Ideal Additions Consulting & Training (IAC)

  • Home
  • About Us
  • Consulting
  • Training
  • Methodology
  • Impact
  • Insights & Articles
  • News
  • Contact Us
  • …  
    • Home
    • About Us
    • Consulting
    • Training
    • Methodology
    • Impact
    • Insights & Articles
    • News
    • Contact Us
WhatsApp

Ideal Additions Consulting & Training (IAC)

  • Home
  • About Us
  • Consulting
  • Training
  • Methodology
  • Impact
  • Insights & Articles
  • News
  • Contact Us
  • …  
    • Home
    • About Us
    • Consulting
    • Training
    • Methodology
    • Impact
    • Insights & Articles
    • News
    • Contact Us
WhatsApp

ISO/IEC 27001 in Jordan: A Guide

Organizational Information NoLonger Exists Only in the Server Room

· InfoSec and Assets

An organization’s information is nolonger confined to its server room.

It may exist in:

Email systems

  • Enterprise Resource Planning (ERP) systems
  • Customer Relationship Management (CRM) systems
  • Mobile devices
  • Cloud services
  • Human resources files
  • Customer databases
  • Contracts

Financial information

  • Software source code
  • Backup copies
  • Devices used by employees and suppliers
  • Information security therefore cannotbe reduced to:

Firewall + Antivirus + ITDepartment

The challenge is much broader.

Organizations must answer questionssuch as:

Who can access the information?

  • How are access rights determined?
  • What happens when an employee leaves?
  • How is information held by a cloud service provider managed?
  • Can information be restored after an incident?
  • Who reports an information-security incident?
  • Which information is most sensitive?
  • Which risks will management accept, and which must be treated?
  • This is where ISO/IEC 27001becomes relevant.

ISO/IEC 27001 is an InternationalStandard that specifies requirements for establishing, implementing,
maintaining, and continually improving an Information Security ManagementSystem (ISMS). It adopts a risk-management approach that can be adapted tothe organization’s size, needs, and context.

What Is the Current Edition ofISO/IEC 27001?

As of 17 August 2026, thecurrent published edition is:

ISO/IEC 27001:2022

It was published in October 2022 andhas an amendment addressing climate-action changes:

ISO/IEC 27001:2022/Amd 1:2024

New implementation projects shouldtherefore not be based on:

ISO/IEC 27001:2013

as though it were still the currentedition.

When referring formally tocertification, ISO uses wording such as:

Certified to ISO/IEC 27001:2022.

What Does ISO/IEC 27001 Protect?

The objective is not limited toprotecting digital files.

An Information Security ManagementSystem addresses three fundamental properties of information:

Confidentiality

Information is accessible only toauthorized individuals and entities.

Integrity

Information remains accurate,complete, and protected against unauthorized alteration or destruction.

Availability

Information and systems remainaccessible when required by the organization and authorized parties.

ISO presents these three principles asthe CIA Triad: Confidentiality, Integrity, and Availability.

An information-security risk couldtherefore involve:

Disclosure of a customer database

Unauthorized modification of a financial record

  • Deletion of a critical file
  • System unavailability
  • Loss of a device
  • Inappropriate access rights
  • Human error
  • A third-party supplier failing to manage information securely
  • ISO/IEC 27001 Is Not Only an ITProject
  • This is one of the most importantprinciples.

If implementation is assigned entirelyto the IT department, it may become a technical project while losing its
organizational and governance dimensions.

ISO explains that information securityrequires a comprehensive approach involving people, policies, processes, andtechnology. Information security should be integrated into theorganization’s operations, information systems, and management controls.

Depending on the organization,implementation will typically require participation from:

Senior management

Information technology

Cybersecurity, where a separate function exists

  • Human resources

Legal and compliance

  • Procurement
  • Operations
  • Risk management
  • Process and information owners
  • Step One: Determine Why You Want toImplement ISO/IEC 27001
  • Do not begin with certification.

Begin by defining the business driver.

The organization’s reasons mayinclude:

Reducing information-security risks

Meeting a customer requirement

Qualifying as an approved supplier

  • Satisfying a contractual requirement
  • Strengthening governance
  • Protecting sensitive information
  • Supporting regulatory compliance
  • Improving organizational maturity
  • A clear business driver helpsdetermine the appropriate ISMS scope.
  • An ISMS covering an entire technologycompany will differ from one covering a specific cloud service, data center, or
    defined group of processes.

Step Two: Conduct a Gap Analysis

Before writing policies, understandwhat already exists.

Compare the organization’s currentarrangements with the requirements of ISO/IEC 27001.

Review areas such as:

Governance

Risk management

Access management

Information and related assets

Human resources

  • Physical security
  • Supplier management
  • Incident management
  • Business continuity

Technology controls

  • Monitoring
  • Internal audit
  • Compliance

The Gap Analysis should not becomemerely a:

  • Document checklist

The organization must also ask:

  • Is the procedure actually implemented?

Do employees understand it?

Is objective evidence available?

Is the control operating effectively?

  • The real gap may not be a missingpolicy. It may be an existing access-control system that is never reviewed.

Step Three: Define the ISMS ScopeAccurately

One of the most serious mistakes is towrite:

“All company operations”

without conducting a proper analysis.

The organization must understand:

Products and services

Processes

Locations

Systems

Interfaces

External parties

Information requiring protection

ISO/IEC 27001 allows the ISMS to bedesigned according to the organization’s size, context, and needs, but the
scope must remain clear, justified, and understandable.

Why Is the Scope Important?

The scope determines:

What enters the risk assessment

Which systems are included

Which people and roles are included

Which locations are included

Which suppliers are relevant

  • What any future certification will cover
    An organization should not choose anartificially narrow scope merely to make certification easier if that scope
    does not represent the service on which customers or other interested parties
    rely.

Step Four: Understand theOrganization’s Context and Interested Parties

Information security must be connectedto the business.

The organization should ask:

Which services are critical?

Which information do customers depend on?

What contractual obligations apply?

What legal requirements apply?

  • Which regulatory bodies are relevant?
  • How dependent is the organization on cloud services?
  • Which suppliers are critical?
  • What would be the effect of a specific system becoming unavailable?
  • It should then determine the relevantneeds and expectations of interested parties.
  • For example:
  • Customers may be concerned with the confidentiality of their data.

Management may prioritize business continuity.

A regulatory authority may impose mandatory requirements.

  • A cloud provider may introduce a different operating and responsibility model.
    This analysis prevents the ISMS frombecoming detached from the organization’s actual operating environment.
    Step Five: Establish ClearInformation-Security Governance

The organization should define:

Who owns the ISMS?

Who approves the information-security policy?

Who owns each risk?

Who has the authority to accept residual risk?

Who manages incidents?

  • Who approves access rights?
  • Who monitors ISMS performance?
  • A common mistake is appointing an:
  • Information Security Officer
  • and then transferring everyinformation risk to that individual.

A risk associated with the HumanResources system, for example, should not become the sole responsibility of the
information-security function.

The relevant process or asset ownermust participate in the risk decision.

Step Six: Identify Information andRelated Assets

An organization cannot manage therisks associated with something it does not know exists.

However, the asset register should notbecome an unnecessarily large bureaucratic exercise.

The organization should identify whatit needs to understand regarding:

Information

Systems

Devices

Applications

Cloud services

Facilities

Suppliers

Supporting assets

An owner or responsible functionshould be assigned where appropriate.

The central question is:

Which information does theorganization depend on, where is it located, and who can access it?

Step Seven: Classify Information

Not every file requires the same levelof protection.

An organization may establish aclassification model such as:

Public

Internal

Confidential

Highly sensitive

This is only an example. ISO does notimpose this specific classification structure.

The selected classification systemmust be:

Clear

Practical

Applicable

Connected to actual controls

  • If a document is classified as“Confidential” but is sent in exactly the same way as a public marketing
    brochure, the classification has achieved nothing.
    Step Eight: Conduct anInformation-Security Risk Assessment

The risk assessment is the foundationof ISO/IEC 27001.

ISO explains that the standard appliesa risk-management process adapted to the organization’s size and needs.

ISO/IEC 27005:2022 provides specialist guidance on managing information-security risks insupport of an ISMS based on ISO/IEC 27001.

A risk scenario can be consideredthrough the following sequence:

Asset or process → threat or event→ vulnerability or enabling condition → impact → likelihood → risk level →
treatment

For example:

Asset:Email system

Scenario:Compromise of an employee’s account

Potential impact: Unauthorized access to sensitive information and correspondence orfraudulent use of the account

The organization should then examine:

Which controls currently exist?

Is multi-factor authentication in use?

Is employee awareness appropriate?

Is monitoring effective?

What residual risk remains?

Step Nine: Do Not Turn the RiskAssessment into a List of Cyberattacks

  • Not every information risk involves ahacker.
    The risk could involve:
  • An employee sending a file to the wrong recipient
  • A lost device
  • A supplier discontinuing a service

A backup that cannot be restored

Access rights remaining active after an employee leaves

A data-center outage

Misconfigured cloud storage

  • Inability to access critical information

This reflects the purpose of ISO/IEC27001: protecting confidentiality, integrity, and availability, notmerely preventing external attacks.

  • Step Ten: Decide How Risks Will BeTreated
    After assessing a risk, it is notenough to record:

Risk = High

The organization must make a decision.

Treatment options may include:

Reducing the risk by implementing a control

Avoiding the activity that creates the risk

Changing the way the activity is performed

Sharing or transferring part of the risk contractually or through insurance, where appropriate

  • Accepting the risk under clearly defined authority
    The decision must be justified andowned by the appropriate person.
    What Is Annex A?
    ISO/IEC 27001 includes a reference setof information-security controls.
    ISO/IEC 27002:2022 provides more detailed guidance on the information-security controlsused to support the ISMS. ISO/IEC 27001 specifies the management-system
    requirements, while ISO/IEC 27002 provides control-related guidance and
    recommended practices.

The current control set contains 93controls organized into four themes:

Organizational controls

People controls

Physical controls

Technological controls

A common mistake is approaching thecontrols as follows:

“There are 93 controls, so we willimplement all 93 in sequence.”

ISO/IEC 27001 is risk-based.

The controls selected should reflectthe organization’s risks and its legal, contractual, operational, and business
requirements—not merely the completion of a checklist.

What Is a Statement ofApplicability?

The Statement of Applicability(SoA) is one of the most important documents in the ISMS.

In practical terms, it records theorganization’s decisions regarding necessary information-security controls,
their implementation status, and the reasons for including or excluding
relevant reference controls.

The SoA should not be:

A copy of Annex A with “Yes”written beside every control.

The organization should be able totrace the relationship between:

Risk Assessment → Risk Treatment →Controls → Statement of Applicability

If the organization cannot explain whyit selected a control, the system has become a mechanical implementation
exercise rather than a risk-management process.

Step Eleven: Do Not Begin byWriting 40 Policies

Documentation should support thesystem.

Depending on its context, anorganization may need policies or procedures covering areas such as:

Access control

Account and permission management

Incident management

Backup

Supplier management

Acceptable use of devices

Remote working

Cryptography

Change management

Secure development

Disposal of information and devices

The number of policies is not anindicator of maturity.

  • A small company may require a simplerdocumentation structure than a large financial or technology institution.
    The principle consistent with IAC’smethodology is:
    Documentation that can beapplied—not bureaucracy created solely for certification.

Step Twelve: Control Access andPermissions

Access management is one of the areasmost closely connected to daily operations.

The organization should ask:

Who can request access?

Who approves it?

How is business need verified?

How is privileged access managed?

When are access rights reviewed?

What happens when an employee changes roles?

What happens when an employee moves to another department?

What happens during extended leave?

  • What happens when the employment relationship ends?
    Creating a user account is only thebeginning.
    The organization must manage thecomplete identity and access life cycle.
    Step Thirteen: Integrate HumanResources with Information Security
    Employees are a fundamental part ofthe ISMS before employment, during employment, and when the relationship ends.

Depending on the context, relevantcontrols may address:

Confidentiality obligations

Security awareness

Employee responsibilities

Access management

Incident reporting

Removal of access rights upon departure

ISO/IEC 27002 explicitly addressespeople-related security alongside access control, cryptography, and incident
response.

Step Fourteen: Manage Suppliers andCloud Services

  • Organizational information may existoutside the organization’s direct technical environment.
    When using a:
  • Cloud provider

Software-as-a-Service platform

Payroll provider

Software development company

Support provider

Data center

Third party that processes information on behalf of the organization

the organization should ask:

Which information can the supplier access?

What risks are involved?

Which contractual obligations apply?

  • How must incidents be reported?
  • What requirements apply when the contract ends?
  • How will the organization retrieve its data?
  • Are subcontractors or downstream providers involved?

Signing a contract with a supplierdoes not remove the associated risk from the organization’s ISMS.

  • Step Fifteen: Design anIncident-Management Process
    An information-security incidentshould not begin with the question:
    Who should we call?
    The organization should define inadvance:
  • How incidents are reported
  • Who classifies them

Who leads the response

Who decides whether escalation is required

When Legal or senior management should become involved

How evidence is preserved

How communication is managed

How lessons are identified after the incident

ISO/IEC 27002 includesinformation-security incident management and response among the control areas
supporting the ISMS.

Step Sixteen: Connect InformationSecurity with Business Continuity

  • Backup is not the same as businesscontinuity.
    A backup may be intact whilerestoration takes longer than the organization can tolerate.
    The organization should therefore ask:

Which services are critical?

Which systems support those services?

What are the relevant dependencies?

Has restoration been tested?

Who decides when an alternative arrangement should be activated?

Is a cyberattack included among the organization’s disruption scenarios?

Where appropriate, ISO/IEC 27001 canbe aligned with an ISO 22301 Business Continuity Management System.

  • Step Seventeen: Test Backups
    The statement:
    “We have backups.”
    is not sufficient.
    The more important question is:
    Have we restored them successfully?
    The organization should review:
  • What is included in the backup?
  • How frequently is it copied?

What happens when the backup process fails?

How are backup copies protected?

Who can access them?

When was restoration last tested successfully?

A control that has never been testedmay create a stronger sense of security than the protection it actually
provides.

Step Eighteen: Build AwarenessInstead of Delivering a Token Annual Course

  • Security awareness should not bereduced to a PowerPoint presentation delivered once a year.
    Employees should understand:
  • How to handle information
  • How to recognize suspicious communications

How to report a concern

The rules governing account use

What to do if a device is lost

Their responsibility for protecting information

Awareness programs may need to differby role.

A software developer requiresdifferent awareness from an employee in Human Resources, Finance, or Customer
Service.

  • Step Nineteen: Identify ApplicableJordanian Compliance Requirements
    A clear distinction must bemaintained:
    ISO/IEC 27001 is an InternationalStandard, and the decision to pursue certification is voluntary unless another
    obligation makes it necessary.

By contrast:

Applicable Jordanian laws,regulations, instructions, and mandatory controls must be followed when they
apply to the organization.

The National Cyber Security Centercurrently lists legislation and regulatory instruments including:

Cybersecurity Law No. 16 of 2019

Instructions for the Classification of Cybersecurity Incidents for 2023 and their amendments

Cybersecurity Service Providers Licensing Regulation for 2024

Instructions concerning violations of the Cybersecurity Law for 2025

Cybercrime Law

Personal Data Protection Law

The Center also publishes the JordanNational Cybersecurity Framework, together with its components, activitymaps, and controls.

  • Official material published by theCenter explains that Article 8 of Cybersecurity Law No. 16 of 2019 is
    associated with the obligation of relevant entities to follow the policies,
    standards, and controls issued by the Center for each sector.
    A Jordanian ISMS should thereforeinclude a Legal and Regulatory Register reflecting the requirements thatgenuinely apply to the organization and its sector.

How Does Jordan’s Personal DataProtection Law Relate to ISO/IEC 27001?

Jordan’s Personal Data Protection LawNo. 24 of 2023 entered into force on 17 March 2024. The Ministry ofDigital Economy and Entrepreneurship explains that sectors handling personal
data are required to comply with its provisions.

However:

ISO/IEC 27001 is not the same asthe Personal Data Protection Law.

ISO/IEC 27001 helps an organizationmanage information-security risks and related controls.

The Personal Data Protection Lawgoverns rights, responsibilities, and the processing of personal data in
accordance with the law and the regulations and instructions issued under it.

There may be considerable overlapbetween the two, but one does not replace the other.

Organizations requiring a morespecialized framework for privacy information management may also consider ISO/IEC27701:2025 for Privacy Information Management Systems.

Step Twenty: Monitor ISMSPerformance

It is not enough to say:

“We implemented the controls.”

The organization must determine how itwill know whether those controls are working.

Depending on its needs, it may monitorindicators such as:

Time required to close incidents

Percentage of access reviews completed

Status of risk-treatment actions

Percentage of corrective actions closed

Success rate of restoration tests

Results of awareness activities

Other measures connected to the organization’s information risks

The objective is not to maximize thenumber of indicators.

The organization should selectmeasures that help management understand ISMS performance and make informed
decisions.

  • Step Twenty-One: Conduct anInternal Audit
    Before an external assessment, theorganization should evaluate the system internally.
    The audit should not examine policiesalone.
    It can begin with an operationalscenario.
    For example, an employee has left theorganization.

The auditor can trace whether:

Relevant parties were notified

The employee’s account was disabled

Cloud permissions were removed

The device was returned

Access to external systems was closed

Objective evidence exists

Alternatively, the audit may beginwith an information-security incident:

How was it reported?

How was it classified?

Who handled it?

What corrective action followed?

Did it result in an update to the risk assessment?

This approach reveals how the realsystem operates.

  • IAC’s management-system services,including ISO/IEC 27001, include internal audits and compliance reviews.
    Step Twenty-Two: Conduct ManagementReview

Information security should not belimited to a report submitted by the IT department.

  • Management should receive informationthat supports decisions, including:
  • Principal information-security risks
  • Incidents
  • Control performance

Risk-treatment status

Significant changes

Audit findings

Compliance obligations

Resource requirements

Issues requiring leadership decisions

If senior management seesinformation-security risks only after a major incident, the ISMS has not yet
reached the governance level.

Step Twenty-Three: AddressNonconformities

Suppose an audit finds that thescheduled access review was not performed.

  • The organization should not merelycomplete the overdue review.
    It should ask:
  • Why was the review not completed?
  • Was ownership unclear?
  • Did the system fail to generate a notification?

Was the scheduled frequency unrealistic?

Was the responsibility omitted from the relevant role?

The appropriate sequence is:

Correct the immediate issue →address the cause → verify effectiveness

This is how the organization builds amanagement system that learns and improves.

When Is an Organization Ready forCertification?

There is no universal threshold suchas:

  • “90% readiness.”
    An organization is closer to readinesswhen it can demonstrate that:
  • The ISMS scope is clear
  • Risks have been identified and remain current
  • Risk-treatment decisions are documented

Necessary controls are operating

The Statement of Applicability reflects the system’s decisions

Policies and procedures are being used

Personnel understand their responsibilities

Performance is being monitored

An internal audit has been completed

Management has reviewed the system

Significant nonconformities have been addressed

The organization may then engage anindependent certification body if it chooses to pursue certification.

  • ISO itself does not certifyorganizations. Certification is voluntary unless required contractually,
    legally, or by another applicable obligation. Certification may provide
    interested parties with an additional level of confidence in the organization’s
    Information Security Management System.
    Does ISO/IEC 27001 Mean anOrganization Will Never Be Breached?

No.

No management system can guaranteethat an information-security incident will never occur.

ISO/IEC 27001 establishes a structuredapproach to managing information-security risks and strengthening the
organization’s ability to protect information and respond to changing threats
and circumstances.

The accurate statement is not:

“ISO 27001 prevents cyberattacks.”

It is:

“ISO/IEC 27001 helps anorganization manage information-security risks through a risk-based management
system founded on continual improvement.”

Is ISO/IEC 27002 AnotherCertification Standard?

No.

ISO/IEC 27001 specifies the requirements for an ISMS and can be used as the basisfor certification.

ISO/IEC 27002:2022 provides guidance and recommended practices for information-securitycontrols. It does not independently lead to ISO/IEC 27002 certification.

Common ISO/IEC 27001 ImplementationMistakes

Purchasing Security Tools BeforeAssessing Risks

The main weakness may lie ingovernance, access management, or supplier control rather than in the absence
of another software product.

Applying Annex A as a Checklist

Controls should support risk treatmentrather than become a purchasing list.

Treating IT as the Owner of EveryRisk

Information-security risk is anorganizational responsibility.

Documenting Policies Employees DoNot Understand

A policy that is not implemented doesnot protect information.

Failing to Control Suppliers

A significant proportion of theorganization’s information may exist outside its direct environment.

Neglecting Physical Security

Information does not exist only indigital form.

Focusing on Certification BeforeBuilding the System

Evidence may appear temporarily beforethe audit and disappear afterward.

Ignoring Applicable Law

Certification does not exempt anorganization from Jordanian legal and regulatory requirements.

Failing to Test Restoration andEmergency Arrangements

An untested plan remains anassumption.

What Is IAC’s Role?

Ideal Additions Consulting &Training (IAC) includes ISO/IEC 27001 Information Security Management Systems
within its management-system consulting services.

The service framework may include:

Designing, developing, and implementing management systems

Conducting internal audits

Performing compliance reviews

Developing policies and procedures

Aligning the system with the applicable legislative and regulatory context

IAC’s training catalogue also includesan introduction to information-security governance and related
management-system requirements, including ISO/IEC 27001, for information
technology, governance, and digital-transformation professionals.

The engagement follows IAC’soverarching methodology:

  • Objective diagnosis → tailoreddesign → phased implementation → internal capability building → impact
    measurement
    The correct starting question is not:
    How many documents do we need forcertification?
    It is:
    Which information-security risksmust the organization manage, and what management system will enable it to do
    so effectively?

To request an initial InformationSecurity Management System diagnostic session, contact IAC to assess the
current state, identify system gaps, define an appropriate scope, and determine
the organizational and regulatory alignment required for your institution.


Previous
When Does Your Company Need Restructuring?
Next
ISO 22301 and Business Continuity
 Return to site
Cookie Use
We use cookies to improve browsing experience, security, and data collection. By accepting, you agree to the use of cookies for advertising and analytics. You can change your cookie settings at any time. Learn More
Accept all
Settings
Decline All
Cookie Settings
These cookies enable core functionality such as security, network management, and accessibility. These cookies can’t be switched off.
These cookies help us better understand how visitors interact with our website and help us discover errors.
These cookies allow the website to remember choices you've made to provide enhanced functionality and personalization.
Save