In the following series of articles, we will be writing to you about the key aspects of ISO 27001 and the changes it most commonly brings about in a company’s operations.
This series is aimed at those who, as a company, have already toyed with the idea of ISO 27001 and would like to understand what it means in practice (not just from an audit perspective, but also in terms of day-to-day operations). It will also be useful even if you’re not planning to seek certification: the approach and methodology often help in their own right to bring more structure to security and IT operations decisions.
What is ISO 27001?
ISO/IEC 27001:2022 is a set of requirements that describes how to establish and operate an information security management system (ISMS) within an organisation. The standard consists of two main parts: the mandatory requirements and a set of controls from which the organisation selects those appropriate to its risks.
What is it used for (from a business perspective)?
It provides a framework to ensure that security is not based on habits and ad hoc decisions, but is instead a consistent system: it should have a scope and risk management, as well as objectives, operational processes and evidence that it is actually in place. For this reason, ISO 27001 is typically not „just about IT”, but also involves management decision-making and organisational operations.
What does the process look like?
The structure of the introduction is in line with the standard: defining the context and scope, clarifying management’s role and responsibilities, planning (risks and objectives), support (competence, awareness, documented information), operation (application of the selected controls), performance evaluation (monitoring, internal audit, management review), followed by continuous improvement (handling non-conformities, corrective actions). The selection of controls and the justification thereof are based on the set of controls set out in Annex A of the standard, which must be managed in a documented manner.
Where can the standard be purchased in Hungary?
In Hungary, to obtain the standards, it is advisable to contact the Hungarian Standards Institution (MSZT) and search for „MSZ EN ISO/IEC 27001” (there may be several versions depending on the edition and language).
Important: the text of the standard is protected by copyright; therefore, for internal company use, it is advisable to purchase the appropriate licence and not to distribute it.
What types of audits are there, and who is authorised to carry them out?
- Internal audit: an organisation may carry this out using its own resources; the key is competence and ensuring that the auditor is, as far as possible, independent of the activity being audited (i.e. they should not be auditing their own work). In many companies, this works well by having an in-house „coordinator”, with an external auditor occasionally helping to review the system objectively. At Manawize, several of our team members hold ISO 27001 internal auditor certification and can assist, both as external partners, with preparation and with the audit itself.
- Certification audit: if the aim is to obtain an official ISO 27001 certificate, this is carried out by an independent certification body, which then issues the certificate (the consultant assisting with the preparation does not replace this).
- Customer/supplier audit: it sometimes happens that a customer or partner requests an audit (or has one carried out); this may follow the ISO framework, but it is not the same as certification.
In the next section, we’ll use specific examples to show you what operational changes you can generally expect if you’re planning to implement ISO 27001 in your company.
If you’re interested in this topic and would like to read more practical, easy-to-understand articles on IT operations and solutions that support business operations, please follow our blog and social media channels.