Myth 1: ISO 27001 is mainly documentation
In many companies, the idea that ISO 27001 is essentially a documentation project persists. The impression is often created that the existence of policies, procedures and records is sufficient to fully meet the requirements of the standard. This myth leads organizations to invest a considerable amount of energy in creating extensive documents without considering the actual purpose and added value of an information security management system.
