Annex A Controls Explained
ISO 27001 Control 5.6 Contact with special interest groups
ISO 27001 Control 5.6 is about establishing and maintaining contact with special interest groups, security forums, and professional associations as a part of an organisation’s information security strategy. These groups provide essential resources and insights that enhance an organisation’s ability to protect, respond to, and recover from security incidents.
Written By: Alan Parker, ISO 27001 Consultant
Last Updated: 11 May 2026
Alan Parker, ISO 27001 Consultant & Internal Auditor,
Helping UK SMEs hit ISO 27001 in 90 days.
B.Sc (Hons) Information Systems · CISMP · ITIL Expert · 30+ years in IT governance and security.
Read full bio →
ISO 27001 Control 5.6 Contact with special interest groups: “The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.”
https://www.iso.org/standard/27001
Key Takeaways
- 5.6 is about not operating in isolation. The standard requires you to have credible external channels that feed your view of the threat landscape.
- For UK SMEs, the NCSC’s CiSP is the single most valuable free SIG to join. It’s government-backed, free, and genuinely useful. Two or three engaged memberships beat ten dormant ones.
- The control is about the quality of engagement, not the quantity of registrations.
- Active participation isn’t mandatory for certification.
- Subscribing to alerts, reading advisories, and documenting how you use them is enough. Practitioner communities (Reddit, Slack, LinkedIn groups) count too. The standard doesn’t require formal industry bodies; it requires credible external sources of insight.
Table of Contents

The Purpose of Engaging with Special Interest Groups
The whole reason behind ISO 27001 control 5.6 is that the standard requires you to evaluate and consider external sources of information, so you don’t remain isolated and blissfully unaware of what’s happening with security in the wider world. Without signing up to special interest groups, you might not be aware of recent trends in ransomware attacks, or of something a little more specific and relevant to your organisation, its risks, and technology stack.
The primary goals of engaging with special interest groups are to:
- Facilitate the flow of relevant and up-to-date information on information security.
- Strengthen the organisation’s capacity to proactively address emerging threats and vulnerabilities.
So, if you haven’t already, start exploring forums, newsletters, and other tools to stay abreast of relevant trends.
Suggested Special Interest Groups for SMEs
| Group | What it offers | Best for | Cost | Where to find |
|---|---|---|---|---|
| NCSC Cyber Information Sharing Partnership (CiSP) | Government-backed threat intelligence sharing platform; alerts, advisories, peer discussion across UK industries | Any UK organisation; particularly useful for those without paid threat feeds | Free (membership application required) | ncsc.gov.uk/section/keep-up-to-date/cisp |
| ISACA (UK chapters) | Global IS audit and governance professional body; local chapter events, training, COBIT and risk management resources | InfoSec leads, internal auditors, GRC professionals | Paid annual membership; chapter events often free or low-cost | isaca.org |
| (ISC)² | Professional body behind CISSP and CCSP; UK chapters, webinars, CPE-eligible content | Security professionals seeking certification or peer network | Paid annual membership; some content free | isc2.org |
| BCS, The Chartered Institute for IT | UK-focused IT professional body; Information Security Specialist Group runs events, webinars, and a journal | UK IT and security generalists; good for SMEs whose security lead wears multiple hats | Paid annual membership; ISSG events often free for members | bcs.org |
| IASME | UK SME-focused security certification body and community; runs Cyber Essentials, IASME Cyber Assurance, and a partner network | UK SMEs specifically; particularly relevant if you also pursue Cyber Essentials | Free to follow; paid for certification | iasme.co.uk |
| OWASP (local chapters) | Open-source web application security community; chapter meetups, free resources, the Top 10 and ASVS | SaaS, software, and web-development SMEs | Free | owasp.org |
| FIRST (Forum of Incident Response and Security Teams) | Global incident response community; SIG groups, conference, technical resources | Organisations with internal incident response capability or aspirations to build one | Free reading; paid for member organisations | first.org |
| SANS Internet Storm Center | Daily threat intelligence summaries and community-driven incident handling | Any SME wanting structured daily threat awareness without paying for a feed | Free | isc.sans.edu |
| Sector-specific ISACs (e.g. FS-ISAC, H-ISAC) | Industry-specific threat intelligence sharing; financial services, healthcare, retail, etc. | Regulated SMEs in financial services, healthcare, or other ISAC-served sectors | Paid membership | first.org/global/sigs/isacs |
| LinkedIn / Slack practitioner communities | Informal practitioner discussion; UK-specific groups for InfoSec, GRC, and ISO 27001 leads | Anyone wanting low-effort peer contact and current practitioner conversation | Free | LinkedIn search; community Slack instances by invitation |
| Local Cyber Resilience Centres (CRCs) | Police-led regional centres providing free guidance, alerts, and training to SMEs | UK SMEs wanting regional, free, government-aligned support | Free for core services | nationalcrcgroup.co.uk |
Don’t go crazy and try to join all of these! If you select two or three relevant ones, they’ll be worth more than the ten you’ve registered for and never engage with, and have set up an email rule to push notifications to a folder you never open.
The control isn’t about quantity; it’s about having credible peer and expert channels you can draw on when you need them.
Key Benefits of Membership in Special Interest Groups
There are a few benefits of all of this that I should highlight, including:
Access to Industry Best Practices
I don’t care who you are; there’s always something to learn, with others forging the way and sharing experiences. There are forums, websites and paywalled content that help you stay informed about methodologies and standards within the industry.
You can not only benefit from the shared experiences of other organisations in managing similar challenges, but also stay ahead of changes to standards. For example, ISO 27001 had an amendment a little while back, which many didn’t realise. If you stay aware of and ahead of the changes, you won’t get caught off guard during an audit.
Real-Time Security Insights
This is so obvious that it doesn’t require much explanation, but if you stay attuned to global security trends through interest groups, you can get immediate updates on new threats, vulnerabilities, and developments affecting the industry. I personally really value the NCSC (the UK’s National Cyber Security Centre), they have excellent news and advisories on current emerging trends and present it in an easily digestible manner.
Collaborative Information Sharing
Some forums are great places to exchange information and bounce ideas about situations you face or wrestle with. For example, the Reddit ISO 27001 forum (https://www.reddit.com/r/ISO27001/) is really good. There are a number of auditors and consultants hanging around, ready and willing to answer questions.
Common Issues
5.6 is one of those controls where the gap between “we joined a thing” and “we actually use a thing” can be wide.
Here are some pitfalls you should try to avoid;
Memberships nobody engages with. The organisation joined CiSP three years ago; the credentials are in someone’s password manager, and nobody has logged in for 18 months. Auditors will ask what insights you’ve drawn from your memberships in the last quarter. “We’re members of X” isn’t an answer; “we picked up the recent advisory on Y and acted on it by doing Z” is.
No evidence of internal sharing. The InfoSec lead reads CiSP advisories every week but never shares relevant ones with the wider team. The whole point of 5.6 is that external insight feeds internal action. If nothing leaves your inbox, the control isn’t doing its job.
No documented review of which SIGs are still relevant. Memberships drift. The forum that was useful three years ago might be quiet now; a new community might have replaced it. An annual review of which SIGs you’re engaged with, and whether they’re still earning their place, is part of keeping the control current.
Over-reliance on a single source. “We just follow NCSC” is fine as a baseline, but if your only input comes from a single source, you’re missing the diversity of perspectives that 5.6 is asking for. Two or three credible sources covering different angles (national-level threat intelligence, sector-specific intelligence, peer practitioner discussion) is what good looks like.
How does ISO 27001 Control 5.6 link to other clauses and controls
Special interest groups don’t operate in isolation; they feed into several other parts of the ISMS. Understanding the relationships helps you put the insights you gather to actual use.
- Control 5.5 – Contact with authorities: The sister control. 5.5 is the formal authority-contact side; 5.6 is the peer-and-expert side.
- Control 5.7 – Threat intelligence: SIG memberships are one of the cheapest sources of usable threat intelligence for SMEs. Most of what feeds 5.7 for a small business comes through 5.6 channels.
- Clause 7.3 – Awareness: Insights from SIGs feed your awareness programme. A monthly “what’s hot in security right now” summary drawn from CiSP and NCSC is genuinely useful internal content.
- Control 5.31 – Legal, statutory, regulatory and contractual requirements: Some SIGs (particularly sector-specific ones like FS-ISAC) are where you’ll first hear about emerging regulatory expectations.
- Clause 9.3 – Management Review: Trends and insights from your SIG engagement are good inputs to management review meetings. They help leadership stay informed about the threat landscape without making it a technical briefing.
FAQs
What is the purpose of Control 5.6 in ISO 27001?
This control encourages organisations to engage with external groups like industry bodies, security forums, and regulatory communities. The goal is to stay informed about security trends, threats, and best practices, and to strengthen collaboration.
What counts as a “special interest group”?
Special interest groups can include:
– Industry associations (e.g., tech or finance sectors)
– Cybersecurity forums and alliances
– Regulatory or compliance bodies
– Standards organisations
– Government and law enforcement partnerships
– Incident sharing networks (e.g., ISACs)
Why is involvement with these groups important?
By participating, you gain:
– Early warnings about new threats
– Insights into regulatory changes
– Opportunities to share knowledge and experiences
– Access to peer support and resources
It helps your organisation stay informed, compliant, and resilient.
Is this control mandatory for certification?
While active participation isn’t mandated, you do need to consider and document how your organisation will benefit from these external contacts — even if it’s just subscribing to alerts or joining a relevant mailing list.
What’s a simple way to implement this control?
Start by:
– Identifying relevant groups in your industry
– Subscribing to security bulletins or newsletters
– Assigning someone to track updates and share insights internally
– Joining free forums or attending webinars
Even small steps can show compliance and improve your security awareness.
Conclusion
Engaging with special interest groups isn’t about ticking a certification box. It’s about ensuring your view of the threat landscape doesn’t ossify, and that you have credible peer and expert channels to draw on when you need them.
Pick two or three SIGs that genuinely fit your sector and your stack, engage with them properly, and document what you’ve learned and what you’ve acted on. That’s enough to satisfy the control and, more importantly, to give your ISMS the external feed it needs.
If you’d like a structured way to track your SIG memberships, what you’ve drawn from them, and how you’ve shared insights internally, the Iseo Blue ISO 27001 Toolkit includes templates that cover exactly this. Or, if you’d rather talk through which SIGs are most relevant to your specific business, the free 30-minute consultation is genuinely free and 30 minutes long.
Author Background
This article was written by Alan Parker, an ISO 27001 consultant and founder of Iseo Blue Limited. He helps UK SMEs achieve certification in 90 days or less, often without a dedicated security team or a large budget.
With over 30 years in IT governance and information security, Alan works with software companies, IT service providers, managed service providers, and professional services firms across the UK, Europe, and internationally.
Qualifications: ITIL v3 Expert, ITIL v4 Bridge, PRINCE2 Practitioner. Named IT Project Expert of the Year (2024, UK). Alan writes in plain English for busy teams who need to get things done.
Connect on LinkedIn or Bluesky, or explore his free ISO 27001 tools and templates at iseoblue.com. B.Sc (Hons) Information Systems, CISMP certified.