
Chapter one
Understanding
ISO 27001
In this chapter we’ll cover the basics of ISO 27001 to give you an understanding of the standard, what it covers and why it is an increasingly important business benefit.
What is ISO 27001?
It may be the world’s best-known standard on information security management, but what does it do?
What is ISO 27001?
It may be the world’s best-known standard on information security management, but what does it do?
What is ISO 27001?
It may be the world’s best-known standard on information security management, but what does it do?
What is ISO 27001?
It may be the world’s best-known standard on information security management, but what does it do?
What is ISO 27001?
What’s it all about?
ISO 27001 is the only genuinely global information security management standard, so naturally, it’s one of the most widely sought-after.
It applies to every industry and sets out how to design, build and implement an Information Security Management System (ISMS) that can be independently certified for assurance purposes.
As the world’s best-known standard on information security management, ISO 27001 helps organisations secure their information assets – which is vital in today’s increasingly digital world. The standard is also regularly updated to ensure it meets the needs of the evolving information security threat landscape, with the most recent update taking place in 2022.

Internationallyrecognised
Internationally recognised best practice standard for information security management systems (ISMS)
Risk-basedapproach
Provides a risk-based approach to information security management
Completeframework
A framework to assist organisations in protecting the Confidentiality, Integrity and Availability of their most valuable assets
Continuousimprovement process
A continuous improvement process (Plan/Do/Check/Act) to ensure your ISMS remains relevant
Why is ISO 27001 so important?
It’s no longer a nice to have,it’s an expectation
The importance of good information security practices in businesses cannot be overstated in today’s digital world. ISO 27001 offers you the best possible protection for your information assets.
But it does so much more.
The IBM Data Breach Incident Report, in partnership with Ponemon, stated that the average global cost of a data breach reached USD $4.35 million in 2022, and 83% of organisations reported suffering more than one security breach in the last 12 months.
With the increasing frequency and cost of cyber threats and data breaches, organisations must prioritise protecting their sensitive information. This is where the ISO 27001 framework can offer considerable benefits in the information security armoury.
ISO 27001 is an international standard for creating and maintaining an Information Security Management System (ISMS). The framework helps organisations evaluate their information security risks and implement mitigation controls. By using the ISO 27001 standard, organisations can improve their security posture, help enhance their brand reputation and improve customer trust creating a solid foundation for business growth.
Influential customers and security-focused supply chains increasingly view ISO 27001 certification as a baseline requirement for doing business. It’s no longer a ‘nice to have; it’s an expectation.
Influential customers and security-focused supply chains increasingly view ISO 27001 certification as a baseline requirement for doing business.It’s no longer a ‘nice to have; it’s an expectation.

Beyond trust
Today trust is no longer enough.You need certainty.
70%
of businesses have received fines for data breaches in excess of £100,000 within the last 12 months
$4.8m
of businesses have received fines for data breaches in excess of £100,000 within the last 12 months
70%
of businesses have received fines for data breaches in excess of £100,000 within the last 12 months
ISO 27001 is the only genuinely global information security management standard, so naturally, it’s one of the most widely sought-after.
That’s why more and more companies are choosing to get ISO 27001 certified, to demonstrate their ability to provide information security certainty to their customers and supply chains. In fact, certifications in ISO 27001 have risen by 450% over the last ten years.
As the only truly global information security standard, ISO 27001 is widely soughtafter and applicable to all industries. It provides a framework for designing, building and implementing an Information Security Management System (ISMS) that can be independently certified for assurance purposes.
More than just cybersecurity
Empowering organisations to achieve robust risk management
ISO 27001 empowers organisations to achieve a robust risk management posture that aligns with the digitisation of modern business practices and accompanying threats
ISO 27001 is more than just a security standard, it’s a management standard that provides a framework for identifying and managing information security risks. It covers information security, physical security, cybersecurity, business improvement, business development, and data privacy.
The standard delivers a risk-based framework in two parts: Clauses and Annex A controls. Clauses 4–10 detail the scope, definitions, and requirements for implementing and maintaining an ISMS.
Annex A provides 93 objectives and controls, divided into four categories: Organisational, People, Physical and Technological. Each category has five attributes aligned to with the common terminology used in information security.
The five attributes are Control Types, Information Security Properties, Cybersecurity Properties, Operational Capabilities and Security Domains. These attributes are used to manage and mitigate risks to the organisation and its supply chain.
Technological controls

Technological controls

Technological controls

Technological controls
