Articles
My articles across various subject – all for you to review.
-
ISO 27001 Certification: UKAS vs Non-UKAS — Does It Matter?
Explore the differences between UK certifications: UKAS vs Non-Accredited certificates. How the differ, and does it matter?
When you are choosing a certification body for ISO 27001, one of the first things you will encounter is the question of accreditation. Some certification bodies hold accreditation from UKAS — the United Kingdom Accreditation Service, or its equivalent in other countries. Others do not. The difference in cost can be significant. Whether the difference … Read more
-
What Is a UKAS-Accredited ISO 27001 Certificate?
Learn what a UKAS accredited ISO 27001 certificate is, and who issues them in the UK.
When an organisation says it holds ISO 27001 certification, the value of that statement (to anyone in the know) depends on who issued the certificate. A UKAS-accredited ISO 27001 certificate is one issued by a certification body that has itself been assessed and approved by the United Kingdom Accreditation Service. Understanding what that means — … Read more
-
How to Conduct an ISO 27001 Management Review (Template Included)
My guide on how to conduct an ISO 27001 Management Review of your ISMS. Included agenda template
The management review is one of those ISMS activities that organisations often get wrong in one of two ways. Either it becomes a formality — a brief meeting where management nods along while the ISMS lead presents a slide deck, then signs the minutes — or it becomes an unwieldy marathon that nobody wants to … Read more
-
ISMS Document Control: How to Manage It Properly
How to manage your ISMS documentation. Read my guide on how to implement ISO 27001 document control and meet the requirements of the standard.
Document control is one of those requirements that organisations either over-engineer into a bureaucratic nightmare or under-deliver on to the point where an auditor cannot find what they need. Both failure modes are common. The right approach sits between them: a consistent, proportionate system that keeps your ISMS documentation accurate, accessible, and trustworthy — without … Read more
-
ISO 27001 Penetration Testing: What the Standard Actually Requires
Learn what the standard really requires around ISO 27001 and penetration testing
Penetration testing is one of the most widely misunderstood requirements in ISO 27001. Consultants frequently tell clients they need annual pen tests to achieve certification. Organisations buy pen tests as an ISO 27001 checkbox exercise. And the common assumption — that pen testing is a mandatory requirement of the standard — is repeated frequently enough … Read more
-
How to Write an ISO 27001 ISMS Scope Statement (With Examples)
How to write your ISO 27001 scope statement for your ISMS with examples of what works and what doesn’t
The ISMS scope statement is one of the first documents you need to produce when implementing ISO 27001 — and one of the most consequential. Get it right and your certification effort stays focused and proportionate. Get it wrong and you either spend the next year trying to certify things that did not need to … Read more
-
ISO 27001 Risk Treatment Options: Accept, Mitigate, Transfer, Avoid
How to handle risk treatment under ISO 27001 clause 6. Common options and the key aspects of a risk treatment plan.
Risk assessment tells you what your risks are. Risk treatment is what you decide to do about them. For many organisations going through ISO 27001 implementation, the assessment itself gets the most attention — identifying assets, threats, vulnerabilities, and likelihood ratings. But the treatment decisions are where the real work happens, and where auditors spend … Read more
-
ISO 27001 Surveillance Audits: What to Expect
What happens after certification? The ISO 27001 surveillance audit in years 1 and 2, and the recertification audit in year 3 process explained.
Getting ISO 27001 certified is the milestone most organisations focus on. What comes after it — the ongoing audit cycle that keeps the certificate valid — is less well understood, and the gap in preparation often shows. Certification is issued for three years. During that period, your certification body conducts surveillance audits — typically in … Read more
-
How to Handle a Data Breach Under ISO 27001
How to create an ISO 27001 Data Breach Procedure in order to handle incidents within the scope of your ISMS
A data breach does not announce itself. It might surface as an unusual login alert at 11pm, a supplier calling to say they have received a strange email from your domain, a member of staff reporting that they sent a client file to the wrong person, or a ransomware notification on a Monday morning. In … Read more
-
ISO 27001 Training and Awareness: Building Your Programme
Most ISO 27001 training programmes are built to satisfy an auditor, not to change behaviour. Staff complete an annual e-learning module, click through the acknowledgement, and forget 80% of it within a week. The organisation ticks the box, the auditor sees a completion record, and twelve months later the phishing simulation results look exactly the … Read more