What is ISO27001?

Introduction to ISO ISO27001 what it is and why it’s important

ISO 27001:2022 is an internationally recognised standard designed to provide a framework for developing and managing an Information Security Management System (ISMS). It was developed by the International Organisation for Standardisation (ISO) with the primary goal of helping businesses like yours to implement appropriate security controls, and thereby protect you and your reputation. work-related injuries, ill-health, and fatalities. 

You may have heard a lot about ISO 27001 but it’s often difficult to know where to start if you’re completely new to the topic, or if you’re just looking to improve your security as a business owner.

It’s important to remember that the implementation of ISO 27001 principles not only demonstrates an organisation’s commitment to security but also helps protect your reputation in the event that there is a security breach. 

In this article, we will explore the core principles of ISO 27001 and the key clauses essential for effective compliance and improved security.

ISO27001 being discussed in a Board room setting

 What is ISO 27001 all about?

ISO 27001 is designed to help you protect what it important to you. That can include personal, commercial or  sensitive (aka ‘special category’) data—whether it’s employee information, client details, financial data, or intellectual property— ISO 27001 helps you to establish a robust ISMS that helps to protect it.

You should think of it as a framework that ensures your organisation takes a systematic, risk-based approach to safeguarding information. But there are many other reasons for implementing ISO 27001.

Yes of course it’s about the protection of information, but in reality it’s about helping to protect your reputation.  We will cover this in other articles, but there are many benefits to implementing ISO27001 and it’s not just about improving security, so let’s look at some of these benefits of implementing this framework here.

The benefits of ISO 27001

Protects Sensitive Data:

The framework ensures your organisation safeguards critical information from threats like breaches, theft, or unauthorised access. This is typically why people start on the journey towards certification, and certainly is a great place to start.

Improves Risk Management:

ISO 27001 uses a risk-based approach to identify and mitigate vulnerabilities before they lead to security incidents. By proactively identifying and mitigating risks, you can significantly reduce the likelihood of a data breach or cyber incident.. This leads to improved trust by your internal and external stakeholders, like employees and customers.

Builds Trust with customers, clients and partners

Certification demonstrates to clients, partners, customers, investors and employees that you take data security seriously. This builds confidence and trust, and can enhance your reputation which could provide a competitive advantage in industries where security is a key concern. A good question to ask is “Are our competitors certified? If they are, then why would people trust us, and not them?!”

Compliance and Regulatory Alignment

The laws around Data Protection and security are only getting more and more complicated. But one thing they all (mostly!) agree on is that organisations need to be able to demonstrate that security is in place.  ISO 27001 helps you meet legal and regulatory requirements, in a practical and efficient way.  Regulations like GDPR,  CCPA, FTC Safeguards Rules and others will impose fines and penalties on you if you have a breach and can’t demonstrate that security is implemented.  

ISO 27001 helps organisations stay compliant with legal and regulatory requirements in a way that is efficient because it meets many requirements, without burdening you with administrative and technical costs.

Enhanced Employee Morale and Engagement

A secure work environment fosters trust and confidence among employees, leading to higher morale and greater engagement. Teams are more likely to participate in security initiatives and contribute to a positive security culture if they understand why it’s important..

Promotes Continuous Improvement

The standard requires regular reviews and updates to ensure the ISMS adapts to new threats, technologies, and business changes. This requires you to continually monitor, review and assess the effectiveness of the security controls, and also requires you to assess your business too.

This presents an opportunity for your business to address weaknesses (and vulnerabilities) in your processes that will help improve your business in a more general way. 

So, ISO 27001 not only improves security. If done well, it can improve your overall business by reducing downtime, increasing productivity, saving you money AND making you a much more trusted partner for your business.

It helps you find the weak link in your organisation and strengthen it, so it doesn’t break when you need it most.

What’s not to love?!  .

Chain showing security as the link

Key concepts to be aware of ISO 27001

Hopefully you can see by now why we’re such big fans of the ISO 27001 standard.  It can help you business in so many ways, and not only in security.

Now that we’ve discussed the benefits, let’s take a closer look at the standard itself.  Don’t worry, we’ll keep this at a relatively high level, but you came here to understand the standard, and there are some fundamental aspects you need to be aware of before we dive into some of the core areas of the standard.

The Clauses

To begin with, it’s worth noting that ISO 27001 is made up of two parts; The ISMS, which has a series of clauses, and then the ISO 27001 Annex A controls.  You’ll hear a lot about both parts, but it is the ISMS and the clauses which are the main part of the standard that we need to consider first..  

A simple way to think of the Clauses, is that they are ‘chapters’ in a book which explains how information security shall be implemented in your organisation.   When you are audited by your Certification Body (CB), it is against these clauses that you are being audited.  We’ll talk about the controls shortly, but it’s your ability to demonstrate that you have built an ISMS that conforms to the requirements of these clauses.

What do these clauses cover? Glad you asked. Let’s take a close look at each ‘chapter’ in the ISMS.

Clause 4: Context of the Organisation

This clause focuses on the strategic understanding of internal and external factors that can affect the ISMS. You must identify and analyse the context in which they operate to develop a management system that aligns with their business. This includes understanding legal and regulatory requirements, internal and external issues, economic conditions, industry-specific risks, and stakeholder expectations.

Additionally, you are required to identify interested parties (e.g., employees, contractors, suppliers, regulatory authorities) and understand their needs and expectations concerning occupational health and safety. By aligning the ISMS with these needs, you can better define your scope and objectives.

Clause 5: Leadership

Clause 5 reiterates the importance of leadership commitment and worker involvement in establishing an effective ISMS. Top management must take accountability for the Information security policy, set clear objectives, and allocate resources to achieve them. This clause also emphasises the need to establish channels for effective communication and interaction with key stakeholders.

Leadership is expected to lead by example and foster a culture of security. This involves defining roles and responsibilities, empowering employees to report risks, issues and incidents, and actively engaging them in decision-making processes related to information security.

Clause 6: Planning

Effective planning is the backbone of a successful ISMS. Under Clause 6, You’re required to identify risks and opportunities, establish clear safety objectives, and develop action plans to achieve them. Planning involves conducting risk assessments, and defining controls (usually using Annex A controls).

Legal compliance is a significant aspect of this clause, as you must identify applicable legal requirements and ensure that your ISMS  is designed to meet these obligations. Additionally, you must establish a risk management process to address both current and potential risks effectively (as described above).

Clause 7: Support

For an ISMS to function effectively, you must provide adequate support in the form of resources, training, awareness, and communication. Clause 7 outlines requirements related to competence, awareness, documented information, and internal and external communication.

Ensuring that employees are competent and aware of their roles is critical to maintaining security within your organisation.. Don’t forget that you and your organisation are responsible for providing the necessary training and resources to enable employees to perform their duties in a secure manner. This clause also requires organisations to maintain documented information to demonstrate compliance and provide evidence of security-related activities.

Clause 8: Operation

The operation clause focuses on implementing and maintaining control measures to address identified risks. You must establish operational controls to ensure that processes are consistently carried out in a secure manner. This includes developing procedures for managing high-risk activities, incident response, configuration management, Business Continuity and outsourcing or contractor-related security issues.

Clause 8 also emphasises the importance of change management, ensuring that any changes in processes, equipment, or personnel are assessed for potential safety impacts before implementation. Additionally, you are required to establish procedures for responding to potential emergency situations and conducting drills to ensure readiness.

Clause 9: Performance Evaluation

Regular performance evaluation is essential for determining the effectiveness of an ISMS. Clause 9 requires you to monitor, measure, analyse, and evaluate your safety performance. This includes conducting internal audits, management reviews, and safety performance assessments.

Audits play a vital role in identifying non-conformities and opportunities for improvement. The results of performance evaluations provide valuable insights that guide decision-making and help organisations refine your ISMS.

Clause 10: Improvement

The final clause emphasises continuous improvement by taking corrective actions based on audit findings, incidents, and performance evaluations. Clause 10 requires you to identify non-conformities and implement corrective measures to prevent their recurrence.

Continuous improvement is not limited to addressing non-conformities; it also involves proactively identifying areas for enhancement and taking actions to achieve higher safety standards. By fostering a culture of continuous improvement, organisations can maintain an effective and evolving ISMS.

And that’s the Clauses covered.

Clearly there’s a lot in there, and we would recommend that you read the standard carefully so you understand the requirements before you venture to far into the Annex A control.

With that said, let’s meet the Annex A controls and see what they cover and what’s needed.

ISO 27001 handshake

Annex A Controls

We mentioned earlier that ISO 27001 is made up of two parts, and this second part is known as the ‘Annex A Controls’.  You will hear a LOT about these controls and we have covered each of them in other articles. But as we’re just getting started I don’t want to throw too much at you, so here are the headlines you need to know;

There are 93 Controls across 4 separate domains for you to consider, and decide if they are applicable to you and your organisation.  These control domains are;

  • Organisational Controls
  • People Controls
  • Physical Controls
  • Technical Controls

As you read through each of the controls you’ll decide if that control is something that is applicable to your organisation, or not.  If it is, you’ll need to explain why, and if it’s not, then you will also need to explain why it is not applicable.

For example, one of the technical controls (8.25)  states “Rules for the secure development of software and systems shall be established and applied.” 

However, if you are an organisation that doesn’t conduct any software development then you might decide that this control isn’t applicable and will simply state ‘Not applicable as we don’t perform any development’.

One final point about the Annex A control;  You’ll hear some say that you do not need to use the Annex A controls, and strictly speaking they are correct.  You can use any other set of security controls you prefer to use (there are a lot to choose from).  You can also add additional controls to your set of controls (e.g. from other ISO standards, like ISO 27701, ISO 22301 etc).

But a word of caution; If you are just starting out on the journey to ISO 27001 certification, then I would urge you to stick with the standard set of controls within ISO 27001.  The external CB will need a good understanding of why you elected to use a different set of controls, so you’ll be having some robust conversations about this.  Also…

ISO 27001 have done a great job of putting together 93 very sensible controls for you to consider.  No, you don’t HAVE to use them – but my question to you would be – why re-invent the wheel?

Rolling the dice with ISO 27001

Risk Based Management

We can’t finish a discussion about ISO 27001 without stating one simple fact; ISO 27001 is a Risk based management system.  Now before this has you running to the hills, I want you to know this is a big help to you!  It may not seem like it, but what this means is that YOU get to decide what is and is not a risk to you and your organisation.

This is such an important topic and we will cover it in more detail in other articles, but I want you to feel confident in the knowledge that the controls, including policies and procedures have to be appropriate for you – based on the risks that YOU face.

There’s no point, for example, having a business continuity plan that talks about ‘bush fires’, if that’s not something that is relevant to you.  There’s no point talking about ‘secure development lifecycle’ when you don’t do any development.

Your task is to understand the threats and vulnerabilities, your organization faces so you can prioritize your efforts and focus on what’s needed.

All business activities come with inherent risks, and the aim is to identify, assess, and mitigate these risks before they result in accidents or health issues. Risk-based thinking involves evaluating potential hazards, assessing the likelihood of occurrence, and implementing controls to eliminate or reduce these risks to acceptable levels.

This principle moves organisations away from traditional reactive approaches, where actions are taken only after incidents occur. By focusing on risk prevention, organisations can protect their workforce and avoid threats, and manage the likelihood or impact should a risk crystallise and become an actual event. 

ISO 27005 is often used as a tool to help organisations improve their approach to risk management, and we would certainly recommend taking a look at this importance guidance for further advice

ISO 27001 questions and answers

FAQ

How long does it take to achieve ISO 27001 certification?

The time required to achieve certification depends on factors such as the size and complexity of your organisation, the scope of the ISMS, and the maturity of existing security practices. For smaller organisations, it may take 3–6 months, while larger or more complex organizations may require 12 months or more. The process involves conducting a risk assessment, implementing controls, and undergoing audits by an accredited certification body.

What is the certification process for ISO 27001?

The certification process typically involves three stages:

  • Stage 1 – Initial Audit: A certification body reviews your ISMS documentation to ensure it aligns with ISO 27001 requirements.

  • Stage 2 – Certification Audit: The auditors assess the implementation of your ISMS, verifying that the controls and processes are effectively mitigating risks.

  • Surveillance Audits: After certification, periodic audits (usually annually) ensure that your ISMS continues to meet the standard’s requirements.

What are the costs associated with ISO 27001 certification?

The costs of achieving ISO 27001 certification vary depending on factors like the size of your organisation, the scope of certification, existing systems in place, and consultancy fees. Costs typically include staff training, implementing controls, auditor fees, and ongoing maintenance expenses. However, the benefits of improved security and client trust often outweigh these costs.

Conclusion

ISO 27001 doesn’t have to be complicated. In fact if you approach it in a systematic and way you’ll quickly learn that the standard makes perfect sense and it a real game-changer when it comes to implementing good security.

It allows you to focus your attention on what’s important, and cut out all of the ‘noise’ that’s going on around you.

If you’re truly struggling with the implementation then you can contact us and we can help get you on the right path towards certification and achieveing all the things you want to achieve and getting all the benefits from the standard.