THE ISMS FOUNDATION
Security controls work better when ownership is clear
Policies, security tools, risk registers, and audit records often develop separately. That makes it difficult to see whether security decisions support the same objectives or whether identified risks are being managed consistently.
An ISMS brings those activities into one governed system. It defines scope, responsibilities, risk criteria, treatment decisions, evidence requirements, and the process used to review performance.
Digisecuritas helps organisations build that structure around their real business environment rather than a generic document set.
ISMS SCOPE
A clear scope prevents gaps and unnecessary complexity
The ISMS scope determines where requirements apply, which risks must be assessed, and what evidence will be examined. It should reflect the organisation's services, dependencies, information flows, and operating model.
CLAUSES 4 TO 10
The standard connects leadership, risk, operation, and review
Understand the organisation, interested parties, relevant requirements, and the boundaries of the Information Security Management System.
Key outputs
RISK BASED MANAGEMENT
Every selected control should connect to a risk decision
ISO/IEC 27001 requires a structured approach to information security risk assessment and treatment. The process must be repeatable, documented, and aligned with the organisation's risk criteria.
Identify information and dependencies
Determine which information, processes, systems, people, facilities, and suppliers support the defined ISMS scope.
Assess risks
Evaluate relevant threats, vulnerabilities, consequences, likelihood, existing controls, and risk levels.
Decide treatment
Choose whether to reduce, avoid, share, or accept each assessed risk.
Select controls
Determine the controls required to support treatment decisions and compare them with Annex A.
Record and approve
Document residual risk, treatment ownership, target dates, and the appropriate approval.
CONTROL JUSTIFICATION
The Statement of Applicability explains the organisation's control choices
The Statement of Applicability, or SoA, records which Annex A controls are applicable, why they are included, whether they have been implemented, and why any controls are excluded.
It should connect the risk assessment with the organisation's treatment decisions and current control environment. A copied control list cannot provide that connection.
The SoA should reflect the organisation's risks, scope, and actual safeguards.
| Control reference | Applicable | Justification | Status | Evidence |
|---|---|---|---|---|
| Sample control | Yes | Supports identified risk treatment | Implemented | Policy and review record |
| Sample control | Yes | Required by customer agreement | In progress | Approved action plan |
| Sample control | No | Activity is outside the ISMS scope | Excluded | Scope justification |
The final SoA must be based on the organisation's licensed copy of the standard and documented risk treatment process.
ANNEX A
Four control themes support risk treatment
ISO/IEC 27001:2022 Annex A contains 93 reference controls grouped into four themes. Organisations select controls according to their assessed risks, obligations, and treatment decisions.
Organisational controls
Governance, policies, responsibilities, supplier relationships, asset management, incident preparation, continuity, legal obligations, and assurance activities.
People controls
Screening, employment responsibilities, awareness, training, remote work, confidentiality, and responsibilities when employment changes.
Physical controls
Facility boundaries, entry controls, secure areas, equipment protection, media handling, maintenance, and disposal.
Technological controls
Identity, access, authentication, logging, monitoring, configuration, malware protection, backup, encryption, network security, secure development, and data protection.
Annex A is a reference set. Control selection must follow the organisation's risk treatment process.
OUR SERVICES
Our ISO 27001 services
ISO 27001 gap assessment
Compare the current management system and control environment against applicable ISO/IEC 27001 requirements.
Typical deliverables
ISMS design and implementation support
Define the ISMS structure, scope, governance, risk process, documentation, objectives, and operating responsibilities.
Typical deliverables
Risk assessment and treatment support
Establish a practical risk methodology and help teams document risks, treatment decisions, control requirements, and residual risk.
Typical deliverables
Statement of Applicability development
Create a structured link between risks, treatment decisions, Annex A controls, implementation status, and control evidence.
Typical deliverables
Internal audit and certification readiness
Independently assess whether the ISMS is operating as intended and prepare stakeholders for the external certification process.
Typical deliverables
Unsure whether you need a gap assessment or full implementation support?
Discuss your ISO 27001 scopeISMS DOCUMENTATION
Documentation that supports the ISMS
Documentation should describe real operations and be supported by current evidence.
CONTROL EVIDENCE
Evidence across the control environment
| ISMS area | What we examine | Example evidence |
|---|---|---|
| Governance | Leadership direction and assigned responsibility | Policies, role records, meeting minutes |
| Risk management | Consistency of assessment and treatment decisions | Methodology, risk register, treatment plan |
| Asset and information management | Visibility and ownership of relevant assets | Inventories, classifications, ownership records |
| Access management | Approval and review of user access | Access requests, review records, authentication settings |
| Supplier security | Security expectations and ongoing oversight | Assessments, agreements, monitoring records |
| Incident management | Preparation, escalation, response, and learning | Response plans, case records, lessons learned |
| Business continuity | Resilience of information and supporting services | Recovery plans, test results, corrective actions |
| Performance evaluation | Monitoring, audit, and management review | Metrics, audit reports, review minutes |
| Improvement | Resolution of nonconformities and recurring issues | Root cause records, corrective action evidence |
CERTIFICATION PATHWAY
The road to certification
Define and plan
Confirm scope, leadership responsibilities, risk methodology, implementation plan, and required resources.
Build and operate
Implement the management system, operate selected controls, and retain appropriate evidence.
Review and correct
Complete monitoring, internal audit, management review, and corrective actions.
Stage 1 audit
The selected certification body reviews ISMS documentation, scope, and preparedness for the main assessment.
Stage 2 audit
The certification body evaluates implementation and the effectiveness of the management system.
Surveillance and improvement
The organisation maintains the ISMS, addresses changes, completes periodic reviews, and participates in surveillance audits.
ISO/IEC 27001 certification is awarded by an independent certification body. Digisecuritas provides consulting, internal audit, gap assessment, and certification readiness support.
ENGAGEMENT TRIGGERS
When organisations need ISO 27001 support
Preparing for first certification
Build an ISMS, organise documentation, test operating controls, and address gaps before engaging a certification body.
Responding to customer requirements
Provide stronger evidence of security governance during enterprise procurement, vendor reviews, and contractual discussions.
Rebuilding an ineffective ISMS
Replace disconnected templates and outdated registers with processes that reflect current operations and risks.
Managing organisational change
Review the ISMS after acquisitions, new services, cloud migration, geographic expansion, technology changes, or material supplier changes.
An ISMS must work between audits
Digisecuritas approaches ISO/IEC 27001 as a security management programme. We connect formal requirements with existing business processes, technology, ownership, evidence, and risk decisions.
The result is an ISMS that teams can operate and leadership can review.
FREQUENTLY ASKED QUESTIONS
Common questions about ISO/IEC 27001
Build an ISMS that stands up to scrutiny
Understand your ISO 27001 gaps, organise your implementation priorities, and prepare for independent certification with greater clarity.
