Contents
Acknowledgments
About the author
AI statement
Introduction
1 Bridging the gap: Why ISO 27001 isn’t just for techies
About this book
How to use this book
Why are you here— And how this book can help
2 ISO— Order in a chaotic world: Why ISO exists, and why ISO 27001 has become so important
ISO: A short history
How ISO standards are born
What ISO standards really do
Types of ISO standards
The one that protects them all
Quiz #1
3 Building an ISMS that works: How ISO/ IEC 27001 became the framework of choice
What is information security (really)?
What is an information security management system?
What makes an ISMS work?
Key principles that support an effective ISMS
Why organizations need an ISMS
How ISO 27001 fits in
Why ISO 27001 matters
Brief history of ISO 27001
Meet the family: ISO/ IEC 27000 series
Know the standards, use them well
Quiz #2
4 The backbone of ISO/ IEC 27001, structure and strategy: How harmonized structure, process thinking, and risk focus shape the standard
Introduction: So far, so good?
Why structure matters in standards
The harmonized clause structure
A little secret about all ISO standards
Why Clauses 4– 10 matter so much
So, why are these clauses so important?
You can’t pick and choose
Not all clauses are created equal
Process-based thinking: Seeing the bigger picture
Why does this matter for ISO 27001?
PDCA and the process approach: The engine behind the ISMS
A quick trip back in time: Meet Mr. Deming
PDCA in ISO 27001: The hidden map
PDCA + process thinking = Your ISMS in action
Risk-based thinking: The real reason ISO 27001 exists
Follow the risk, not the routine
So, what is risk-based thinking?
Risk is not just a section— It’s the theme
Quiz #3
5 Terms you’ll hear again and again: Clarifying the core terms that shape an effective ISMS
ISO/ IEC 27000: The vocabulary standard
Core ISMS terms you’ll encounter often
Quiz #4
6 What you must deliver and document: Understanding ISMS requirements and documentation needs
Where do ISMS requirements come from?
Requirement ≠ Documentation— But one often leads to the other
ISO/ IEC 27001:2022— Mandatory documents you need
Building your ISMS documentation framework early
The danger of copy– paste compliance
Clause 7.5.2: Documented information that works
Clause 7.5.3: Controlling what you create
ISMS documentation template
Quiz #5
Answer key: Implementation Task 1
7 From Gap to Gantt, your ISMS project starts here: Assess where you stand— Then plan the journey with purpose
Why Gap Analysis is the first real step
Gantt chart
Quiz #6
Case 1: The data fortress in Nairobi
8 Clause 4— Understand your world before you secure it: Mapping context, interested parties, and scope for a strong ISMS foundation
Introduction
Guiding principles for every clause
Why context matters in ISO 27001
Clause 4.1: Understanding the organization and its context
Clause 4.2: Understanding the needs and expectations of interested parties
Understanding the climate-change amendment
Clause 4.3: Determining the scope of the ISMS
Clause 4.4: Information security management system
Quiz #7
Case 2: Monsoons, markets, and messy Chennai politics
9 Clause 5— Leadership isn’t optional: Setting direction, roles, and commitment for information security success
Clause 5.1: Leadership and commitment
Clause 5.2: Policy
Clause 5.3: Organizational roles, responsibilities, and authorities
Quiz #8
Case 3: Leadership on the line— Abu Dhabi
10 Clause 6— Plan your risks, control your future: Mastering risk
management and the statement of applicability
Beyond this chapter: Where to learn more about risk
A quick refresher: Risk management
Clause 6.1: Actions to address risks and opportunities
Clause 6.1.2: Information security risk assessment
Clause 6.1.3: Information security risk treatment
Clause 6.2: Information security objectives and planning to achieve them
Clause 6.3: Planning of changes
Quiz #9
Case 4: Planning in motion— Singapore
11 Clause 7— Empower your people, manage your info: Building competence, awareness, and communication for a strong ISMS
Introduction
Clause 7.1: Resources
Clause 7.2: Competence
Clause 7.3: Awareness
Clause 7.4: Communication
Clause 7.5: Documented information
Quiz #10
Case 5: Culture, calls, and quiet change— Hyderabad
12 Clause 8— Put your ISMS into action: Implementing controls and avoiding common pitfalls
Introduction
Clause 8.1: Operational planning and control
Clause 8.2: Information security risk assessment
Clause 8.3: Information security risk treatment
Quiz #11
Case 6: Risk, rollouts, and reality— Lagos
13 Clause 9— Is it working? Evaluate and improve: Measuring performance, auditing, and management review
Clause 9.1 Monitoring, measurement, analysis, and evaluation
Clause 9.2 Internal audit
Clause 9.3 Management review
Quiz #12
Case 7: Wheels, audits, and wake-up calls— Kigali
14 Clause 10— Get better, stay better: Handling nonconformities, corrective actions, and continual improvement
Clause 10.1 Continual improvement
Clause 10.2 Nonconformity and corrective action
Quiz #13
Case 8: A loop of fixes— London
15 Preparing for ISO 27001 certification: What auditors want and how to pass with confidence
Why consider ISO 27001 certification?
Choosing the right ISO 27001 certification body
Understanding the ISO 27001 3-year certification cycle
Your ISO 27001 journey— The road ahead
16 Practice paper: Test what you’ve learned
17 Quiz compass
18 Case answer key and reflections
19 Practice paper: Answers and explanations
Bibliography