This week I cross posted " So Many Security Standards, Audits, and Certifications. Which One is Right?! " to Infosec Island , and was confronted in the comments section by someone claiming that ISO 27001 is not a Point-In-Time assurance, but is in fact, an ongoing, and even real-time assurance. I knew this was not right because of my experience with ISO as a lead auditor for a large Japanese company, so I made my case, and the commenter backed down.