Knowledge / frameworks

ISO/IEC 27001

A management system standard. The certificate is proof you run the system, not that you are unbreachable.

ISO/IEC 27001 PDCAPlanSoA + riskDooperateCheckauditActimproveAnnex A controls are a menu, not a shopping list

ISO/IEC 27001 specifies an information security management system: scope, risk assessment, Statement of Applicability, internal audit, management review, improvement.

Annex A is a menu of controls. Treating it as a shopping list is how you get 114 tick-boxes and an open RDP server.

Useful when customers demand it. Insufficient alone for Australian government work, where ISM and Essential Eight still apply.