Enquire Us

How to Implement ISO 27001

Implementing ISO/IEC 27001 means building an information security management system that meets the requirements of clauses 4 to 10 and applying the Annex A controls that your risk assessment says apply. This page sets out the sequence, in the order the work actually has to be done.

What is being implemented

ISO/IEC 27001 is the international standard for an information security management system, published jointly by the International Organization for Standardization and the International Electrotechnical Commission. The current edition is ISO/IEC 27001:2022. Its Annex A lists 93 controls grouped into four themes: organisational, people, physical and technological.

Two distinct things are being built. The management system itself is defined by clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation and improvement. These requirements are mandatory. The Annex A controls are the second part, and which of them apply is determined by the organisation’s own risk assessment and recorded in the Statement of Applicability, with reasons for inclusion and exclusion.

Getting this the right way round matters. Implementations that begin by writing 93 control documents and only later define a scope and a risk assessment tend to produce a large body of paperwork that does not correspond to any real risk, and auditors notice.

The implementation sequence

The stages below are the working order. Some overlap in practice, but none of them can sensibly be skipped.

  1. Secure management commitment and appoint the owner. Top management has explicit obligations in the standard. Confirm the sponsor, the budget and the person accountable for the ISMS before anything else starts.
  2. Define the context and the interested parties. Identify the internal and external issues relevant to information security and the requirements of customers, regulators and other interested parties.
  3. Set the scope of the ISMS. State which parts of the organisation, which locations, which services and which information systems are covered, and record the interfaces and dependencies with anything outside the boundary. A scope that is too broad makes the project unmanageable; one that is too narrow will not satisfy the customers asking for the certificate.
  4. Run a gap assessment. Compare current practice against clauses 4 to 10 and against Annex A, and produce a prioritised list of what is missing.
  5. Write the information security policy and assign roles. The policy sets direction and commits the organisation to meeting requirements and to continual improvement. Roles, responsibilities and authorities must be assigned and communicated.
  6. Build and run the information security risk assessment. Define the methodology and the risk acceptance criteria first, then identify risks to confidentiality, integrity and availability within the scope, assign owners, and analyse and evaluate them consistently.
  7. Produce the risk treatment plan. For each risk decide the treatment, then determine the controls needed. Compare the controls determined against Annex A to check nothing has been overlooked.
  8. Produce the Statement of Applicability. Record every Annex A control, whether it is applicable, the justification for inclusion or exclusion, and its implementation status. This is a mandatory document and it is one of the first things an auditor asks for.
  9. Implement the applicable controls. Access control, cryptography, logging and monitoring, supplier security, secure development, physical security, human resource security, business continuity and the rest of the applicable set, each with the records that show it operating.
  10. Deliver competence, awareness and communication. Determine the competence required for the roles that affect information security, train accordingly, run awareness for all staff and keep the evidence.
  11. Control documented information. The policies, procedures and records required by the standard and those the organisation determines are necessary, under version control with defined approval and retention.
  12. Operate the system and let evidence accumulate. Controls must be running long enough to produce records. This is the stage most commonly compressed, and compressing it is the usual reason a Stage 2 audit raises findings.
  13. Monitor, measure, analyse and evaluate. Decide what is measured, how, by whom and how often, and evaluate the performance and effectiveness of the ISMS against it.
  14. Conduct the internal audit. Audit the whole ISMS against the standard and against the organisation’s own requirements, using auditors who are competent and objective in respect of the areas they audit. Record findings and act on them.
  15. Hold the management review. Top management reviews the ISMS against the inputs the standard specifies, including audit results, performance measures, the status of risks and opportunities for improvement, and records the decisions.
  16. Close nonconformities and take corrective action. React to each nonconformity, evaluate the cause, act to stop it recurring and record the outcome.
  17. Select the certification body and complete Stage 1. Choose a body accredited by a national accreditation body that is a signatory to the International Accreditation Forum Multilateral Recognition Arrangement. Stage 1 reviews the scope, documentation and readiness and identifies anything that would block Stage 2.
  18. Complete Stage 2 and close any findings. Stage 2 tests whether the ISMS operates as described. Nonconformities must be addressed before the certificate is issued.
  19. Maintain the certificate. The certificate covers three years. Surveillance audits are conducted annually and a recertification audit takes place before it expires. Risk assessment, internal audit and management review continue on their own cycles throughout.

What usually goes wrong

  • Scope drafted to be easy rather than to be useful. If the certificate does not cover the service the customer is buying, it will not close the sale.
  • A risk assessment written to justify controls already chosen. The order is risk first, then controls. An auditor can see the difference.
  • A Statement of Applicability with no justifications. Exclusions in particular need a stated reason.
  • Internal audit treated as a formality. An internal audit that raises no findings across an entire first year ISMS is not credible.
  • Management review held once, in a hurry, without the specified inputs.
  • Too little operating time before Stage 2. Controls that have produced no records cannot be shown to be effective.
  • Supplier and cloud arrangements left out. Where processing depends on third parties, the controls over them are part of the system.

How Univate supports implementation

  • Scope definition, context and interested party analysis.
  • Gap assessment against ISO/IEC 27001:2022 and a prioritised roadmap.
  • Risk assessment methodology, facilitated risk workshops and the risk treatment plan.
  • Statement of Applicability, policy set and procedures written to fit how the organisation actually works.
  • Control implementation support across access management, logging, secure development, supplier security and continuity.
  • Awareness training and internal auditor training.
  • Internal audit, management review facilitation and support through Stage 1 and Stage 2 with the certification body the client selects.

Frequently asked questions

Which edition of ISO 27001 should be implemented?

ISO/IEC 27001:2022 is the current edition. Its Annex A lists 93 controls grouped into four themes: organisational, people, physical and technological.

Do all 93 Annex A controls have to be implemented?

No. The applicable controls are determined by the information security risk assessment and risk treatment carried out by the organisation. Every Annex A control is then listed in the Statement of Applicability with a justification for its inclusion or exclusion and its implementation status.

What is the Statement of Applicability?

It is the mandatory document that records each Annex A control, whether it applies, the reason for including or excluding it, and whether it has been implemented. It is one of the first documents a certification auditor asks to see.

What happens at Stage 1 and Stage 2?

Stage 1 is a readiness and documentation review that examines the scope, the risk assessment, the Statement of Applicability and the internal audit and management review evidence, and identifies anything that would prevent Stage 2. Stage 2 is the main audit and tests whether the ISMS operates as described.

Can the internal audit be done by the person who built the ISMS?

Auditors must be objective and impartial in relation to the work they audit, so someone auditing their own work does not satisfy the requirement. Many organisations use trained internal auditors from another function, or an external internal audit provider.

How long does the certificate last?

The certificate covers a three year cycle, with surveillance audits carried out annually and a recertification audit before it expires.

Univate Solutions supports organisations across India, the GCC, South East Asia, Africa and the United States. Speak to a consultant about your scope.

Univate Global delivers ISO certifications, data privacy compliance and cybersecurity frameworks across its international markets.