An organization’s information is nolonger confined to its server room.
It may exist in:
Email systems
- Enterprise Resource Planning (ERP) systems
- Customer Relationship Management (CRM) systems
- Mobile devices
- Cloud services
- Human resources files
- Customer databases
- Contracts
Financial information
- Software source code
- Backup copies
- Devices used by employees and suppliers
- Information security therefore cannotbe reduced to:
Firewall + Antivirus + ITDepartment
The challenge is much broader.
Organizations must answer questionssuch as:
Who can access the information?
- How are access rights determined?
- What happens when an employee leaves?
- How is information held by a cloud service provider managed?
- Can information be restored after an incident?
- Who reports an information-security incident?
- Which information is most sensitive?
- Which risks will management accept, and which must be treated?
- This is where ISO/IEC 27001becomes relevant.
ISO/IEC 27001 is an InternationalStandard that specifies requirements for establishing, implementing,
maintaining, and continually improving an Information Security ManagementSystem (ISMS). It adopts a risk-management approach that can be adapted tothe organization’s size, needs, and context.
What Is the Current Edition ofISO/IEC 27001?
As of 17 August 2026, thecurrent published edition is:
ISO/IEC 27001:2022
It was published in October 2022 andhas an amendment addressing climate-action changes:
ISO/IEC 27001:2022/Amd 1:2024
New implementation projects shouldtherefore not be based on:
ISO/IEC 27001:2013
as though it were still the currentedition.
When referring formally tocertification, ISO uses wording such as:
Certified to ISO/IEC 27001:2022.
What Does ISO/IEC 27001 Protect?
The objective is not limited toprotecting digital files.
An Information Security ManagementSystem addresses three fundamental properties of information:
Confidentiality
Information is accessible only toauthorized individuals and entities.
Integrity
Information remains accurate,complete, and protected against unauthorized alteration or destruction.
Availability
Information and systems remainaccessible when required by the organization and authorized parties.
ISO presents these three principles asthe CIA Triad: Confidentiality, Integrity, and Availability.
An information-security risk couldtherefore involve:
Disclosure of a customer database
Unauthorized modification of a financial record
- Deletion of a critical file
- System unavailability
- Loss of a device
- Inappropriate access rights
- Human error
- A third-party supplier failing to manage information securely
- ISO/IEC 27001 Is Not Only an ITProject
- This is one of the most importantprinciples.
If implementation is assigned entirelyto the IT department, it may become a technical project while losing its
organizational and governance dimensions.
ISO explains that information securityrequires a comprehensive approach involving people, policies, processes, andtechnology. Information security should be integrated into theorganization’s operations, information systems, and management controls.
Depending on the organization,implementation will typically require participation from:
Senior management
Information technology
Cybersecurity, where a separate function exists
- Human resources
Legal and compliance
- Procurement
- Operations
- Risk management
- Process and information owners
- Step One: Determine Why You Want toImplement ISO/IEC 27001
- Do not begin with certification.
Begin by defining the business driver.
The organization’s reasons mayinclude:
Reducing information-security risks
Meeting a customer requirement
Qualifying as an approved supplier
- Satisfying a contractual requirement
- Strengthening governance
- Protecting sensitive information
- Supporting regulatory compliance
- Improving organizational maturity
- A clear business driver helpsdetermine the appropriate ISMS scope.
- An ISMS covering an entire technologycompany will differ from one covering a specific cloud service, data center, or
defined group of processes.
Step Two: Conduct a Gap Analysis
Before writing policies, understandwhat already exists.
Compare the organization’s currentarrangements with the requirements of ISO/IEC 27001.
Review areas such as:
Governance
Risk management
Access management
Information and related assets
Human resources
- Physical security
- Supplier management
- Incident management
- Business continuity
Technology controls
- Monitoring
- Internal audit
- Compliance
The Gap Analysis should not becomemerely a:
- Document checklist
The organization must also ask:
- Is the procedure actually implemented?
Do employees understand it?
Is objective evidence available?
Is the control operating effectively?
- The real gap may not be a missingpolicy. It may be an existing access-control system that is never reviewed.
Step Three: Define the ISMS ScopeAccurately
One of the most serious mistakes is towrite:
“All company operations”
without conducting a proper analysis.
The organization must understand:
Products and services
Processes
Locations
Systems
Interfaces
External parties
Information requiring protection
ISO/IEC 27001 allows the ISMS to bedesigned according to the organization’s size, context, and needs, but the
scope must remain clear, justified, and understandable.
Why Is the Scope Important?
The scope determines:
What enters the risk assessment
Which systems are included
Which people and roles are included
Which locations are included
Which suppliers are relevant
- What any future certification will cover
An organization should not choose anartificially narrow scope merely to make certification easier if that scope
does not represent the service on which customers or other interested parties
rely.
Step Four: Understand theOrganization’s Context and Interested Parties
Information security must be connectedto the business.
The organization should ask:
Which services are critical?
Which information do customers depend on?
What contractual obligations apply?
What legal requirements apply?
- Which regulatory bodies are relevant?
- How dependent is the organization on cloud services?
- Which suppliers are critical?
- What would be the effect of a specific system becoming unavailable?
- It should then determine the relevantneeds and expectations of interested parties.
- For example:
- Customers may be concerned with the confidentiality of their data.
Management may prioritize business continuity.
A regulatory authority may impose mandatory requirements.
- A cloud provider may introduce a different operating and responsibility model.
This analysis prevents the ISMS frombecoming detached from the organization’s actual operating environment.
Step Five: Establish ClearInformation-Security Governance
The organization should define:
Who owns the ISMS?
Who approves the information-security policy?
Who owns each risk?
Who has the authority to accept residual risk?
Who manages incidents?
- Who approves access rights?
- Who monitors ISMS performance?
- A common mistake is appointing an:
- Information Security Officer
- and then transferring everyinformation risk to that individual.
A risk associated with the HumanResources system, for example, should not become the sole responsibility of the
information-security function.
The relevant process or asset ownermust participate in the risk decision.
Step Six: Identify Information andRelated Assets
An organization cannot manage therisks associated with something it does not know exists.
However, the asset register should notbecome an unnecessarily large bureaucratic exercise.
The organization should identify whatit needs to understand regarding:
Information
Systems
Devices
Applications
Cloud services
Facilities
Suppliers
Supporting assets
An owner or responsible functionshould be assigned where appropriate.
The central question is:
Which information does theorganization depend on, where is it located, and who can access it?
Step Seven: Classify Information
Not every file requires the same levelof protection.
An organization may establish aclassification model such as:
Public
Internal
Confidential
Highly sensitive
This is only an example. ISO does notimpose this specific classification structure.
The selected classification systemmust be:
Clear
Practical
Applicable
Connected to actual controls
- If a document is classified as“Confidential” but is sent in exactly the same way as a public marketing
brochure, the classification has achieved nothing.
Step Eight: Conduct anInformation-Security Risk Assessment
The risk assessment is the foundationof ISO/IEC 27001.
ISO explains that the standard appliesa risk-management process adapted to the organization’s size and needs.
ISO/IEC 27005:2022 provides specialist guidance on managing information-security risks insupport of an ISMS based on ISO/IEC 27001.
A risk scenario can be consideredthrough the following sequence:
Asset or process → threat or event→ vulnerability or enabling condition → impact → likelihood → risk level →
treatment
For example:
Asset:Email system
Scenario:Compromise of an employee’s account
Potential impact: Unauthorized access to sensitive information and correspondence orfraudulent use of the account
The organization should then examine:
Which controls currently exist?
Is multi-factor authentication in use?
Is employee awareness appropriate?
Is monitoring effective?
What residual risk remains?
Step Nine: Do Not Turn the RiskAssessment into a List of Cyberattacks
- Not every information risk involves ahacker.
The risk could involve:
- An employee sending a file to the wrong recipient
- A lost device
- A supplier discontinuing a service
A backup that cannot be restored
Access rights remaining active after an employee leaves
A data-center outage
Misconfigured cloud storage
- Inability to access critical information
This reflects the purpose of ISO/IEC27001: protecting confidentiality, integrity, and availability, notmerely preventing external attacks.
- Step Ten: Decide How Risks Will BeTreated
After assessing a risk, it is notenough to record:
Risk = High
The organization must make a decision.
Treatment options may include:
Reducing the risk by implementing a control
Avoiding the activity that creates the risk
Changing the way the activity is performed
Sharing or transferring part of the risk contractually or through insurance, where appropriate
- Accepting the risk under clearly defined authority
The decision must be justified andowned by the appropriate person.
What Is Annex A?
ISO/IEC 27001 includes a reference setof information-security controls.
ISO/IEC 27002:2022 provides more detailed guidance on the information-security controlsused to support the ISMS. ISO/IEC 27001 specifies the management-system
requirements, while ISO/IEC 27002 provides control-related guidance and
recommended practices.
The current control set contains 93controls organized into four themes:
Organizational controls
People controls
Physical controls
Technological controls
A common mistake is approaching thecontrols as follows:
“There are 93 controls, so we willimplement all 93 in sequence.”
ISO/IEC 27001 is risk-based.
The controls selected should reflectthe organization’s risks and its legal, contractual, operational, and business
requirements—not merely the completion of a checklist.
What Is a Statement ofApplicability?
The Statement of Applicability(SoA) is one of the most important documents in the ISMS.
In practical terms, it records theorganization’s decisions regarding necessary information-security controls,
their implementation status, and the reasons for including or excluding
relevant reference controls.
The SoA should not be:
A copy of Annex A with “Yes”written beside every control.
The organization should be able totrace the relationship between:
Risk Assessment → Risk Treatment →Controls → Statement of Applicability
If the organization cannot explain whyit selected a control, the system has become a mechanical implementation
exercise rather than a risk-management process.
Step Eleven: Do Not Begin byWriting 40 Policies
Documentation should support thesystem.
Depending on its context, anorganization may need policies or procedures covering areas such as:
Access control
Account and permission management
Incident management
Backup
Supplier management
Acceptable use of devices
Remote working
Cryptography
Change management
Secure development
Disposal of information and devices
The number of policies is not anindicator of maturity.
- A small company may require a simplerdocumentation structure than a large financial or technology institution.
The principle consistent with IAC’smethodology is:
Documentation that can beapplied—not bureaucracy created solely for certification.
Step Twelve: Control Access andPermissions
Access management is one of the areasmost closely connected to daily operations.
The organization should ask:
Who can request access?
Who approves it?
How is business need verified?
How is privileged access managed?
When are access rights reviewed?
What happens when an employee changes roles?
What happens when an employee moves to another department?
What happens during extended leave?
- What happens when the employment relationship ends?
Creating a user account is only thebeginning.
The organization must manage thecomplete identity and access life cycle.
Step Thirteen: Integrate HumanResources with Information Security
Employees are a fundamental part ofthe ISMS before employment, during employment, and when the relationship ends.
Depending on the context, relevantcontrols may address:
Confidentiality obligations
Security awareness
Employee responsibilities
Access management
Incident reporting
Removal of access rights upon departure
ISO/IEC 27002 explicitly addressespeople-related security alongside access control, cryptography, and incident
response.
Step Fourteen: Manage Suppliers andCloud Services
- Organizational information may existoutside the organization’s direct technical environment.
When using a:
- Cloud provider
Software-as-a-Service platform
Payroll provider
Software development company
Support provider
Data center
Third party that processes information on behalf of the organization
the organization should ask:
Which information can the supplier access?
What risks are involved?
Which contractual obligations apply?
- How must incidents be reported?
- What requirements apply when the contract ends?
- How will the organization retrieve its data?
- Are subcontractors or downstream providers involved?
Signing a contract with a supplierdoes not remove the associated risk from the organization’s ISMS.
- Step Fifteen: Design anIncident-Management Process
An information-security incidentshould not begin with the question:
Who should we call?
The organization should define inadvance:
- How incidents are reported
- Who classifies them
Who leads the response
Who decides whether escalation is required
When Legal or senior management should become involved
How evidence is preserved
How communication is managed
How lessons are identified after the incident
ISO/IEC 27002 includesinformation-security incident management and response among the control areas
supporting the ISMS.
Step Sixteen: Connect InformationSecurity with Business Continuity
- Backup is not the same as businesscontinuity.
A backup may be intact whilerestoration takes longer than the organization can tolerate.
The organization should therefore ask:
Which services are critical?
Which systems support those services?
What are the relevant dependencies?
Has restoration been tested?
Who decides when an alternative arrangement should be activated?
Is a cyberattack included among the organization’s disruption scenarios?
Where appropriate, ISO/IEC 27001 canbe aligned with an ISO 22301 Business Continuity Management System.
- Step Seventeen: Test Backups
The statement:
“We have backups.”
is not sufficient.
The more important question is:
Have we restored them successfully?
The organization should review:
- What is included in the backup?
- How frequently is it copied?
What happens when the backup process fails?
How are backup copies protected?
Who can access them?
When was restoration last tested successfully?
A control that has never been testedmay create a stronger sense of security than the protection it actually
provides.
Step Eighteen: Build AwarenessInstead of Delivering a Token Annual Course
- Security awareness should not bereduced to a PowerPoint presentation delivered once a year.
Employees should understand:
- How to handle information
- How to recognize suspicious communications
How to report a concern
The rules governing account use
What to do if a device is lost
Their responsibility for protecting information
Awareness programs may need to differby role.
A software developer requiresdifferent awareness from an employee in Human Resources, Finance, or Customer
Service.
- Step Nineteen: Identify ApplicableJordanian Compliance Requirements
A clear distinction must bemaintained:
ISO/IEC 27001 is an InternationalStandard, and the decision to pursue certification is voluntary unless another
obligation makes it necessary.
By contrast:
Applicable Jordanian laws,regulations, instructions, and mandatory controls must be followed when they
apply to the organization.
The National Cyber Security Centercurrently lists legislation and regulatory instruments including:
Cybersecurity Law No. 16 of 2019
Instructions for the Classification of Cybersecurity Incidents for 2023 and their amendments
Cybersecurity Service Providers Licensing Regulation for 2024
Instructions concerning violations of the Cybersecurity Law for 2025
Cybercrime Law
Personal Data Protection Law
The Center also publishes the JordanNational Cybersecurity Framework, together with its components, activitymaps, and controls.
- Official material published by theCenter explains that Article 8 of Cybersecurity Law No. 16 of 2019 is
associated with the obligation of relevant entities to follow the policies,
standards, and controls issued by the Center for each sector.
A Jordanian ISMS should thereforeinclude a Legal and Regulatory Register reflecting the requirements thatgenuinely apply to the organization and its sector.
How Does Jordan’s Personal DataProtection Law Relate to ISO/IEC 27001?
Jordan’s Personal Data Protection LawNo. 24 of 2023 entered into force on 17 March 2024. The Ministry ofDigital Economy and Entrepreneurship explains that sectors handling personal
data are required to comply with its provisions.
However:
ISO/IEC 27001 is not the same asthe Personal Data Protection Law.
ISO/IEC 27001 helps an organizationmanage information-security risks and related controls.
The Personal Data Protection Lawgoverns rights, responsibilities, and the processing of personal data in
accordance with the law and the regulations and instructions issued under it.
There may be considerable overlapbetween the two, but one does not replace the other.
Organizations requiring a morespecialized framework for privacy information management may also consider ISO/IEC27701:2025 for Privacy Information Management Systems.
Step Twenty: Monitor ISMSPerformance
It is not enough to say:
“We implemented the controls.”
The organization must determine how itwill know whether those controls are working.
Depending on its needs, it may monitorindicators such as:
Time required to close incidents
Percentage of access reviews completed
Status of risk-treatment actions
Percentage of corrective actions closed
Success rate of restoration tests
Results of awareness activities
Other measures connected to the organization’s information risks
The objective is not to maximize thenumber of indicators.
The organization should selectmeasures that help management understand ISMS performance and make informed
decisions.
- Step Twenty-One: Conduct anInternal Audit
Before an external assessment, theorganization should evaluate the system internally.
The audit should not examine policiesalone.
It can begin with an operationalscenario.
For example, an employee has left theorganization.
The auditor can trace whether:
Relevant parties were notified
The employee’s account was disabled
Cloud permissions were removed
The device was returned
Access to external systems was closed
Objective evidence exists
Alternatively, the audit may beginwith an information-security incident:
How was it reported?
How was it classified?
Who handled it?
What corrective action followed?
Did it result in an update to the risk assessment?
This approach reveals how the realsystem operates.
- IAC’s management-system services,including ISO/IEC 27001, include internal audits and compliance reviews.
Step Twenty-Two: Conduct ManagementReview
Information security should not belimited to a report submitted by the IT department.
- Management should receive informationthat supports decisions, including:
- Principal information-security risks
- Incidents
- Control performance
Risk-treatment status
Significant changes
Audit findings
Compliance obligations
Resource requirements
Issues requiring leadership decisions
If senior management seesinformation-security risks only after a major incident, the ISMS has not yet
reached the governance level.
Step Twenty-Three: AddressNonconformities
Suppose an audit finds that thescheduled access review was not performed.
- The organization should not merelycomplete the overdue review.
It should ask:
- Why was the review not completed?
- Was ownership unclear?
- Did the system fail to generate a notification?
Was the scheduled frequency unrealistic?
Was the responsibility omitted from the relevant role?
The appropriate sequence is:
Correct the immediate issue →address the cause → verify effectiveness
This is how the organization builds amanagement system that learns and improves.
When Is an Organization Ready forCertification?
There is no universal threshold suchas:
- “90% readiness.”
An organization is closer to readinesswhen it can demonstrate that:
- The ISMS scope is clear
- Risks have been identified and remain current
- Risk-treatment decisions are documented
Necessary controls are operating
The Statement of Applicability reflects the system’s decisions
Policies and procedures are being used
Personnel understand their responsibilities
Performance is being monitored
An internal audit has been completed
Management has reviewed the system
Significant nonconformities have been addressed
The organization may then engage anindependent certification body if it chooses to pursue certification.
- ISO itself does not certifyorganizations. Certification is voluntary unless required contractually,
legally, or by another applicable obligation. Certification may provide
interested parties with an additional level of confidence in the organization’s
Information Security Management System.
Does ISO/IEC 27001 Mean anOrganization Will Never Be Breached?
No.
No management system can guaranteethat an information-security incident will never occur.
ISO/IEC 27001 establishes a structuredapproach to managing information-security risks and strengthening the
organization’s ability to protect information and respond to changing threats
and circumstances.
The accurate statement is not:
“ISO 27001 prevents cyberattacks.”
It is:
“ISO/IEC 27001 helps anorganization manage information-security risks through a risk-based management
system founded on continual improvement.”
Is ISO/IEC 27002 AnotherCertification Standard?
No.
ISO/IEC 27001 specifies the requirements for an ISMS and can be used as the basisfor certification.
ISO/IEC 27002:2022 provides guidance and recommended practices for information-securitycontrols. It does not independently lead to ISO/IEC 27002 certification.
Common ISO/IEC 27001 ImplementationMistakes
Purchasing Security Tools BeforeAssessing Risks
The main weakness may lie ingovernance, access management, or supplier control rather than in the absence
of another software product.
Applying Annex A as a Checklist
Controls should support risk treatmentrather than become a purchasing list.
Treating IT as the Owner of EveryRisk
Information-security risk is anorganizational responsibility.
Documenting Policies Employees DoNot Understand
A policy that is not implemented doesnot protect information.
Failing to Control Suppliers
A significant proportion of theorganization’s information may exist outside its direct environment.
Neglecting Physical Security
Information does not exist only indigital form.
Focusing on Certification BeforeBuilding the System
Evidence may appear temporarily beforethe audit and disappear afterward.
Ignoring Applicable Law
Certification does not exempt anorganization from Jordanian legal and regulatory requirements.
Failing to Test Restoration andEmergency Arrangements
An untested plan remains anassumption.
What Is IAC’s Role?
Ideal Additions Consulting &Training (IAC) includes ISO/IEC 27001 Information Security Management Systems
within its management-system consulting services.
The service framework may include:
Designing, developing, and implementing management systems
Conducting internal audits
Performing compliance reviews
Developing policies and procedures
Aligning the system with the applicable legislative and regulatory context
IAC’s training catalogue also includesan introduction to information-security governance and related
management-system requirements, including ISO/IEC 27001, for information
technology, governance, and digital-transformation professionals.
The engagement follows IAC’soverarching methodology:
- Objective diagnosis → tailoreddesign → phased implementation → internal capability building → impact
measurement
The correct starting question is not:
How many documents do we need forcertification?
It is:
Which information-security risksmust the organization manage, and what management system will enable it to do
so effectively?
To request an initial InformationSecurity Management System diagnostic session, contact IAC to assess the
current state, identify system gaps, define an appropriate scope, and determine
the organizational and regulatory alignment required for your institution.
