<?xml version="1.0" encoding="UTF-8"?>
<!--generator='jetpack-15.8-a.1'-->
<!--Jetpack_Sitemap_Buffer_News_XMLWriter-->
<?xml-stylesheet type="text/xsl" href="//sgrii.com/news-sitemap.xsl"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd">
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-metrics-effectiveness-vs-activity/</loc>
  <lastmod>2026-04-13T11:48:52Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your ISMS Dashboard Reports Activity. Your Auditor Will Ask About Effectiveness. These are Different Questions with Difference Evidence Standards</news:title>
   <news:publication_date>2026-04-13T11:48:35Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-internal-audit-operational-vs-document-audit/</loc>
  <lastmod>2026-04-13T11:25:21Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your ISMS Internal Audit Reviewed Documents. A Stage 2 Auditor Will Test Controls. These Are Not The Same Activity And The Gap Between Them Is Where Certification Credibility Lives.</news:title>
   <news:publication_date>2026-04-13T11:24:52Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27701-integration-isms-pims-architecture/</loc>
  <lastmod>2026-04-13T11:12:51Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 ISO 27701 Is No Longer an Extension. It is a Standalone Standard. Most Organisations Implementing Both Have Not Absorbed What That Means Architecturally.</news:title>
   <news:publication_date>2026-04-13T11:12:13Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-corrective-action-root-cause/</loc>
  <lastmod>2026-04-13T11:07:22Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2025 &amp;quot;Employee Clicked the Phishing Link&amp;quot; Is NOT a Root Cause. It is a Description of What Happened. ISO 27001 Clause 10.2 Requires You to Explain Why the System Allowed It.</news:title>
   <news:publication_date>2026-04-13T11:06:53Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-risk-assessment-scenario-based-methodology/</loc>
  <lastmod>2026-04-13T11:03:37Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your Risk Assessment Identified Risks. It Should Have Identified Risk Scenarios. The Difference Determines Whether Your SoA is Defensible or Decorative.</news:title>
   <news:publication_date>2026-04-13T11:02:56Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-annex-a6-a7-people-physical-controls-governance/</loc>
  <lastmod>2026-04-13T10:53:52Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Twenty-Two Controls That Most Implementations Delegate to HR and Facilities. ISO 27001 Delegates Them to Nobody. They are Information Security Controls.</news:title>
   <news:publication_date>2026-04-13T10:53:12Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-annex-a8-technological-controls-audit-evidence/</loc>
  <lastmod>2026-04-13T10:47:21Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Thirty-Four Technological Controls. Seven New Since 2022. Stage 2 Auditors Test These Operationally. Most ISMS Programmes are Not Prepared for That Test.</news:title>
   <news:publication_date>2026-04-13T10:46:22Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-annex-a5-organisational-controls-policy-vs-control/</loc>
  <lastmod>2026-04-13T10:40:27Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Thirty-Seven Organisational Controls. Three New Since 2022. Most Implementations Treat Them as Policies. The Standard Treats Them as Operational Obligations.</news:title>
   <news:publication_date>2026-04-13T10:39:49Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-integration-isms-2/</loc>
  <lastmod>2026-04-13T10:35:14Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your Statement of Applicability Was Built from Annex A. It Should Have Been Built from Your Risk Register. Here is the Correct Construction Sequence.</news:title>
   <news:publication_date>2026-04-13T10:33:52Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/13/iso-27001-integration-isms/</loc>
  <lastmod>2026-04-13T10:30:20Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your ISMS Has Seven Clauses and Ninety-Three Controls. Most Certified Systems Treat Them as Independent Components. They Are Not.</news:title>
   <news:publication_date>2026-04-13T10:29:22Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/12/iso-27001-clause-9-performance-evaluation-decision-making/</loc>
  <lastmod>2026-04-12T06:07:19Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your Management Review Is A Presentation. ISO 27001 Clause 9 Requires It to Be A System Decision Mechanism. These are NOT the Same Thing.</news:title>
   <news:publication_date>2026-04-12T06:06:39Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/12/iso-27001-clause-8-operational-control-evidence/</loc>
  <lastmod>2026-04-12T06:02:43Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your Risk Treatment Plans Are Not Controls. They are Plans. ISO 27001 Clause 8 Requires Evidence That The Plans Became Operational Reality</news:title>
   <news:publication_date>2026-04-12T06:02:11Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/12/iso-27001-clause-7-support/</loc>
  <lastmod>2026-04-12T05:53:05Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Awareness Training is Not Competence. ISO 27001 Clause 7 Requires Both - With Different Evidence Standards for Each.</news:title>
   <news:publication_date>2026-04-12T05:52:13Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/12/iso-27001-clause-6-risk-soa-traceability/</loc>
  <lastmod>2026-04-12T05:48:12Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Your Statement of Applicability Listed Controls. Your Risk Register Should Have Selected Them. For Most Certified Systems, That Process Ran in Reverse.</news:title>
   <news:publication_date>2026-04-12T05:46:34Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
 <url>
  <loc>https://sgrii.com/2026/04/12/iso-27001-clause-5-leadership/</loc>
  <lastmod>2026-04-12T05:39:14Z</lastmod>
  <news:news>
   <news:publication>
    <news:name>SGRII Performance &amp; Digital Solutions</news:name>
    <news:language>en</news:language>
   </news:publication>
   <news:title>ISO 27001:2022 Signing the Information Security Policy Is Administration. ISO 27001 Clause 5 Requires Leadership. Most Boards Cannot Provide the Difference on Evidence.</news:title>
   <news:publication_date>2026-04-12T05:38:29Z</news:publication_date>
   <news:genres>Blog</news:genres>
  </news:news>
 </url>
</urlset>