each one carrying the tasks that document it, with a named owner and a date. This year Anders prepared by reading a list instead of rebuilding one.