Contents

 

Acknowledgments

About the author

AI statement

Introduction

1 Bridging the gap: Why ISO 27001 isn’t just for techies

About this book

How to use this book

Why are you here— And how this book can help

2 ISO— Order in a chaotic world: Why ISO exists, and why ISO 27001 has become so important

ISO: A short history

How ISO standards are born

What ISO standards really do

Types of ISO standards

The one that protects them all

Quiz #1

3 Building an ISMS that works: How ISO/ IEC 27001 became the framework of choice

What is information security (really)?

What is an information security management system?

What makes an ISMS work?

Key principles that support an effective ISMS

Why organizations need an ISMS

How ISO 27001 fits in

Why ISO 27001 matters

Brief history of ISO 27001

Meet the family: ISO/ IEC 27000 series

Know the standards, use them well

Quiz #2

4 The backbone of ISO/ IEC 27001, structure and strategy: How harmonized structure, process thinking, and risk focus shape the standard

Introduction: So far, so good?

Why structure matters in standards

The harmonized clause structure

A little secret about all ISO standards

Why Clauses 4– 10 matter so much

So, why are these clauses so important?

You can’t pick and choose

Not all clauses are created equal

Process-​based thinking: Seeing the bigger picture

Why does this matter for ISO 27001?

PDCA and the process approach: The engine behind the ISMS

A quick trip back in time: Meet Mr. Deming

PDCA in ISO 27001: The hidden map

PDCA + process thinking = Your ISMS in action

Risk-​based thinking: The real reason ISO 27001 exists

Follow the risk, not the routine

So, what is risk-​based thinking?

Risk is not just a section— It’s the theme

Quiz #3

5 Terms you’ll hear again and again: Clarifying the core terms that shape an effective ISMS

ISO/ IEC 27000: The vocabulary standard

Core ISMS terms you’ll encounter often

Quiz #4

6 What you must deliver and document: Understanding ISMS requirements and documentation needs

Where do ISMS requirements come from?

Requirement ≠ Documentation— But one often leads to the other

ISO/ IEC 27001:2022— Mandatory documents you need

Building your ISMS documentation framework early

The danger of copy– paste compliance

Clause 7.5.2: Documented information that works

Clause 7.5.3: Controlling what you create

ISMS documentation template

Quiz #5

Answer key: Implementation Task 1

7 From Gap to Gantt, your ISMS project starts here: Assess where you stand— Then plan the journey with purpose

Why Gap Analysis is the first real step

Gantt chart

Quiz #6

Case 1: The data fortress in Nairobi

8 Clause 4— Understand your world before you secure it: Mapping context, interested parties, and scope for a strong ISMS foundation

Introduction

Guiding principles for every clause

Why context matters in ISO 27001

Clause 4.1: Understanding the organization and its context

Clause 4.2: Understanding the needs and expectations of interested parties

Understanding the climate-​change amendment

Clause 4.3: Determining the scope of the ISMS

Clause 4.4: Information security management system

Quiz #7

Case 2: Monsoons, markets, and messy Chennai politics

9 Clause 5— Leadership isn’t optional: Setting direction, roles, and commitment for information security success

Clause 5.1: Leadership and commitment

Clause 5.2: Policy

Clause 5.3: Organizational roles, responsibilities, and authorities

Quiz #8

Case 3: Leadership on the line— Abu Dhabi

10 Clause 6— Plan your risks, control your future: Mastering risk

management and the statement of applicability

Beyond this chapter: Where to learn more about risk

A quick refresher: Risk management

Clause 6.1: Actions to address risks and opportunities

Clause 6.1.2: Information security risk assessment

Clause 6.1.3: Information security risk treatment

Clause 6.2: Information security objectives and planning to achieve them

Clause 6.3: Planning of changes

Quiz #9

Case 4: Planning in motion— Singapore

11 Clause 7— Empower your people, manage your info: Building competence, awareness, and communication for a strong ISMS

Introduction

Clause 7.1: Resources

Clause 7.2: Competence

Clause 7.3: Awareness

Clause 7.4: Communication

Clause 7.5: Documented information

Quiz #10

Case 5: Culture, calls, and quiet change— Hyderabad

12 Clause 8— Put your ISMS into action: Implementing controls and avoiding common pitfalls

Introduction

Clause 8.1: Operational planning and control

Clause 8.2: Information security risk assessment

Clause 8.3: Information security risk treatment

Quiz #11

Case 6: Risk, rollouts, and reality— Lagos

13 Clause 9— Is it working? Evaluate and improve: Measuring performance, auditing, and management review

Clause 9.1 Monitoring, measurement, analysis, and evaluation

Clause 9.2 Internal audit

Clause 9.3 Management review

Quiz #12

Case 7: Wheels, audits, and wake-​up calls— Kigali

14 Clause 10— Get better, stay better: Handling nonconformities, corrective actions, and continual improvement

Clause 10.1 Continual improvement

Clause 10.2 Nonconformity and corrective action

Quiz #13

Case 8: A loop of fixes— London

15 Preparing for ISO 27001 certification: What auditors want and how to pass with confidence

Why consider ISO 27001 certification?

Choosing the right ISO 27001 certification body

Understanding the ISO 27001 3-​year certification cycle

Your ISO 27001 journey— The road ahead

16 Practice paper: Test what you’ve learned

17 Quiz compass

18 Case answer key and reflections

19 Practice paper: Answers and explanations

Bibliography