
ISO 27001
ISO 27001 is the leading international standard for information security. Over 44,000 organisations all over the world use ISO 27001 to protect their data. The basic goal of the certification is to protect three aspects of information:
- CONFIDENTIALITY. Only authorised people have the right to access information
- INTEGRITY. Only authorised people can change the information
- AVAILABILITY. The information must be accessible to authorised people whenever it's needed
Don't look at ISO27001 and Cyber Essentials as somehow equivalent. They complement each other very well and don't directly overlap. ISO27001 focuses more on process controls and policy positions, with some practical assessment. Cyber Essentials is the opposite - the focus is much more on practical assessment, with some process and policy assessment.
Successful implementation of ISO 27001 requires careful planning and project management.
Unlike the checklist-style of Cyber Essentials, ISO 27001 is an interlocking framework of policies and processes. So, you'll need to create process documents and maintain mandatory records of training, internal audits, and more.
Statius Management Services Ltd is a management consultancy company that we work closely with, and whose aim is to implement ISO management systems along side our technical deployments, that improve business efficiency and minimise disruption.
Obtaining ISO 27001 is about systematically and rigorously testing your information security processes is against the 100+ controls detailed in Annex A of the standard.