ISO/IEC 27001 – Information security management

ISO/IEC 27001 is the international standard for information security management systems. It describes how a company protects its information: systematically, verifiably and on the basis of assessed risks. The standard applies to every sector and every size.

It does not prescribe any technology. It requires you to know your risks and to decide, with reasons, what you do about them. That is precisely why two systems holding the same certificate often look completely different. One of them runs the day-to-day business, the other exists only for the audit.

Who it applies to

Where it usually goes wrong

The scope is drawn too narrowly

To save effort, only part of the company is included. One site, one department, one business area. That sounds like a sensible way in, and in principle it is permitted. But the scope has to stand up to scrutiny.

In the audit it then emerges that the excluded areas use the same systems. The same network, the same file storage, the same user accounts. The boundary cannot be explained, and the certificate loses its meaning. An honestly drawn small scope is worth more than an artificially trimmed large one.

Risk treatment and the Statement of Applicability do not match

The controls from Annex A are ticked off as a list. Every line gets a tick, the Statement of Applicability is filled in completely. Only the link to the assessed risks cannot be established. Ask in the audit which risk a particular control addresses, and no answer comes.

This is most obvious with excluded controls. The justification is almost always missing there. Yet that is exactly the point an auditor asks about first. An exclusion is permissible if you can explain it convincingly.

Effectiveness is not measured

The controls are in place, the documents exist. But nobody checks whether they work day to day. There is a password policy, and there is no analysis of whether it is being followed.

This is the most common finding in the surveillance audit. The standard demands monitoring, measurement and evaluation – not just implementation. Often a handful of figures from systems you already run will do. Reports from the directory service, numbers from the ticket system, results from training.

Relationship to NIS 2

ISO 27001 covers a considerable part of the NIS 2 Directive requirements. Risk management, access control, supply chain, contingency planning, staff training – all of that is already in the standard. If you are certified, you have largely done the substantive work. But the certificate is not a substitute.

NIS 2 contains obligations that go beyond the standard. These include registration with the BSI and the reporting duties with their tight deadlines. The responsibility of top management is also explicitly regulated. If both are ahead of you, plan them together. Two separate projects cost more and produce duplicate documentation. More under NIS 2 consulting.

How we support you

We start with a stocktake. Which security measures, rules and records are already in place? In our experience there are more than the people involved assume. They are simply not prepared as evidence. Out of that comes a plan that names the real gaps.

Then follow the scope, the risk assessment and the Statement of Applicability. We make sure these three documents fit together. After that, the internal audit and preparation for the certification audit. More under Building a management system and Internal audits & gap analyses.

Who handles this at our end

Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806, specialising in information security

This standard is covered by one person here. We say so openly, because it matters for your planning: if he is on holiday or off sick, there is no second option as there is for ISO 9001.

In return you get technical depth. Rüdiger Rammé develops databases and interfaces himself and knows the systems that come up in the audit. Permissions, logging, interfaces, data flows. If demonstrating compliance needs a technical solution, we build it. See Software & databases.

The team in detail

Frequently asked questions

How long does it take to reach certification?

Reckon on nine to eighteen months if you start without an existing management system. With a working ISO 9001 system it goes considerably faster. The biggest factor in the timeline is in your own hands: the availability of the people from IT and the operating departments.

What does it cost?

Projects of this kind typically run between 10,000 and 50,000 euros. Where you land within that depends on the scope, the number of sites and the maturity of your IT. The certification body's fees come on top.

Does ISO 27001 automatically make us NIS 2 compliant?

No, but it covers a considerable part. Registration with the BSI and the reporting duties with their deadlines go beyond the standard. If both are due, we plan them together rather than one after the other.

Can we keep the scope small?

Yes, if it stands up to scrutiny. An area with its own systems and clear interfaces can be separated cleanly. A department that uses the same network as everyone else cannot. We check this early so there is no surprise in the audit.

Do we need an IT department of our own?

No. Many certified companies work with external service providers. What matters is that you keep the responsibility and stay in control. What the provider delivers belongs in a contract and needs reviewing regularly. That is exactly what an auditor looks at.

Let us talk about it

The first conversation is free and without obligation.

Get in touch