Desk
Percy, the Reisen Cyber Institute papillon. Tap for a boop.

ISO 27001

ISO/IEC 27001

The grown-up binder: scope, risk, controls, and proof you run the loop.

A certifiable information security management system (ISMS).

Who it's for. Companies selling to enterprises, especially in Europe and regulated supply chains. Certification is optional; the management system is the point.

  1. 01

    The ISMS, not the sticker

    Official-ish

    Plan, implement, maintain, and continually improve an information security management system.

    Monday version

    ISO cares that you manage security as a system — scope, leadership, risk, controls, audits — not that you bought a famous firewall.

    Do this

    • Draw a scope you can defend (sites, systems, cloud, suppliers).
    • Get leadership to sign risk acceptance, not just the certificate budget.
    • Run internal audits and management review like they change work, because they should.
  2. 02

    Risk assessment & treatment

    Official-ish

    Identify information security risks, then treat them against criteria you defined.

    Monday version

    A living risk register beats a 90-page PDF nobody opens. Residual risk needs an owner.

    Do this

    • Use criteria that match the business, not a generic heat map from 2014.
    • Record treatment: mitigate, avoid, transfer, accept.
    • Revisit when you ship a new product or add a vendor, not once a year for theater.
  3. 03

    Statement of Applicability

    Official-ish

    Document which Annex A controls apply, which do not, and why.

    Monday version

    The SoA is the “we chose these controls on purpose” memo. Auditors live here.

    Do this

    • Map each applicable control to evidence you can find in under five minutes.
    • Write honest exclusions. “N/A because vibes” fails.
    • Keep the SoA in sync when the scope or stack changes.
  4. 04

    Annex A, in human

    Official-ish

    A reference control set (aligned with ISO 27002) covering people, physical, tech, and supplier themes.

    Monday version

    Think themes: identity, logging, crypto, secure development, supplier due diligence — not 93 disconnected chores.

    Do this

    • Group controls by how you operate (IAM, endpoint, SDLC, vendors).
    • Prefer one strong control that covers many rows over 40 weak ones.
    • Train owners. An orphan control is a finding with extra steps.
Drill ISO 27001 — this path is unlocked

Friendly translation, not legal advice. Always read the official text before you tell an auditor you “basically already do this.”