
Understanding ISO/IEC 27001 for Information Security
A risk-based approach to protecting information, customer data, access, systems, suppliers, and business processes.
It is not only a technology issue
Information security also covers people, processes, facilities, suppliers, contracts, governance, and incident response.
Define the scope and assets
Organizations need to define the services, systems, locations, personnel, data, and third parties included in the scope.
Conduct a risk assessment
Risk is assessed based on threats, vulnerabilities, impacts, likelihood, and existing controls.
Evaluate control effectiveness
Controls need to be monitored, tested, audited, and improved. Certification does not mean an organization is free from every incident.