ISO 27001 is the most widely recognised international standard for information security management, and it is frequently misunderstood by the organisations pursuing it. It does not certify that your systems are secure. It certifies that you operate an information security management system — a documented, evidence-producing process for identifying risks and doing something about them.
What an ISMS actually is
The management system is the substance of the standard. It requires you to define a scope, identify information security risks, decide how to treat them, implement controls, monitor whether they work, and improve based on what you find.
That cycle must be genuine and repeatable, because certification is evidence-based. An auditor is not primarily assessing whether your firewall configuration is elegant — they are assessing whether you can demonstrate that risks were identified, decisions were taken by someone with authority, and the resulting controls are operating.
The structure of the standard
The main clauses cover the management system itself: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. These are mandatory.
Annex A provides a catalogue of controls, restructured in the 2022 revision into four themes — organisational, people, physical and technological. Annex A controls are not all mandatory. You select what is applicable based on your risk assessment, and document the reasoning in a Statement of Applicability, which is one of the documents auditors examine most closely.
Scope is the decision that matters most
Scope determines cost, effort and how useful the certificate is. Too narrow and customers will notice the certificate does not cover the service they buy. Too broad and you are implementing controls across parts of the business that carry little risk.
The scope statement appears on the certificate, so a sophisticated customer will read it. Defining it around the products and services customers actually care about, plus the infrastructure and teams supporting them, is usually the right balance.
How certification works
- Gap analysis — compare current practice against the standard to size the work honestly.
- Build the ISMS — scope, risk methodology, risk assessment, treatment plan, policies and the Statement of Applicability.
- Implement and operate — controls must run long enough to generate evidence, which is why this stage cannot be compressed indefinitely.
- Internal audit — required by the standard, and genuinely useful for finding problems before the external auditor does.
- Management review — documented leadership engagement, which auditors check specifically.
- Stage 1 audit — largely documentation, confirming the ISMS is designed appropriately.
- Stage 2 audit — the substantive audit, testing whether the system operates as described.
- Surveillance and recertification — ongoing audits across a three-year cycle, so certification is a commitment rather than an event.
What commonly goes wrong
- Buying a policy template set and stopping there. Policies nobody follows fail immediately, because auditors ask for evidence of operation.
- A risk assessment written once and never revisited. The standard expects it to be live.
- Absent leadership involvement. Management review is explicitly required, and its absence is a common non-conformity.
- No evidence trail. If access reviews happened but were never recorded, they cannot be audited.
- Treating it as a security project rather than a business one. HR, legal, procurement and facilities all sit inside a typical scope.
- Confusing certification with security. A certified organisation with a badly configured perimeter is entirely possible, which is why technical testing remains necessary alongside.
Related from TechBiz Security
Sources & further reading
- ISO/IEC 27001 — Information security management systems
- ISO — ISO/IEC 27001 standard page
- NIST SP 800-53 — Security and Privacy Controls
- CIS Critical Security Controls
0 comments
Leave a comment