Frameworks

ISO/IEC 27001, explained

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Unlike a framework you simply align to, it’s a standard you can be formally certified against — useful when customers or partners require independent proof that you manage information security properly.

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Unlike a framework you simply align to, it’s a standard you can be formally certified against — useful when customers or partners require independent proof that you manage information security properly.

The essentials

What it involves

  • A management system (ISMS) — not just technical controls, but processes and governance.
  • A risk-based approach to selecting and applying controls.
  • Independent certification by an accredited body, renewed periodically.
  • Ongoing improvement, internal audits and management review.
  • Strong overlap with the Privacy Act, NIST CSF and NZISM.

Do you need it?

Is certification right for you?

ISO 27001 certification is worth it when customers, partners or tenders require it, or when it gives you a competitive edge. If you just want to be genuinely secure, aligning to NIST CSF or the NZISM may be enough. We’ll help you make that call honestly rather than sell you certification you don’t need.

FAQ

Common questions

What's the difference between ISO 27001 and NIST CSF?

NIST CSF is a framework you align to; ISO/IEC 27001 is a standard you can be formally certified against. CSF is great for structure; ISO 27001 is what you pursue when you need certified proof.

How long does ISO 27001 certification take?

For a smaller organisation, typically several months to build the management system, followed by the certification audit. Preparation is the bulk of the work.

Do we need ISO 27001 to be secure?

No. Many organisations are genuinely secure by aligning to NIST CSF or the NZISM. Certification is about independent proof — pursue it when customers or tenders require it.

Let’s talk

Every good plan starts with a conversation, and there’s no obligation in having one.