ISO 27001 Information Security Roles and Responsibilities Explained – Control 5.2

ISO 27001 Information Security Roles and Responsibilities Explained – Control 5.2

Information security fails far more often because of unclear ownership than weak technology. Over my 30 years in governance, risk, and compliance, I have seen far too many small businesses, tech startups, and growing teams assume that “security is an IT problem.” When a data breach, ransomware incident, or auditor

ISO 27001 Information Security Roles and Responsibilities Explained – Control 5.2 Read More »

ISO 27001 Management Responsibilities Explained – Control 5.4

ISO 27001 Management Responsibilities Explained – Control 5.4

Information security programmes rarely fail because policies are missing. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft spotless security policies only to fail completely because management behaviour did not match stated intent. When executives demand exception passes around Multi-Factor Authentication (MFA),

ISO 27001 Management Responsibilities Explained – Control 5.4 Read More »

ISO 27001 Information Security in Project Management Explained – Control 5.8

ISO 27001 Information Security in Project Management Explained – Control 5.8

Many security weaknesses are introduced during change, not day-to-day operations. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in securing existing production environments, only to allow project teams to launch new software platforms, migrate core databases to the cloud, or

ISO 27001 Information Security in Project Management Explained – Control 5.8 Read More »

ISO 27001 Inventory of Information and Other Associated Assets Explained – Control 5.9

ISO 27001 Inventory of Information and Other Associated Assets Explained – Control 5.9

You cannot protect what you do not know you have. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in advanced cyber defenses while remaining completely blind to unmapped cloud storage buckets, orphaned databases, legacy physical servers, or unvetted SaaS applications

ISO 27001 Inventory of Information and Other Associated Assets Explained – Control 5.9 Read More »

ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10

ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10

Most information security incidents involve misuse, not technical failure. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in next-gen firewalls, endpoint detection, and complex cloud security tools, only to suffer a disastrous breach because an employee installed unvetted shadow IT

ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10 Read More »

ISO 27001 Information Security in Supplier Relationships Explained – Control 5.19

ISO 27001 Information Security in Supplier Relationships Explained – Control 5.19

Your security posture is only as strong as your weakest supplier relationship. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations build ironclad internal perimeters, only to hand over global administrative credentials, unencrypted customer databases, or direct network connections to unvetted third-party suppliers.

ISO 27001 Information Security in Supplier Relationships Explained – Control 5.19 Read More »

ISO 27001 Addressing Information Security Within Supplier Agreements Explained – Control 5.20

ISO 27001 Addressing Information Security Within Supplier Agreements Explained – Control 5.20

Supplier risk is rarely caused by bad intent—it is caused by unclear expectations. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal verbal promises, glossy vendor marketing claims, or generic commercial purchase orders that contain zero security language. When a

ISO 27001 Addressing Information Security Within Supplier Agreements Explained – Control 5.20 Read More »

ISO 27001 Managing Information Security in the ICT Supply Chain Explained – Control 5.21

ISO 27001 Managing Information Security in the ICT Supply Chain Explained – Control 5.21

ICT supply chains introduce risk long before systems go live. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations carefully configure their internal firewalls and cloud environments, only to inherit devastating vulnerabilities, backdoors, or malicious code through unvetted third-party software libraries, compromised hardware

ISO 27001 Managing Information Security in the ICT Supply Chain Explained – Control 5.21 Read More »

ISO 27001 Monitoring, Review and Change Management of Supplier Services Explained – Control 5.22

ISO 27001 Monitoring, Review and Change Management of Supplier Services Explained – Control 5.22

Supplier risk does not stay static. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations conduct a rigorous security assessment during supplier onboarding, sign a tight contract, and then completely ignore the vendor for three years. In the meantime, the supplier migrates its

ISO 27001 Monitoring, Review and Change Management of Supplier Services Explained – Control 5.22 Read More »

ISO 27001 Information Security for Use of Cloud Services Explained – Control 5.23

ISO 27001 Information Security for Use of Cloud Services Explained – Control 5.23

Cloud services change the control boundary, not the responsibility. Over my 30 years in governance, risk, and compliance, I have seen far too many small businesses, startups, and tech teams adopt SaaS, PaaS, and IaaS platforms under the dangerous assumption that AWS, Azure, Google Cloud, or Microsoft 365 handles “all

ISO 27001 Information Security for Use of Cloud Services Explained – Control 5.23 Read More »

ISO 27001 Information Security Incident Management Planning and Preparation Explained – Control 5.24

ISO 27001 Information Security Incident Management Planning and Preparation Explained – Control 5.24

Incidents rarely fail because teams don’t try hard enough—they fail because planning happened too late. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations wait until ransomware is actively encrypting their file servers or customer data is leaking onto the web before trying

ISO 27001 Information Security Incident Management Planning and Preparation Explained – Control 5.24 Read More »

ISO 27001 Response to Information Security Incidents Explained – Control 5.26

ISO 27001 Response to Information Security Incidents Explained – Control 5.26

Incident response is where preparation is tested under pressure. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations write comprehensive disaster recovery plans and incident playbooks, only to panic when a real-world breach occurs—improvising containment steps, leaking unverified information to the media, destroying

ISO 27001 Response to Information Security Incidents Explained – Control 5.26 Read More »

ISO 27001 Learning From Information Security Incidents Explained – Control 5.27

ISO 27001 Learning From Information Security Incidents Explained – Control 5.27

Incidents only become valuable when organisations actually learn from them. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rush through incident containment and recovery, issue a quick patch, and close the ticket—only to suffer the exact same breach three months later. Closing

ISO 27001 Learning From Information Security Incidents Explained – Control 5.27 Read More »

ISO 27001 Information Security During Disruption Explained – Control 5.29

ISO 27001 Information Security During Disruption Explained – Control 5.29

Disruption changes operational priorities, but security must never be sacrificed in the chaos. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations manage a major crisis—whether a physical disaster, a network outage, or a cyber incident—by completely disabling core security controls just to

ISO 27001 Information Security During Disruption Explained – Control 5.29 Read More »

ISO 27001 Legal, Statutory, Regulatory and Contractual Requirements Explained – Control 5.31

ISO 27001 Legal, Statutory, Regulatory and Contractual Requirements Explained – Control 5.31

Information security obligations do not exist in isolation. They are shaped, bounded, and enforced by law, regulation, and contract. Over my 30 years in governance, risk, and compliance, I have seen far too many security teams design technically brilliant architectures that completely fail in practice because they ignored the legal

ISO 27001 Legal, Statutory, Regulatory and Contractual Requirements Explained – Control 5.31 Read More »

ISO 27001 Compliance with Policies, Rules, and Standards Explained – Control 5.36

ISO 27001 Compliance with Policies, Rules, and Standards Explained – Control 5.36

Security controls only work if people actually follow them. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft immaculate, comprehensive security policies, stick them in a PDF on an obscure intranet page, and assume that documentation equals protection. Write-and-forget policies are useless.

ISO 27001 Compliance with Policies, Rules, and Standards Explained – Control 5.36 Read More »

ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5

ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5

The risk does not end when someone leaves your business. In many cases, it increases dramatically. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run smooth technical onboarding processes, only to completely fumble off boarding, leaving active credentials assigned to departed contractors,

ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5 Read More »

ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6

ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6

Confidential information only stays confidential if expectations are clear and legally enforceable. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal trust, handshakes, or generic, copy-pasted templates when sharing high-value IP, customer databases, or trade secrets with staff, contractors, and

ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6 Read More »

ISO 27001 Protecting Against Physical and Environmental Threats Explained – Control 7.5

ISO 27001 Protecting Against Physical and Environmental Threats Explained – Control 7.5

Not all security threats are digital. Some arrive as fire, water ingress, extreme heat, power surges, or civil disruption. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses build military-grade firewalls and zero-trust software architectures while completely ignoring physical reality, like placing primary

ISO 27001 Protecting Against Physical and Environmental Threats Explained – Control 7.5 Read More »

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14

Availability is not achieved by hope. It is achieved by designing systems that continue to operate when something fails. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses suffer catastrophic downtime because they assumed their systems were redundant simply because they were in

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14 Read More »

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18

Utility programs are powerful by design. That power is exactly why they need tighter control than ordinary software. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations leave administrative utilities, system diagnostics, and low-level disk tools sitting openly on production servers for “convenience.”

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18 Read More »

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19

Most serious production outages do not start with clever external attackers. They start with uncontrolled software changes inside live environments. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses let well-meaning engineers or staff apply “quick updates,” unapproved utilities, or untested patches directly

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19 Read More »

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27

Most security failures are not caused by missing security tools. They are caused by poor design decisions made early and never revisited. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses bolt expensive security appliances onto a fundamentally flawed network design, only for

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27 Read More »

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29

Most security failures are discovered after deployment, when fixing them is slow, expensive, and disruptive. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run comprehensive tests on software functionality, only to go live with massive security holes because no one bothered to

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29 Read More »

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31

Many major security incidents are not complex, external cyber attacks. They are simple, accidental changes made in the wrong environment. Over my 30 years in governance, risk, and compliance, I have seen developers accidentally drop a database or release unverified code simply because they thought they were connected to a

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31 Read More »

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34

Audits are supposed to reduce risk. Handled badly, they create it. Over my 30 years in governance, risk, and compliance, I have seen plenty of well-meaning auditors accidentally cause system outages or extract sensitive data without proper controls. Uncontrolled audit testing is a security incident waiting to happen. ISO 27001:2022

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34 Read More »