ISO 27001 Policies for Information Security Explained – Control 5.1

ISO 27001:2022 Annex A 5.1 | Policies for Information Security Beginner’s Guide

Information security policies are often treated as pure paperwork, something written once during initial certification, approved by executives without being read, filed away in a dusty portal, and dusted off only when an auditor schedules a review. Over my 30 years in governance, risk, and compliance, I have seen far […]

ISO 27001:2022 Annex A 5.1 | Policies for Information Security Beginner’s Guide Read More »

ISO 27001 Information Security Roles and Responsibilities Explained – Control 5.2

ISO 27001:2022 Annex A 5.2 | Information Security Roles and Responsibilities Beginner’s Guide

Information security fails far more often because of unclear ownership than weak technology. Over my 30 years in governance, risk, and compliance, I have seen far too many small businesses, tech startups, and growing teams assume that “security is an IT problem.” When a data breach, ransomware incident, or auditor

ISO 27001:2022 Annex A 5.2 | Information Security Roles and Responsibilities Beginner’s Guide Read More »

ISO 27001 Management Responsibilities Explained – Control 5.4

ISO 27001:2022 Annex A 5.4 | Management Responsibilities Beginner’s Guide

Information security programmes rarely fail because policies are missing. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft spotless security policies only to fail completely because management behaviour did not match stated intent. When executives demand exception passes around Multi-Factor Authentication (MFA),

ISO 27001:2022 Annex A 5.4 | Management Responsibilities Beginner’s Guide Read More »

ISO 27001 Contact with Special Interest Groups Explained – Control 5.6

ISO 27001:2022 Annex A 5.6 | Contact with Special Interest Groups Beginner’s Guide

Information security does not exist in isolation. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations build their security controls in a complete vacuum, relying entirely on internal guesswork or static textbooks while the rest of their industry sector is actively adapting to

ISO 27001:2022 Annex A 5.6 | Contact with Special Interest Groups Beginner’s Guide Read More »

ISO 27001 Threat Intelligence Explained – Control 5.7

ISO 27001:2022 Annex A 5.7 | Threat Intelligence Beginner’s Guide

Threats change faster than most static control sets. Over my 30 years in governance, risk, and compliance, I have seen far too many small businesses, startups, and tech firms build their security controls around outdated 10-year-old threat assumptions or generic compliance checklists—completely oblivious to the active, real-world attack techniques targeting

ISO 27001:2022 Annex A 5.7 | Threat Intelligence Beginner’s Guide Read More »

ISO 27001 Information Security in Project Management Explained – Control 5.8

ISO 27001:2022 Annex A 5.8 | Information Security in Project Management Beginner’s Guide

Many security weaknesses are introduced during change, not day-to-day operations. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in securing existing production environments, only to allow project teams to launch new software platforms, migrate core databases to the cloud, or

ISO 27001:2022 Annex A 5.8 | Information Security in Project Management Beginner’s Guide Read More »

ISO 27001 Inventory of Information and Other Associated Assets Explained – Control 5.9

ISO 27001:2022 Annex A 5.9 | Inventory of Information and Other Associated Assets Beginner’s Guide

You cannot protect what you do not know you have. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in advanced cyber defenses while remaining completely blind to unmapped cloud storage buckets, orphaned databases, legacy physical servers, or unvetted SaaS applications

ISO 27001:2022 Annex A 5.9 | Inventory of Information and Other Associated Assets Beginner’s Guide Read More »

ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10

ISO 27001:2022 Annex A 5.10 | Acceptable Use of Information and Other Associated Assets Beginner’s Guide

Most information security incidents involve misuse, not technical failure. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in next-gen firewalls, endpoint detection, and complex cloud security tools, only to suffer a disastrous breach because an employee installed unvetted shadow IT

ISO 27001:2022 Annex A 5.10 | Acceptable Use of Information and Other Associated Assets Beginner’s Guide Read More »

ISO 27001 Return of Assets Explained – Control 5.11

ISO 27001:2022 Annex A 5.11 | Return of Assets Beginner’s Guide

Information security risk does not magically end when an employee, contractor, or third-party vendor separates from your business. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations execute swift logical offboarding—disabling Microsoft 365 or Slack accounts—while completely forgetting about the physical company laptop,

ISO 27001:2022 Annex A 5.11 | Return of Assets Beginner’s Guide Read More »

ISO 27001 Identity Management Explained – Control 5.16

ISO 27001:2022 Annex A 5.16 | Identity Management Beginner’s Guide

Identity is the fundamental gateway to access. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in firewalls, endpoint detection, and data loss prevention while leaving their front door wide open through chaotic identity management. Unmanaged identity sprawl—orphaned contractor accounts, duplicate

ISO 27001:2022 Annex A 5.16 | Identity Management Beginner’s Guide Read More »

ISO 27001 Information Security in Supplier Relationships Explained – Control 5.19

ISO 27001:2022 Annex A 5.19 | Information Security in Supplier Relationships Beginner’s Guide

Your security posture is only as strong as your weakest supplier relationship. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations build ironclad internal perimeters, only to hand over global administrative credentials, unencrypted customer databases, or direct network connections to unvetted third-party suppliers.

ISO 27001:2022 Annex A 5.19 | Information Security in Supplier Relationships Beginner’s Guide Read More »

ISO 27001 Addressing Information Security Within Supplier Agreements Explained – Control 5.20

ISO 27001:2022 Annex A 5.20 | Addressing Information Security Within Supplier Agreements Beginner’s Guide

Supplier risk is rarely caused by bad intent—it is caused by unclear expectations. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal verbal promises, glossy vendor marketing claims, or generic commercial purchase orders that contain zero security language. When a

ISO 27001:2022 Annex A 5.20 | Addressing Information Security Within Supplier Agreements Beginner’s Guide Read More »

ISO 27001 Managing Information Security in the ICT Supply Chain Explained – Control 5.21

ISO 27001:2022 Annex A 5.21 | Managing Information Security in the ICT Supply Chain Beginner’s Guide

ICT supply chains introduce risk long before systems go live. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations carefully configure their internal firewalls and cloud environments, only to inherit devastating vulnerabilities, backdoors, or malicious code through unvetted third-party software libraries, compromised hardware

ISO 27001:2022 Annex A 5.21 | Managing Information Security in the ICT Supply Chain Beginner’s Guide Read More »

ISO 27001 Monitoring, Review and Change Management of Supplier Services Explained – Control 5.22

ISO 27001:2022 Annex A 5.23 | Monitoring, Review and Change Management of Supplier Services Beginner’s Guide

Supplier risk does not stay static. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations conduct a rigorous security assessment during supplier onboarding, sign a tight contract, and then completely ignore the vendor for three years. In the meantime, the supplier migrates its

ISO 27001:2022 Annex A 5.23 | Monitoring, Review and Change Management of Supplier Services Beginner’s Guide Read More »

ISO 27001 Information Security for Use of Cloud Services Explained – Control 5.23

ISO 27001:2022 Annex A 5.23 | Information Security for Use of Cloud Services Beginner’s Guide

Cloud services change the control boundary, not the responsibility. Over my 30 years in governance, risk, and compliance, I have seen far too many small businesses, startups, and tech teams adopt SaaS, PaaS, and IaaS platforms under the dangerous assumption that AWS, Azure, Google Cloud, or Microsoft 365 handles “all

ISO 27001:2022 Annex A 5.23 | Information Security for Use of Cloud Services Beginner’s Guide Read More »

ISO 27001 Information Security Incident Management Planning and Preparation Explained – Control 5.24

ISO 27001:2022 Annex A 5.24 | Information Security Incident Management Planning and Preparation Beginner’s Guide

Incidents rarely fail because teams don’t try hard enough—they fail because planning happened too late. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations wait until ransomware is actively encrypting their file servers or customer data is leaking onto the web before trying

ISO 27001:2022 Annex A 5.24 | Information Security Incident Management Planning and Preparation Beginner’s Guide Read More »

ISO 27001 Assessment and Decision on Information Security Events Explained – Control 5.25

ISO 27001:2022 Annex A 5.25 | Assessment and Decision on Information Security Events Beginner’s Guide

Not every security event is an incident, but failing to recognize the difference creates massive risk. Over my 30 years in governance, risk, and compliance, I have seen far too many organizations fall into two extreme traps: either treating every single automated SIEM ping or minor spam email as a

ISO 27001:2022 Annex A 5.25 | Assessment and Decision on Information Security Events Beginner’s Guide Read More »

ISO 27001 Response to Information Security Incidents Explained – Control 5.26

ISO 27001:2022 Annex A 5.26 | Response to Information Security Incidents Beginner’s Guide

Incident response is where preparation is tested under pressure. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations write comprehensive disaster recovery plans and incident playbooks, only to panic when a real-world breach occurs—improvising containment steps, leaking unverified information to the media, destroying

ISO 27001:2022 Annex A 5.26 | Response to Information Security Incidents Beginner’s Guide Read More »

ISO 27001 Learning From Information Security Incidents Explained – Control 5.27

ISO 27001:2022 Annex A 5.27 | Learning From Information Security Incidents Beginner’s Guide

Incidents only become valuable when organisations actually learn from them. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rush through incident containment and recovery, issue a quick patch, and close the ticket—only to suffer the exact same breach three months later. Closing

ISO 27001:2022 Annex A 5.27 | Learning From Information Security Incidents Beginner’s Guide Read More »

ISO 27001 Collection of Evidence Explained – Control 5.28

ISO 27001:2022 Annex A 5.28 | Collection of Evidence Beginner’s Guide

When security incidents escalate, evidence quality determines outcomes. Over my 30 years in governance, risk, and compliance, I have seen far too many incident response teams rush to reboot compromised servers, restore backups, or wipe infected drives to restore uptime, completely destroying volatile forensic memory in the process. When you

ISO 27001:2022 Annex A 5.28 | Collection of Evidence Beginner’s Guide Read More »

ISO 27001 Information Security During Disruption Explained – Control 5.29

ISO 27001:2022 Annex A 5.29 | Information Security During Disruption Beginner’s Guide

Disruption changes operational priorities, but security must never be sacrificed in the chaos. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations manage a major crisis—whether a physical disaster, a network outage, or a cyber incident—by completely disabling core security controls just to

ISO 27001:2022 Annex A 5.29 | Information Security During Disruption Beginner’s Guide Read More »

ISO 27001 ICT Readiness for Business Continuity Explained – Control 5.30

ISO 27001:2022 Annex A 5.30 | ICT Readiness for Business Continuity Beginner’s Guide

When disruption strikes, your ICT capability determines how quickly your business recovers—or if it recovers at all. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations confuse basic data backups with true business continuity. Having an off-site tape or cloud snapshot means nothing

ISO 27001:2022 Annex A 5.30 | ICT Readiness for Business Continuity Beginner’s Guide Read More »

ISO 27001 Legal, Statutory, Regulatory and Contractual Requirements Explained – Control 5.31

ISO 27001:2022 Annex A 5.31 | Legal, Statutory, Regulatory and Contractual Requirements Beginner’s Guide

Information security obligations do not exist in isolation. They are shaped, bounded, and enforced by law, regulation, and contract. Over my 30 years in governance, risk, and compliance, I have seen far too many security teams design technically brilliant architectures that completely fail in practice because they ignored the legal

ISO 27001:2022 Annex A 5.31 | Legal, Statutory, Regulatory and Contractual Requirements Beginner’s Guide Read More »

ISO 27001 Independent Review of Information Security Explained – Control 5.35

ISO 27001:2022 Annex A 5.35 | Independent Review of Information Security Beginner’s Guide

Security programmes drift when they are never challenged. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations fall into the trap of self-validation, assuming that because their internal IT team built a control, it must be running effectively. Over time, operational shortcuts become

ISO 27001:2022 Annex A 5.35 | Independent Review of Information Security Beginner’s Guide Read More »

ISO 27001 Compliance with Policies, Rules, and Standards Explained – Control 5.36

ISO 27001:2022 Annex A 5.36 | Compliance with Policies, Rules, and Standards Beginner’s Guide

Security controls only work if people actually follow them. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft immaculate, comprehensive security policies, stick them in a PDF on an obscure intranet page, and assume that documentation equals protection. Write-and-forget policies are useless.

ISO 27001:2022 Annex A 5.36 | Compliance with Policies, Rules, and Standards Beginner’s Guide Read More »

ISO 27001 Information Security Awareness Explained – Control 6.3

ISO 27001:2022 Annex A 6.3 | Information Security Awareness Beginner’s Guide

Security controls fail most often through human misunderstanding, not technical weakness. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in firewalls, SIEM platforms, and zero-trust tools, only to run an uninspiring 45-minute slide deck once a year during onboarding and

ISO 27001:2022 Annex A 6.3 | Information Security Awareness Beginner’s Guide Read More »

ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5

ISO 27001:2022 Annex A 6.5 | Responsibilities After Termination or Change of Employment Beginner’s Guide

The risk does not end when someone leaves your business. In many cases, it increases dramatically. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run smooth technical onboarding processes, only to completely fumble off boarding, leaving active credentials assigned to departed contractors,

ISO 27001:2022 Annex A 6.5 | Responsibilities After Termination or Change of Employment Beginner’s Guide Read More »

ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6

ISO 27001:2022 Annex A 6.6 | Confidentiality or Non-disclosure Agreements Beginner’s Guide

Confidential information only stays confidential if expectations are clear and legally enforceable. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal trust, handshakes, or generic, copy-pasted templates when sharing high-value IP, customer databases, or trade secrets with staff, contractors, and

ISO 27001:2022 Annex A 6.6 | Confidentiality or Non-disclosure Agreements Beginner’s Guide Read More »

ISO 27001 Securing Offices, Rooms and Facilities Explained – Control 7.3

ISO 27001:2022 Annex A 7.3 | Securing Offices, Rooms and Facilities Beginner’s Guide

Once someone is inside the building, security failure becomes a proximity problem. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in front-desk reception turnstiles and perimeter keycards, only to leave internal server closets unlocked, HR offices open to casual visitors,

ISO 27001:2022 Annex A 7.3 | Securing Offices, Rooms and Facilities Beginner’s Guide Read More »

ISO 27001 Protecting Against Physical and Environmental Threats Explained – Control 7.5

ISO 27001:2022 Annex A 7.5 | Protecting Against Physical and Environmental Threats Beginner’s Guide

Not all security threats are digital. Some arrive as fire, water ingress, extreme heat, power surges, or civil disruption. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses build military-grade firewalls and zero-trust software architectures while completely ignoring physical reality, like placing primary

ISO 27001:2022 Annex A 7.5 | Protecting Against Physical and Environmental Threats Beginner’s Guide Read More »

ISO 27001 Protection Against Malware Explained – Control 8.7

ISO 27001:2022 Annex A 8.7 | Protection Against Malware Beginner’s Guide

Malware rarely announces itself. It blends into everyday emails, innocent file downloads, compromised software updates, and routine maintenance until systems stop working, files are encrypted, or data is quietly exfiltrated. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses place blind, absolute faith

ISO 27001:2022 Annex A 8.7 | Protection Against Malware Beginner’s Guide Read More »

ISO 27001 Management of Technical Vulnerabilities Explained – Control 8.8

ISO 27001:2022 Annex A 8.8 | Management of Technical Vulnerabilities Beginner’s Guide

No system is ever completely vulnerability-free. The real risk comes from not knowing what weaknesses exist, or reacting too slowly when you do. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations treat vulnerability management as an occasional, reactive firefighting exercise. They run

ISO 27001:2022 Annex A 8.8 | Management of Technical Vulnerabilities Beginner’s Guide Read More »

ISO 27001 Redundancy of Information Processing Facilities Explained – Control 8.14

ISO 27001:2022 Annex A 8.14 | Redundancy of Information Processing Facilities Beginner’s Guide

Availability is not achieved by hope. It is achieved by designing systems that continue to operate when something fails. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses suffer catastrophic downtime because they assumed their systems were redundant simply because they were in

ISO 27001:2022 Annex A 8.14 | Redundancy of Information Processing Facilities Beginner’s Guide Read More »

ISO 27001 Use of Privileged Utility Programs Explained – Control 8.18

ISO 27001:2022 Annex A 8.18 | Use of Privileged Utility Programs Beginner’s Guide

Utility programs are powerful by design. That power is exactly why they need tighter control than ordinary software. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations leave administrative utilities, system diagnostics, and low-level disk tools sitting openly on production servers for “convenience.”

ISO 27001:2022 Annex A 8.18 | Use of Privileged Utility Programs Beginner’s Guide Read More »

ISO 27001 Installation of Software on Operational Systems Explained – Control 8.19

ISO 27001:2022 Annex A 8.19 | Installation of Software on Operational Systems Beginner’s Guide

Most serious production outages do not start with clever external attackers. They start with uncontrolled software changes inside live environments. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses let well-meaning engineers or staff apply “quick updates,” unapproved utilities, or untested patches directly

ISO 27001:2022 Annex A 8.19 | Installation of Software on Operational Systems Beginner’s Guide Read More »

ISO 27001 Application Security Requirements Explained – Control 8.26

ISO 27001:2022 Annex A 8.26 | Application Security Requirements Beginner’s Guide

Applications are where your data lives, where decisions are made, and where money changes hands. Over my 30 years in governance, risk, and compliance, I have seen organisations deploy state-of-the-art firewalls and hardware encryption, only to get completely ruined because their core web application lacked basic security rules. If your

ISO 27001:2022 Annex A 8.26 | Application Security Requirements Beginner’s Guide Read More »

ISO 27001 Secure Systems Architecture and Engineering Principles Explained – Control 8.27

ISO 27001:2022 Annex A 8.27 | Secure Systems Architecture and Engineering Principles Beginner’s Guide

Most security failures are not caused by missing security tools. They are caused by poor design decisions made early and never revisited. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses bolt expensive security appliances onto a fundamentally flawed network design, only for

ISO 27001:2022 Annex A 8.27 | Secure Systems Architecture and Engineering Principles Beginner’s Guide Read More »

ISO 27001 Security Testing in Development and Acceptance Explained – Control 8.29

ISO 27001:2022 Annex A 8.29 | Security Testing in Development and Acceptance Beginner’s Guide

Most security failures are discovered after deployment, when fixing them is slow, expensive, and disruptive. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run comprehensive tests on software functionality, only to go live with massive security holes because no one bothered to

ISO 27001:2022 Annex A 8.29 | Security Testing in Development and Acceptance Beginner’s Guide Read More »

ISO 27001 Separation of Development, Test and Production Environments Explained – Control 8.31

ISO 27001:2022 Annex A 8.31 | Separation of Development, Test and Production Environments Beginner’s Guide

Many major security incidents are not complex, external cyber attacks. They are simple, accidental changes made in the wrong environment. Over my 30 years in governance, risk, and compliance, I have seen developers accidentally drop a database or release unverified code simply because they thought they were connected to a

ISO 27001:2022 Annex A 8.31 | Separation of Development, Test and Production Environments Beginner’s Guide Read More »

ISO 27001 Protection of Information Systems During Audit Testing Explained – Control 8.34

ISO 27001:2022 Annex A 8.34 | Protection of Information Systems During Audit Testing Beginner’s Guide

Audits are supposed to reduce risk. Handled badly, they create it. Over my 30 years in governance, risk, and compliance, I have seen plenty of well-meaning auditors accidentally cause system outages or extract sensitive data without proper controls. Uncontrolled audit testing is a security incident waiting to happen. ISO 27001:2022

ISO 27001:2022 Annex A 8.34 | Protection of Information Systems During Audit Testing Beginner’s Guide Read More »