ISO 27001 UK executive guide header image

ISO 27001 – UK executive guide

What is ISO 27001?

ISO 27001 is the international standard for Information Security. It provides a framework for an information security management system. This enables organisations to manage the security of assets like finance information, intellectual property, employee details or information entrusted by third parties.

Who is ISO 27001 for?

ISO 27001 is a great tool for organisations of any size and in any sector to use to keep their information assets more secure. It allows the business to demonstrate that it complies with current international best practice, and that it is effectively securing information assets and managing the risks around them. It also ensures that the organisation constantly improves its systems and processes to fit evolving needs.

Why would I want it?

  • Use as a tool to manage GDPR compliance
  • Prove you have a system in place to continually review and improve your information security. This improves credibility with customers, business partners and staff
  • Bid for contracts with larger organisations who require the certification
  • Minimise the evidence required for larger organisation to complete their due diligence
  • Identify your information assets and their value, so you can make informed decisions to mitigate risks and ensure efficient spending

What does it involve?

There are several steps involved in achieving ISO 27001:

Firstly, it’s important to have a solid understanding of ISO 27001. This includes what it is, and the importance of managing your assets, risks and incidents. At this stage, it is important to determine your scope and understand the Plan, Do, Check, Act approach (which you may be familiar with through HSE).

  • The next step covers the importance of leadership and identifying your Information Security Management System (ISMS) team, allocation of resources, competence, and communication.
  • Then we can move on to the planning stage, creating objectives and deciding how we’ll achieve them
  • The planning stage also includes identifying information assets and building an asset register so that you can move on to identifying the risks to these assets.
  • Risk assessment is also part of the planning stage, including risk methodology, risk assessments and building the risk register
  • The final part of the planning involves determining risk treatment to mitigate the risks to an acceptable level.
  • At this stage we also create the Statement of Applicability. This takes all the controls in Annexe A of ISO 27001 and determines whether they are applicable
  • Once you understand what you are protecting and the controls you have identified, you can implement the plans to mitigate risks that your information assets may be exposed to.
  • Performance Evaluation and improvement helps us to check that what we have put in place is working and then feed this back into opportunity for improvement. This will include a full internal audit, and feedback into the ISMS Team.

About implementation

The implementation will involve completion of relevant policies, procedures and forms and the ISMS manual to communicate how to maintain the Information Security Management System. We normally phase these within the levels so that this is not simply a document completion exercise, but something that fulfils the need at that particular stage.

Once implementation is complete then you are ready for a stage one audit to determine that you have an ISMS in place.

This is followed by a stage two audit which then checks to see if the ISMS is working.

Once the accreditation body is satisfied that you have met the standard, they will issue you with your certification.

The most important goal for us is to share knowledge and ensure that the organisation implementing ISO 27001 is competent and confident to maintain this system as part of their business as usual.

How long does it take?

We have managed to implement ISO 27001 within a 12 week process for some clients. However generally an implementation takes around 3-6 months (sometimes longer depending on resource availability and scope of the organisation)

How much does it cost?

We tailor our ISO 27001 consultancy service to your individual needs and circumstances. So please get in touch and we’ll provide you with a quote based on your situation and requirements.

Alternatively, we’ve pioneered the  Securious ISO 27001 Academy. We work with businesses in a series of online workshops, for just £2,895 +VAT which includes all the necessary templates.

What should I do next?

If you need any help, feel free to contact the team at Securious, the South West’s leading cyber security company. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.

If you have any questions, a member of the team would be more than happy to speak with you – just fill in the contact form below, or get in touch with them on 01392 241110, or info@securious.co.uk