ISO 27001 Information Security standard

ISO 27001 Information Security Standard - Quick Guide

This introduction to the ISO 27001 standard is intended for those that are considering developing an ISMS (Information Security Management System) based on that standard OR are looking to extend an existing management system to also meet its requirements.

It seems that every day another information security incident makes the news. As a result, organizations are increasingly implementing an ISMS to preserve the Confidentiality, Integrity and Availability of information belonging to them or under their control.

Whilst there are several models or frameworks that may be used as a basis for an ISMS, the ISO 27001:2022 standard is most widely accepted model in use. It’s published by ISO (the International Standards Organization to specify requirements for an ISMS and enable organizations to seek formal certification as an assurance to themselves, their clients, and other interested parties. Read on for a valuable introduction to ISO 27001. In many cases, that certification is a necessary contractual requirement. It can be an essential step to simply be considered for a tender.

The following is a brief summary of the requirements of the standard and the most significant changes in the new edition. The standard can be purchased online from ISO or from local standards bodies.

ISO 27001 Clause 4: Context of the organization

4.1 Understanding the organization and its context.
4.2 Understanding the needs and expectations of interested parties.
4.3 Determining the scope of the ISMS.
4.4 Information security management system.

For the purposes of an ISMS, the context of the organization are the internal and external factors that can affect the ability to achieve information security. It is only by understanding this context that you can most effectively develop your management system.

To help you get started, it’s generally a good idea to put some structure in place – such as creating categories like PEST (Political – Economic-Social-Technological) for the external factors. Categories should also be created for the internal factors – such as Culture, Resources and Performance.

You may then consider how significant those factors are, and how well placed you are to address them. For internal factors, are they a Strength or a Weakness? For external factors, are they an Opportunity or a Threat? That process of consideration is typically referred to as a SWOT analysis.

The relevant needs and expectations of interested parties need to be understood. That would include the legal and regulatory environment, and any contractual obligations. At that point, the scope and boundaries of the ISMS may be determined, and the system can be developed including all the necessary operational and support processes.

ISO 27001 Clause 5: Leadership

5.1 Leadership and commitment.
5.2 Policy.
5.3 Organizational roles, responsibilities and authorities.

For an ISMS to be successful, it needs to be inspired and led from the top. Top management must take accountability for it, express their commitment, give direction, and – critically – ensure that sufficient resources are made available.

Everyone in the organization should be aware of what its policies and objectives are, and their role and responsibilities for achieving them.

In larger organizations, top management may not be able to attend to the day-to-day administration of the system themselves. Other people may perform those roles, but they must be given leadership, support, and adequate resources.

ISO 27001 Clause 6: Planning for the ISMS

6.1 Actions to address risks and opportunities.
6.2 Information security objectives and planning to achieve them.
6.3 Planning of changes.

This clause is closely linked to clause 4. Having identified factors that affect its information security, the organization needs to develop strategies and actions to:

  • Maintain and build on its Strengths
  • Correct Weaknesses that might be barriers to meeting requirements and achieving objectives.
  • Grasp or maximise Opportunities.
  • Mitigate or manage Threats or Risks.

A risk assessment process needs to be developed and Action Plans to address the risks and opportunities identified.

There should be an SOA or ‘Statement of applicability’. This is one of the mandatory documents in an ISMS. It should list all the Annex A controls together with justifications for their inclusion or exclusion. The SOA may also list any additional controls that you choose to include.

The organization should put a programme in place to set measurable information security objectives, assign them, and monitor progress on them.

Changes to the management system should take place in a planned manner.

ISO 27001 Clause 7: Support

7.1 Resources.
7.2 Competence.
7.3 Awareness.
7.4 Communication.
7.5 Documented information.

Determine, plan, and provide the resources and support mechanisms needed for the organization to achieve its information security objectives.

People with responsibilities in the ISMS must be competent to the required level. When the required level in place, action must be taken to acquire it e.g. by training, education, recruitment or outsourcing.

People that work for the organization must be aware of its ISMS policy, how they should contribute to the system, and any consequences of them not conforming to requirements.

The organization needs to determine how it will communicate – both internally and externally – about matters relating to the ISMS.

The ISMS should be documented to the extent required for conformance to the various clauses / controls in the standard. The organization should keep the required records.

ISO Standard Gap Analysis Service

The first step in developing your management system is to conduct a Gap Analysis - a check on how existing arrangements stack up against a selected standard or framework. Qudos can provide qualified and experienced lead auditors to conduct your analysis against ISO 27001 as well as many other standards and frameworks. Once completed, we can uniquely generate a list of targeted Action plans in Qudos3 IMS Software to help you bridge the gaps identified. Contact us now for details.


ISO 27001 Clause 8: Operations

8.1 Operational planning and control.
8.2 Information security risk assessment.
8.3 Information security risk treatment.

The organization is required to plan, implement and maintain the necessary people, process and technology controls to address the information security risks that have been identified.

A risk assessment should be performed on a periodic basis. Risk treatment planning should be similarly checked regularly to ensure that it is still effective and adequately meets the needs of the organization.

Plan, implement and control the processes needed to meet information security requirements. This includes any processes that are outsourced.

ISO 27001 Clause 9: Performance evaluation

9.1 Monitoring, measurement, analysis and evaluation.
9.2 Internal audit.
9.3 Management review.

All systems need to be checked to verify that they are on track. An ISMS is no exception. Having implemented a system of controls over information security processes, organizations need to measure, monitor, and evaluate performance in meeting requirements and achieving objectives.

Performance evaluation requirements may broadly be divided into these areas:

  • Evaluate the performance of the information security system.
  • Audit its effective implementation and conformance to requirements.
  • Top management to periodically review the system.

The Management Review can be very instrumental in a management system as it also supports planning activities. Although ISO 27001 doesn’t specify as such, it typically takes place in the form of a meeting with a set agenda.

ISO 27001 Clause 10: Improvement

10.1 Continual improvement.
10.2 Nonconformity and corrective action.

The organization will need to ensure that it deals with any nonconformities; determining the cause(s) and taking action to eliminate them and or to prevent reoccurrence.

Continually improve the system to achieve objectives or increase the likelihood of achieving them. Also, seek opportunities to improve confidentiality, integrity and availability.

Annex controls

Well, that's it for a summary of the clauses of ISO 27001. However, what sets this standard apart from all the other ISO management system standards is its Annex A. This specifies 93 controls in 4 categories - each dealing with a different element of information security. They don’t all have to be included in your ISMS, but they must all be considered and if they are excluded, a valid reason should be given. That should be done in the SOA or Statement of Applicability that we mentioned above in clause 6.

Of course, your ISMS may also include controls that do not appear in Annex A, but which you otherwise consider important and include in your system.

The 4 categories in Annex A run from A5 to A8. They are summarised here for you.

Annex A5: Organizational Controls

Organisational controls focus on how your organization approaches information security, including documenting and communicating its policies, and establishing a suitable structure.

Theis is numerically the largest category with 37 controls. They include:

  • A set of documented information security policies that are communicated to, and acknowledged by the relevant people.
  • Roles and responsibilities for elements of the ISMS / Segregating duties.
  • Threat intelligence.
  • Asset management.
  • Acceptable use of information / assets.
  • Classifying and labelling of information.
  • Access control.
  • Incident management.
  • Readiness for Business Continuity.
  • Privacy and IP protection.

Annex A6: People Controls

Employees and other people are critical to any ISMS, and this Annex A category includes 8 controls that focus on their interaction with the system. It includes controls such as:

  • Background checks.
  • Employment terms and conditions.
  • NDAs (Non-Disclosure Agreements)
  • Remote Working arrangements.

This category illustrates that establishing and maintaining an ISMS is not just for the Information Technology team but needs to involve other parts of a business - such as senior management and the Human Resources (or People and Culture) team.

Annex A7: Physical Controls

Physical controls focus on the physical environment of the ISMS. There are 13 controls in this category, including:

  • Securing offices, rooms and facilities.
  • Clear desk and clear screen.
  • Storage media
  • Secure disposal or reuse of equipment.

Annex A8: Technological Controls

Technological controls are essentially about your IT infrastructure. So, they are the digital controls as opposed to the physical controls in category A7. There are a massive 34 controls in this category. They relate to topics such as:

  • End-point device security. End-point devices may be laptops, mobile phones and other devices used to input and access information.
  • Cryptography (encryption).
  • Data masking, leakage prevention, and deletion.
  • System / Software Development.

As not all organizations that implement an ISMS are responsible for software or other IT development, there are often a number of controls in this category that are not applicable and may, therefore, be excluded. That’s quite OK. You just need to state in your SOA why they are excluded.

The above guide is summarised from the much more in-depth version in Qudos ISO 27001 InfoSec Toolkit. The Toolkit is exclusively available in Qudos3 IMS Software.

Qudos3 IMS Software is the comprehensive solution for an effective and efficient management system for Information Security as well as other compliance and risk topics such as Quality, AI, OHS, and Environmental.

Contact us now for details.