We are a 25-person B2B software company based in Barcelona. Due to demands from enterprise clients, we began the ISO 27001 certification process, and our Stage 1 audit is scheduled in two months. Our consultant informed us that we need to establish a recurring process and concrete audit evidence for the management of technical vulnerabilities control under Annex A.
Our dev team updates dependencies across code repos occasionally, and automated security patches are applied to servers. However, to date, we have neither a written vulnerability management procedure, nor an official scanning schedule, nor an agreed remediation SLA for resolving discovered flaws. Exactly what logs, reports, and process documentation will the auditor want to see? What is the baseline to pass the audit on the first attempt without drowning in bureaucracy?