What is ISO 27001?

ISO 27001 is an international standard developed by ISO, which defines the requirements for an Information Security Management System. You can purchase the ISO 27001 document online in hard copy or downloadable format. ISO 27001 Certification is optional but brings additional benefits.

Information Security Management System

An Information Security Management System (ISMS) provides the framework for governing information security within your organisation.  

Management Systems lay out a set of processes intended to drive continual improvement with in the organisation.

One of the most recognisable structures if Denning’s Plan – Do – Check – Act improvement cycle, which can be used as the basis of your ISMS.

Annex SL Framework

The ISO has worked to align the various management system standards to a common clause structure, making it easier and more efficient to integrate ISO 27001 with other standards.

Annex A Controls

Annex A is a unique feature of ISO 27001:2022 that other standards do not have.  

There are 93 Controls and Control Objectives in Annex A of the standard to treat the information security risks you have identified.  

The reasons of included and excluding each of the 93 controls needs to be documented.

ISO 27001 Certification

Although it is not mandatory, most organisations proceed to ISO 27001 Certification, as this provides impartial assurance of your ISMS.

ISO 27001 Certification also brings other benefits including certification badges and logos, to demonstrate your commitment to Information Security.

The ISO 27001 Certification Process is over two stages, and certificates last for three years.  Read more about the ISO 27001 Certification Process.

ISO 27001 for Tendering

Many organisations also find that implementing the requirements of ISO 27001 and achieving Certification make responding to tenders much easier.

Tender documents can often include questions related to the Annex A controls of ISO 27001.

ISO 27001 is not as Hard as it Sounds

There are many Benefits of ISO 27001 and as a risk based standard it can be adapted to suit can size or type of organisation.  Contact Assent to find out how we can help you, alternatively visit out Cyber Security Portal.

Robert Clements
Robert Clements
Articles: 301