← Catalogo generale
Effedore Edizioni
The Helm and the Lens · English
In attesa di approvazione / Pending approval

The Helm and the Lens – Vol. 5b

ISO/IEC 27001 and the Custody of the Guest Volume 5b — The Lens

Every system described in the companion volume has to be believed by somebody who did not build it. Volume 5b follows the two people whose job that is — the internal auditor and the certification auditor — through thirty hotels in thirty cities.

572 Pagine

The owner who signed the policy believes it. So does the general manager who approved the Statement of Applicability, and so, usually, does the coordinator who wrote most of it. None of them is the right person to say whether it works. The guest cannot say, because the guest sees only the counter and the confirmation email. The corporate client cannot say, because it sees only the answers on its questionnaire. Somebody has to go and look — with a method, with independence, and with the discipline to write down what was found rather than what was expected.
In this standard there are two such people. The internal auditor works for the hotel and can be asked to look again. The certification auditor is sent by a body that has itself been assessed by an accreditation body, which has in turn been evaluated by its peers under an international arrangement; that auditor works, in a sense, for everybody else. Volume 5a was the helm: what ownership decides and what management does with those decisions. Volume 5b takes the same thirty questions from the other side and asks how anybody would know.
Why auditing a hotel is its own problem
Three facts govern everything in this book. The first is that the information an auditor must examine is mostly invisible from a meeting room: it is on a printed list in a pantry, in a tray under the counter, on a tablet in a vehicle, in a messaging group and in a supplier's data centre. An audit that stays where the documents are will find the documents in order and the information somewhere else.
The second is that a hotel's exposure moves through the day, the week and the year. The desk at four in the afternoon, the back office at two in the morning, the fair week and the weekend of three weddings are different organisations from the hotel at eleven on a Tuesday in November. An audit programme that always visits at the same quiet hour measures the hotel when it is least like itself.
The third is that most of what the auditor must judge is held by other people: the property system is hosted, the backups are kept by the provider, the transfer company has the arrival list, the lock supplier can connect at night. To these the certification rules add a fourth, and it is what separates this volume from the first. Certification is a relationship with obligations on both sides. The certifier must be impartial, competent, confidential, and must not advise; the hotel must be honest, must give access, must declare significant change and must not claim more than its certificate says. Much of the fourth chapter is about what each side owes the other, and about what happens when either forgets.
Two chapters that answer each other
Chapter 3 belongs to the internal auditor: how to audit information that cannot be seen; when to audit a hotel whose risks move through the week; what a checklist should look like at a front desk; how to audit the law without pretending to be a lawyer; near misses, supplier audits, retention, root cause, restores, account rights, penetration tests; the report that ownership will actually read; and follow-up that is not the auditor checking their own work.
Chapter 4 belongs to the certifier: the chain that gives a certificate its value; choosing a body that has seen a hotel; Stage 1 and Stage 2; evidence in a business that runs on discretion; major findings, minor findings and the opportunity that is not one; the certificate and its scope; surveillance; what a certified hotel may say; lenders and insurers as readers; multi-site groups; change during the cycle; recertification.
Thirty cases, and the case that runs the other way
Every case is composite: thirty properties in thirty cities — Zurich, Seville, Lima, Abu Dhabi, Hanoi, Casablanca, Johannesburg, Honolulu and twenty-two others — none of them a real hotel, each assembled from patterns that recur. Every financial figure is modelled and declared as such. No certification body, accreditation body, supplier, consultancy, brand or person is named anywhere in the body of the book.
Each subchapter carries the same elements: a Guiding Question that can be tried on your own hotel today; What the Standard Says, in the book's own words; the Verification Pact, which runs five common beliefs against what actually holds; a table setting each requirement against what would demonstrate it and against what nobody is asking for; and the instrument of the subchapter — a sheet a reader can take to their own hotel and use. Each closes with the case that runs the other way: the auditor who tests everything, the follow-up so rigorous that nothing ever closes, the hotel so anxious about its certificate that it freezes all change. Over-correction is as common in auditing as under-performance.
Thirty concept cards, one per subchapter, hold the moment each case turns. Eight appendices follow the Afterword, as working material: an audit programme across a cycle, the certification rules set out as questions a hotel can ask, an owner's explanation of audit time and sampling, interview questions department by department, a catalogue of evidence that does not expose guests, the certification cycle month by month, findings written well and badly, and the thirty cases in brief.
What this book is not
It is not a manual of audit technique in general, nor a guide to technical security testing, which is a different profession. It will not tell a reader whether a particular hotel should be certified, and it recommends no certification body, consultant or tool. It reproduces no part of any standard. Where it describes what the rules for certification bodies require, it says so; where it describes a method, it says that too. The distinction matters, because a good deal of what hotels believe about certification is in fact what one particular certification body happens to do — and a hotel that knows which is which can ask better questions and decline worse offers.
Edition, and what is moving around it
The volume is written against the 2022 edition of the standard with its 2024 amendment, the general rules for bodies that certify management systems, the additional rules for bodies certifying information security management systems in their 2024 edition, and the international guidance on auditing. Around those rules, things are moving: the international arrangement for accreditation changed its form in January 2026, and the mandatory documents governing multi-site certification, remote auditing, integrated audits and transitions between editions are being reissued under new designations. This volume describes what those documents require and does not rely on their numbers; the series platform carries the current designations and dates, and will say what changes when any of them is revised.
The Helm and the Lens — Volume 5b. Thirty subchapters, thirty concept cards, eight appendices, Sources and Research Methodology, Glossary, Index. First edition, 2026, Edizioni Effedore. Its companion volume of the helm is Volume 5a, ISO/IEC 27001 and the Custody of the Guest.

Pubblicazione 2026-09-28 Edizione 2026 Formati 1 In attesa di approvazione / Pending approval
The Helm and the Lens – Vol. 5b
EDIZIONI · FORMATI

Formati disponibili

Le edizioni fisiche e digitali associate a questa scheda.

Copertina flessibile

NEL LIBRO

Contenuto / Contents

La struttura del volume così come presentata nell’edizione pubblicata.

Table of Contents
  • Preface.
CHAPTER 3.
  • 3.1  Auditing Information Nobody Can See.
  • 3.2  Planning an Audit Around the Hotel's Week.
  • 3.3  The Checklist That Goes to the Front Desk.
  • 3.4  Auditing the Law Without Becoming a Lawyer.
  • 3.5  The Digital Near-Miss.
  • 3.6  Interviewing for Awareness.
  • 3.7  Second-Party Audit: The Software House and the Cloud.
  • 3.8  Retention: The Data the Hotel Believes It Deleted.
  • 3.9  Root Cause, and the Answer That Is Not the Employee.
  • 3.10  Backups That Have Never Been Restored.
  • 3.11  Auditing Accounts and the Rights Behind Them...
  • 3.12  The Penetration Test and What It Did Not Test.
  • 3.13  The Report That Ownership Will Read.
  • 3.14  Follow-Up, and the Closure the Auditor Did Not Design.
  • 3.15  What the Internal Audit Owes the Management Review..
CHAPTER 4.
  • 4.1  The Chain That Makes a Certificate Mean Something.
  • 4.2  Choosing a Certification Body That Has Seen a Hotel
  • 4.3  Stage 1: Is the System Ready to Be Audited?.
  • 4.4  Stage 2: Does It Work at the Counter?.
  • 4.5  The Lead Auditor, and the Hotel's Side of the Table.
  • 4.6  Objective Evidence in a Business That Runs on Trust.
  • 4.7  Findings: Major, Minor and the Opportunity That Is Not One.
  • 4.8  The Certificate, and What It Actually Certifies.
  • 4.9  Surveillance, and the Year the Hotel Changed Hands.
  • 4.10  What a Certified Hotel May Say.
  • 4.11  Integration with Quality, Environment, Safety and Privacy.
  • 4.12  Lenders, Insurers and the Certificate as Evidence.
  • 4.13  Multi-Site Certification for a Hotel Group.
  • 4.14  Change During the Cycle: New System, New Owner, New Edition
  • 4.15  Recertification, and the System That Has to Stay Awake.
  • Afterword.
  • Appendix A — An Internal Audit Programme Across the Cycle.
  • Appendix B — The Certification Rules as Questions a Hotel Can Ask.
  • Appendix C — Audit Time, Sampling and Remote Auditing, for Owners.
  • Appendix D — Interview Questions, Department by Department.
  • Appendix E — Evidence Without Exposure, Control by Control
  • Appendix F — The Certification Cycle, Month by Month.
  • Appendix G — Findings Written Well and Badly.
  • Appendix H — Thirty Cases in Brief.
  • Sources and Research Methodology.
  • Glossary.
  • About the Author.
  • Contact.
  • The Series.
  • The Online Platform...
  • Acknowledgements.
  • Analytical Index.
PRIMA DELL’ACQUISTO

Estratti / Extracts

Passaggi selezionati dal libro disponibili per la consultazione.

01 Preface Apri / Open

Every system described in the companion volume has to be believed by somebody who did not build it.

The owner who signed the policy believes it, and so does the general manager who approved the Statement of Applicability, and so, usually, does the coordinator who wrote most of it. None of them is the right person to say whether it works. The guest cannot say, because the guest sees only the counter and the confirmation email. The corporate client cannot say, because it sees only the answers on its questionnaire. Somebody has to go and look, with a method, with independence, and with the discipline to write down what was found rather than what was expected. In this standard there are two such people, and this book is about both.

The first is the internal auditor. The standard requires the hotel to audit its own management system at planned intervals, and to do so objectively, which in most hotels means a quality manager, a colleague from another property of the same group, an auditor from the owner’s company or an outside professional engaged for a few days a year. The second is the certification auditor, sent by a body that has itself been assessed by an accreditation body, which has in turn been evaluated by its peers under an international arrangement. The first works for the hotel and can be asked to look again. The second works, in a sense, for everybody else.

That is why this volume is the lens. The first volume was the helm: what ownership decides and what management does with those decisions. This one takes the same thirty questions from the other side, and asks how anybody would know. The third chapter belongs to the internal auditor: how to audit information that cannot be seen, when to audit a hotel whose risks move through the week, what a checklist should look like at a front desk, how to audit the law without pretending to be a lawyer, what to do with near misses, how to interview a housekeeper at her trolley, how to audit a supplier, where old data hides, how to find a cause that is not a person, how to test a backup, how to audit the rights behind accounts, how to read a penetration test, how to write for owners, how to follow up without checking one’s own work, and what the audit owes the management review. The fourth chapter belongs to the certifier: the chain that gives a certificate its value, the choice of certification body, the two stages of the first audit, the auditor and the hotel’s side of the table, evidence in a business built on discretion, findings, the certificate itself, surveillance, what a certified hotel may say, integration with other standards, the certificate before lenders and insurers, multi-site certification, change during the cycle and, finally, recertification.

Eight appendices follow the Afterword. Like those of the first volume, they are working material: a map of audit coverage across a cycle, the certification rules set out as questions a hotel can ask, an owner’s explanation of audit time and sampling, interview questions by department, a catalogue of evidence that does not expose guests, the certification cycle month by month, a set of findings written well and badly, and the thirty cases in brief.

Where auditing came from

Hotels have always been audited. The night audit is older than any management system: a person who was not at the desk during the day, reading what the desk did and checking that the figures agree. The owner’s visit, the brand’s inspection, the mystery guest, the health inspector with a thermometer and the fire officer with a checklist all belong to the same family. What the management system standards added was a particular kind of audit, one that examines not a result but the system that produces results, and asks whether it would go on producing them when nobody was watching.

Certification against management system standards began with quality in the late nineteen-eighties and spread, over three decades, to environment, safety, energy and information. With it grew the infrastructure that makes certification mean something to strangers: rules for the bodies that certify, rules for the bodies that accredit them, and an international arrangement through which each country’s accreditation body accepts the others’ work. In January 2026 the two international organisations that had carried that arrangement for management system certification and for laboratories and inspection bodies merged into one. None of this is visible to a guest, and very little of it is visible to most hoteliers. It is nevertheless the reason a certificate issued in Casablanca can be read by a procurement analyst in Paris.

Information security certification has its own rules on top of the general ones, because auditing information security raises questions that auditing quality does not: how much time an auditor needs for an organisation whose risks are largely invisible, what competence an auditor must have, how to audit records that the organisation cannot lawfully show. Those rules were revised in 2024, and certification bodies completed their transition to them in the spring of 2026. This book describes them by function and never quotes them, for the same reasons the first volume never quoted the standard.

Who this book is for

The quality manager who has been told that she will also audit information security, and wonders what an auditor of passports and servers needs to know that an auditor of breakfast buffets does not. The group’s internal auditor who flies in for three days and has to decide where to spend them. The coordinator who will guide the certification auditor through the hotel and wants to know what she will ask. The general manager who receives the audit report and has to decide what to do with it. The owner, the asset manager and the finance director who choose a certification body, sign the contract, read the certificate and answer the questionnaires of lenders and insurers. And the certification auditor who has spent a career in banks and is about to audit a hotel for the first time.

Three facts about auditing a hotel govern everything in this book. The first is that the information an auditor must examine is mostly invisible from a meeting room. It is on a printed list in a pantry, in a tray under the counter, on a tablet in a ranger’s vehicle, in a messaging group and in a supplier’s data centre. An audit that stays where the documents are will find the documents in order and the information somewhere else.

The second is that a hotel’s exposure moves through the day, the week and the year. The desk at four in the afternoon, the back office at two in the morning, the fair week, the season’s opening and the weekend of three weddings are different organisations from the hotel at eleven on a Tuesday in November. An audit programme that always visits at the same quiet hour measures the hotel when it is least like itself.

The third is that most of what the auditor must judge is held by other people. The property system is hosted, the backups are kept by the provider, the transfer company has the arrival list, the lock supplier can connect at night. An auditor who audits only what the hotel runs itself audits the smallest part of its exposure, and one who knows how to read a supplier’s assurance audits the rest.

To these the certification rules add a fourth, and it is what separates this volume from the first. Certification is a relationship with obligations on both sides. The certifier must be impartial, competent, confidential and must not advise; the hotel must be honest, must give access, must tell the certifier about significant change and must not claim more than its certificate says. Most of the fourth chapter is about what each side owes the other, and about what happens when either forgets.

What this book is, and what it is not

It is a practitioner’s guide to auditing an information security management system in a hotel, from the inside and from the outside. It is not a manual of audit technique in general, which is well covered by the international guidance on auditing management systems, and it is not a guide to technical security testing, which is a different profession. It will not tell a reader whether a particular hotel should be certified, and it does not recommend certification bodies, consultants or tools.

Where the book describes what the rules for certification bodies require, it describes the requirement as a requirement, in its own words. Where it describes a method, it says so. The distinction matters even more in this volume than in the first, because a good deal of what hotels believe about certification is in fact what one particular certification body happens to do, or what a consultant has said, and a hotel that knows which is which can ask better questions and decline worse offers.

As in the first volume, every case is composite: thirty properties in thirty cities, none of them a real hotel, each assembled from patterns that recur. Every financial figure is modelled and declared as such. No certification body, accreditation body, supplier, consultancy, brand or person is named in the body of the book, and the international accreditation arrangement is described by what it does rather than by its name, which appears only in the Sources.

The fixed elements of a subchapter

Every subchapter carries the same elements as those of the first volume. A Guiding Question opens it and can be tried on your own hotel today. What the Standard Says sets out the applicable requirements in the book’s own words: in the third chapter mostly those of the standard itself on internal audit and on the controls the auditor examines, in the fourth chapter mostly those of the rules that bind certification bodies, which the hotel does not have to meet but needs to understand. The Verification Pact runs five common beliefs against what actually holds.

02 3.9  Root Cause, and the Answer That Is Not the Employee Apri / Open

GUIDING QUESTION  Take the last three information security incidents your hotel recorded and read the cause written against each. If any of them says human error, staff error or failure to follow procedure, ask what made the error possible, and whether that has changed. If it has not, the incident is waiting to happen again with a different name beside it.

Opening

The second email went to the same wrong agency as the first, four months later, from a different desk.

The hotel is a hundred and ninety rooms in a Renaissance palazzo in Florence, owned by a Tuscan family company and run by a general manager, Lorenzo Bartolini. A large part of its business came through tour operators and travel agencies, and every day the reservations team sent dozens of rooming lists back and forth by email: who was arriving with which group, in which room, with which requests. In the spring a reservations agent sent the rooming list for an American university group to the wrong travel agency. The hotel worked with two agencies whose names differed by one word, and the email program had completed the address as she typed. The list contained forty-two names, passport numbers, dates of birth, dietary requirements and, for three students, notes about medical conditions and accessibility needs that their university had sent so the hotel could prepare.

The wrong agency, which was honest, told the hotel the same day and deleted the email. The hotel recorded an incident, assessed it with its data protection officer, notified the authority because of the health information, and wrote to the students. The cause recorded in the incident report was human error. The agent received a written warning and repeated the annual awareness course. The incident was closed.

In the summer, a colleague of hers on the late shift sent a rooming list for a German choir to the same wrong agency, in exactly the same way. This time the agency did not notice for a week. The company’s internal auditor, Chiara Ferri, was asked to look at both incidents together. She began by asking not who had sent the emails, but why it was possible for anybody at that desk to send them. By the end of her first afternoon she had a list of reasons, and none of them was the name of an employee.

She spent that afternoon at the reservations desk rather than in an office. She watched an agent prepare three rooming lists, timed them, and noted what the screen offered at each step. The report came out of the property system with every field it held. The email program offered five addresses after two letters, and the two agencies sat next to each other in the list, their names in small type and their domains nearly identical. The phone rang twice while the agent was typing. Nobody at the desk had ever been asked whether the task could be made safer; the question had never been put, because the first incident had been closed with a name.

The Problem

The first failure is where the investigation stopped. It asked who had sent the email, found the answer, and wrote it down as the cause. Who did something is a fact about the incident; it is not a cause. The question that finds a cause is why the thing that happened was possible, and in the first investigation nobody asked it.

The second failure is that a disciplinary action was treated as a corrective action. A written warning may or may not have been fair to the agent; that is a matter for the hotel’s disciplinary process. It changed nothing about the desk: the same program, the same address book, the same lists, the same pressure. A corrective action must remove a cause, and a warning to one person removes none of the causes that allowed a second person to make the same mistake.

The third failure is the training. Repeating the awareness course was offered as proof that the problem had been addressed. The agent already knew that emails should go to the right address. She had not failed to know something; she had been let down by a tool that guessed and an address book that made the guess wrong. Training cannot correct a cause that lies in the tool.

The fourth failure is that the mechanism was never examined. The email program completed addresses from the first letters typed. Two agencies with almost identical names sat side by side in the address book. The rooming lists were sent forty or fifty times a day, often under pressure at the end of a shift. Any one of these made the error likely; together they made it certain that it would happen again, to somebody.

The fifth failure is the content of the list. The rooming list was produced by a standard report from the property system that included every field held for each guest: passport numbers, dates of birth, notes. The agency needed names and room types. Most of what made the incident serious, and made it notifiable, was data that did not need to be in the email at all.

The sixth failure is that nobody looked for the same cause elsewhere. The sales team sent event lists by email in the same way, the events team sent delegate lists to suppliers the same way, and the spa sent booking confirmations with treatment notes. The standard asks the organisation, when it deals with a nonconformity, to determine whether similar ones exist or could occur. The first investigation looked at one desk and one person.

The seventh failure is what the warning taught the rest of the team. After the first incident, staff understood that reporting a mistake led to a letter in one’s file. Chiara found, when she asked, that two other misdirected emails had happened in the weeks between the two incidents and had been quietly recalled or apologised for without anybody being told. A root cause investigation that ends in blame reduces the number of mistakes that are reported, not the number that are made.

Underneath all seven sits a single structural fact. In a hotel, the same tasks are performed hundreds of times a week by different people under similar pressure, with the same tools and the same data. Where one of them makes an error, the conditions that made it possible are shared by all the others. An investigation that stops at the person who made the error leaves those conditions in place, and waits for the next person.

The Principle

Treat human error as the point where the investigation begins, not where it ends. When an incident appears to be caused by a person, the internal auditor asks why the error was possible, why it was likely, why it was not caught, and why its consequences were as serious as they were, and keeps asking until the answers describe things the hotel can change: a tool, a template, a process, a workload, a rule, a control. The auditor then asks where else the same conditions exist, and whether the hotel’s response to the incident has made people more or less willing to report the next one.

Four questions carry most of the weight. Why was the error possible: what in the tool, the process or the environment allowed it? Why was it likely: what made it happen here and not elsewhere, now and not before? Why was it not caught: what check could have stopped it before it left the hotel? Why was it serious: what made the consequences larger than they needed to be? Each question points at a different kind of change, and a good investigation produces at least one change for each.

The standard supports this reading. When a nonconformity occurs, it asks the organisation to review it, determine its causes and determine whether similar nonconformities exist or could occur, and to take action appropriate to the effects. It asks that knowledge gained from incidents be used to strengthen controls. Its reference controls ask that a disciplinary process be formalised and communicated, which is a matter of fairness to staff, not a substitute for removing causes, and that staff be encouraged to report events. An investigation that stops at the person meets none of these requirements.

There is a point about fairness and blame. Some errors are careless and some are deliberate, and a hotel is entitled to deal with those through its disciplinary process. But the question of whether a person should be disciplined is separate from the question of why the error was possible, and the two should be answered separately, by different people if necessary. When they are merged, the investigation becomes a trial, the person investigated becomes a defendant, and the evidence that would have revealed the cause is withheld by everybody who fears being next.

It is worth saying why investigations stop at the person so often, because the auditor meets the same pull. A name is quick, it closes the file, and it places the fault somewhere other than in the decisions of the people who run the investigation. The tool was chosen by management, the report was configured by the IT provider, the workload was set by the budget. An answer that reaches the process implicates those choices, and the people who made them are usually the ones reading the report. The internal auditor’s independence exists precisely so that the answer can go where the evidence leads, including upwards.

What the Standard Says

This subchapter rests on the clause on nonconformity and corrective action, the reference controls on incident response, learning from incidents, the disciplinary process, event reporting and information transfer, and the clause on internal audit. What follows is what they oblige, in this book’s own words.

  • When a nonconformity occurs, the organisation must react, control and correct it, deal with the consequences, and evaluate the need to eliminate its causes by reviewing it, determining its causes and determining whether similar nonconformities exist or could occur.
  • Corrective actions must be appropriate to the effects of the nonconformities encountered, and their effectiveness must be reviewed.
  • Information security incidents must be responded to in accordance with documented procedures.   …
L’AUTORE
Francesco Dore

Francesco Dore

Autore e ricercatore indipendente

Francesco Dore è autore e ricercatore indipendente. Il suo lavoro nasce dall’incontro tra esperienza professionale, studio dei sistemi di gestione, hotellerie e ricerca applicata. Nei suoi libri utilizza un approccio basato sull’analisi dei processi, sul confronto delle fonti e sull’osservazione delle conseguenze reali delle decisioni organizzative.

Conosci l’autore →