Annex A Controls Explained

ISO 27001 Control 5.6 Contact with special interest groups

Written By: Alan Parker, ISO 27001 Consultant
Last Updated: 11 May 2026

Alan Parker, ISO 27001 Consultant & Internal Auditor,
Helping UK SMEs hit ISO 27001 in 90 days.
B.Sc (Hons) Information Systems · CISMP · ITIL Expert · 30+ years in IT governance and security.
Read full bio

ISO 27001 Control 5.6 Contact with special interest groups: “The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.”

https://www.iso.org/standard/27001

Key Takeaways

  • 5.6 is about not operating in isolation. The standard requires you to have credible external channels that feed your view of the threat landscape.
  • For UK SMEs, the NCSC’s CiSP is the single most valuable free SIG to join. It’s government-backed, free, and genuinely useful. Two or three engaged memberships beat ten dormant ones.
  • The control is about the quality of engagement, not the quantity of registrations.
  • Active participation isn’t mandatory for certification.
  • Subscribing to alerts, reading advisories, and documenting how you use them is enough. Practitioner communities (Reddit, Slack, LinkedIn groups) count too. The standard doesn’t require formal industry bodies; it requires credible external sources of insight.


ISO 27001 Control 5.6 Contact with special interest groups

The Purpose of Engaging with Special Interest Groups

The whole reason behind ISO 27001 control 5.6 is that the standard requires you to evaluate and consider external sources of information, so you don’t remain isolated and blissfully unaware of what’s happening with security in the wider world. Without signing up to special interest groups, you might not be aware of recent trends in ransomware attacks, or of something a little more specific and relevant to your organisation, its risks, and technology stack.

The primary goals of engaging with special interest groups are to:

  • Facilitate the flow of relevant and up-to-date information on information security.
  • Strengthen the organisation’s capacity to proactively address emerging threats and vulnerabilities.

So, if you haven’t already, start exploring forums, newsletters, and other tools to stay abreast of relevant trends.

Suggested Special Interest Groups for SMEs

GroupWhat it offersBest forCostWhere to find
NCSC Cyber Information Sharing Partnership (CiSP)Government-backed threat intelligence sharing platform; alerts, advisories, peer discussion across UK industriesAny UK organisation; particularly useful for those without paid threat feedsFree (membership application required)ncsc.gov.uk/section/keep-up-to-date/cisp
ISACA (UK chapters)Global IS audit and governance professional body; local chapter events, training, COBIT and risk management resourcesInfoSec leads, internal auditors, GRC professionalsPaid annual membership; chapter events often free or low-costisaca.org
(ISC)²Professional body behind CISSP and CCSP; UK chapters, webinars, CPE-eligible contentSecurity professionals seeking certification or peer networkPaid annual membership; some content freeisc2.org
BCS, The Chartered Institute for ITUK-focused IT professional body; Information Security Specialist Group runs events, webinars, and a journalUK IT and security generalists; good for SMEs whose security lead wears multiple hatsPaid annual membership; ISSG events often free for membersbcs.org
IASMEUK SME-focused security certification body and community; runs Cyber Essentials, IASME Cyber Assurance, and a partner networkUK SMEs specifically; particularly relevant if you also pursue Cyber EssentialsFree to follow; paid for certificationiasme.co.uk
OWASP (local chapters)Open-source web application security community; chapter meetups, free resources, the Top 10 and ASVSSaaS, software, and web-development SMEsFreeowasp.org
FIRST (Forum of Incident Response and Security Teams)Global incident response community; SIG groups, conference, technical resourcesOrganisations with internal incident response capability or aspirations to build oneFree reading; paid for member organisationsfirst.org
SANS Internet Storm CenterDaily threat intelligence summaries and community-driven incident handlingAny SME wanting structured daily threat awareness without paying for a feedFreeisc.sans.edu
Sector-specific ISACs (e.g. FS-ISAC, H-ISAC)Industry-specific threat intelligence sharing; financial services, healthcare, retail, etc.Regulated SMEs in financial services, healthcare, or other ISAC-served sectorsPaid membershipfirst.org/global/sigs/isacs
LinkedIn / Slack practitioner communitiesInformal practitioner discussion; UK-specific groups for InfoSec, GRC, and ISO 27001 leadsAnyone wanting low-effort peer contact and current practitioner conversationFreeLinkedIn search; community Slack instances by invitation
Local Cyber Resilience Centres (CRCs)Police-led regional centres providing free guidance, alerts, and training to SMEsUK SMEs wanting regional, free, government-aligned supportFree for core servicesnationalcrcgroup.co.uk

Don’t go crazy and try to join all of these! If you select two or three relevant ones, they’ll be worth more than the ten you’ve registered for and never engage with, and have set up an email rule to push notifications to a folder you never open.

The control isn’t about quantity; it’s about having credible peer and expert channels you can draw on when you need them.


Key Benefits of Membership in Special Interest Groups

There are a few benefits of all of this that I should highlight, including:

Access to Industry Best Practices

I don’t care who you are; there’s always something to learn, with others forging the way and sharing experiences. There are forums, websites and paywalled content that help you stay informed about methodologies and standards within the industry.

You can not only benefit from the shared experiences of other organisations in managing similar challenges, but also stay ahead of changes to standards. For example, ISO 27001 had an amendment a little while back, which many didn’t realise. If you stay aware of and ahead of the changes, you won’t get caught off guard during an audit.

Real-Time Security Insights

This is so obvious that it doesn’t require much explanation, but if you stay attuned to global security trends through interest groups, you can get immediate updates on new threats, vulnerabilities, and developments affecting the industry. I personally really value the NCSC (the UK’s National Cyber Security Centre), they have excellent news and advisories on current emerging trends and present it in an easily digestible manner.

Collaborative Information Sharing

Some forums are great places to exchange information and bounce ideas about situations you face or wrestle with. For example, the Reddit ISO 27001 forum (https://www.reddit.com/r/ISO27001/) is really good. There are a number of auditors and consultants hanging around, ready and willing to answer questions.


Common Issues

5.6 is one of those controls where the gap between “we joined a thing” and “we actually use a thing” can be wide.

Here are some pitfalls you should try to avoid;

Memberships nobody engages with. The organisation joined CiSP three years ago; the credentials are in someone’s password manager, and nobody has logged in for 18 months. Auditors will ask what insights you’ve drawn from your memberships in the last quarter. “We’re members of X” isn’t an answer; “we picked up the recent advisory on Y and acted on it by doing Z” is.

No evidence of internal sharing. The InfoSec lead reads CiSP advisories every week but never shares relevant ones with the wider team. The whole point of 5.6 is that external insight feeds internal action. If nothing leaves your inbox, the control isn’t doing its job.

No documented review of which SIGs are still relevant. Memberships drift. The forum that was useful three years ago might be quiet now; a new community might have replaced it. An annual review of which SIGs you’re engaged with, and whether they’re still earning their place, is part of keeping the control current.

Over-reliance on a single source. “We just follow NCSC” is fine as a baseline, but if your only input comes from a single source, you’re missing the diversity of perspectives that 5.6 is asking for. Two or three credible sources covering different angles (national-level threat intelligence, sector-specific intelligence, peer practitioner discussion) is what good looks like.


Special interest groups don’t operate in isolation; they feed into several other parts of the ISMS. Understanding the relationships helps you put the insights you gather to actual use.


FAQs

What is the purpose of Control 5.6 in ISO 27001?

This control encourages organisations to engage with external groups like industry bodies, security forums, and regulatory communities. The goal is to stay informed about security trends, threats, and best practices, and to strengthen collaboration.

What counts as a “special interest group”?

Special interest groups can include:

– Industry associations (e.g., tech or finance sectors)
– Cybersecurity forums and alliances
– Regulatory or compliance bodies
– Standards organisations
– Government and law enforcement partnerships
– Incident sharing networks (e.g., ISACs)

Why is involvement with these groups important?

By participating, you gain:

– Early warnings about new threats
– Insights into regulatory changes
– Opportunities to share knowledge and experiences
– Access to peer support and resources

It helps your organisation stay informed, compliant, and resilient.

Is this control mandatory for certification?

While active participation isn’t mandated, you do need to consider and document how your organisation will benefit from these external contacts — even if it’s just subscribing to alerts or joining a relevant mailing list.

What’s a simple way to implement this control?

Start by:

– Identifying relevant groups in your industry
– Subscribing to security bulletins or newsletters
– Assigning someone to track updates and share insights internally
– Joining free forums or attending webinars

Even small steps can show compliance and improve your security awareness.

Conclusion

Engaging with special interest groups isn’t about ticking a certification box. It’s about ensuring your view of the threat landscape doesn’t ossify, and that you have credible peer and expert channels to draw on when you need them.

Pick two or three SIGs that genuinely fit your sector and your stack, engage with them properly, and document what you’ve learned and what you’ve acted on. That’s enough to satisfy the control and, more importantly, to give your ISMS the external feed it needs.

If you’d like a structured way to track your SIG memberships, what you’ve drawn from them, and how you’ve shared insights internally, the Iseo Blue ISO 27001 Toolkit includes templates that cover exactly this. Or, if you’d rather talk through which SIGs are most relevant to your specific business, the free 30-minute consultation is genuinely free and 30 minutes long.


Author Background

This article was written by Alan Parker, an ISO 27001 consultant and founder of Iseo Blue Limited. He helps UK SMEs achieve certification in 90 days or less, often without a dedicated security team or a large budget.

With over 30 years in IT governance and information security, Alan works with software companies, IT service providers, managed service providers, and professional services firms across the UK, Europe, and internationally.

Qualifications: ITIL v3 Expert, ITIL v4 Bridge, PRINCE2 Practitioner. Named IT Project Expert of the Year (2024, UK). Alan writes in plain English for busy teams who need to get things done.

Connect on LinkedIn or Bluesky, or explore his free ISO 27001 tools and templates at iseoblue.com. B.Sc (Hons) Information Systems, CISMP certified.