ISO 27001

What is ISO 27001 and what does it mean for your organisation?

Understand what ISO 27001 requires and how to organise information security systematically.

ISO 27001 explained: what an ISMS is, who the standard is relevant to and the first steps your organisation can take.

What exactly does ISO 27001 cover?

ISO 27001 is not just about technology. The standard brings policies, people, processes, suppliers and technology together in one manageable cycle. You first determine which information and processes are within scope, the risks involved and who is responsible.

You then implement controls, gather evidence and check periodically whether the approach remains appropriate. What matters most is being able to explain your choices and making information security part of normal business operations.

  • a clear scope and context
  • a risk assessment and treatment plan
  • policies, roles and controls
  • internal audits and management review
  • continual improvement following changes and incidents

Who is the standard relevant to?

Organisations of any size and in any sector can use the standard. In practice, ISO 27001 is particularly relevant when customers require demonstrable security, when large amounts of sensitive information are processed or when digital services are important to business continuity.

A certificate can provide confidence, but do not start with the certificate. Start by asking which risks you want to manage and which ongoing arrangements you need.

How do you start without making it too complex?

Choose a realistic scope, appoint an owner and make existing arrangements visible. Many organisations already have policies, access management, backups and supplier agreements. The first improvements often come from consistency, ownership and evidence.

Certification or simply working to the standard?

You can use ISO 27001 without certification. Certification means that an independent certification body assesses whether the management system meets the standard and works in practice.

Always ask why certification is wanted. Sometimes a demonstrably effective ISMS is sufficient; sometimes a customer or tender explicitly requires an accredited certificate.

Frequently asked questions

Is ISO 27001 mandatory?+

Usually not directly. Customers, contracts or sector-specific rules may require the standard or comparable controls.

Is ISO 27001 only for IT companies?+

No. Any organisation that manages information can use the standard.

What is an ISMS?+

An ISMS is the integrated management system you use to manage information security risks and make improvements.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

ISO 27001ISO 27001 certification: the complete roadmapRead article →ISO 27001An ISO 27001 checklist for organisations getting startedRead article →ISO 27001How much does ISO 27001 certification cost?Read article →

This is general guidance and does not replace a legal assessment or the official standard.