EXPERTISE · ISO/IEC 27001

Treat information security as a managed system, not a checklist.

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It provides a management-system structure for governing information security risks, controls, objectives and evidence across the organization.

DEFINITION

What does this mean in an enterprise context?

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It provides a management-system structure for governing information security risks, Annex A controls, objectives, processes and the documented evidence needed to demonstrate that controls operate as intended.

CONTROL DIMENSIONS

Four lenses for executive review.

Context

Define ISMS scope, boundaries, interested parties and legal, regulatory or contractual security obligations.

Leadership

Establish information security policy, accountability, roles and top-management commitment.

Risk & Treatment

Assess information security risks and select proportionate Annex A controls through a documented treatment plan.

Evidence & Improvement

Operate controls, monitor performance, run internal audits and management review, and continually improve the ISMS.

QUESTIONS TO ASK

Useful questions for leadership, risk and technology teams.

What is the scope of the ISMS?

The scope should be defined by clear organizational boundaries, the assets and processes it covers, and how it interfaces with outsourced or third-party services — a vague scope is one of the most common audit findings.

How are information security risks assessed and treated?

Risks should be identified against a documented methodology, assigned an accountable owner, and treated through a plan that maps directly to the controls named in the Statement of Applicability.

How is the Statement of Applicability justified?

Every Annex A control decision — included or excluded — needs an explicit, risk-based justification rather than a blanket adoption or exclusion.

How do internal audit and management review drive improvement?

Audits should test whether controls operate as documented and feed nonconformities into corrective action, with management review resetting objectives based on results.

RESEARCH

Independent analysis on ISO/IEC 27001 information security management systems.

The research library is published separately under /research/ using WordPress.

Explore research →

INDEPENDENT ADVISORY

Complex technology. Clearer risk decisions.

For AI strategy, governance, Agentic AI, security, assurance or cyber-risk requirements, describe the decision you are facing and the context around it.

Discuss an Advisory Requirement ↗