ORYS Group
Home
Expertise
About Case studies Blog Careers
Cybersecurity

ISO 27001: where to start?

A pragmatic reading of the standard, so you can launch your certification journey without spreading your teams too thin.

A cybersecurity expert in a server room — ISO 27001

ISO/IEC 27001 has become the reference framework for demonstrating that an organisation manages its information security seriously and repeatably. Yet many projects stall at the starting line, buried under documentation and controls that seem to apply everywhere at once. The good news: the standard does not ask you to secure everything on day one. It asks you to build a management system that improves over time. Here is how we help our clients take the first, decisive steps.

Understand what the standard actually certifies

A common misconception is that ISO 27001 certifies a product or a technical setup. It does not. What is audited is your Information Security Management System — the ISMS — that is, the governance, processes and decisions through which you identify risks, treat them and keep them under control. The 93 controls listed in Annex A are a toolbox, not a checklist to implement blindly. This distinction changes everything: the goal is not to tick boxes but to prove that your security decisions are deliberate, documented and reviewed.

Define a scope you can actually defend

The scope is the single most strategic decision of the whole project. Too broad, and you drown your teams in evidence for systems that carry little real risk. Too narrow, and your certificate loses credibility with clients and partners. We recommend starting from the service or business line where the security stakes are highest and the boundaries are clear — a SaaS platform, a managed-services division, a data-processing centre.

A well-drawn scope answers three questions without ambiguity: which information assets are covered, which teams and locations are involved, and which third parties intervene. Everything outside the scope must be an explicit, justified exclusion, not an oversight discovered during the audit.

Run a risk assessment that reflects reality

Risk assessment is the beating heart of ISO 27001, and the step where superficial projects are exposed. The method matters less than its consistency: you can work by asset, by scenario or by process, provided you apply the same criteria throughout. For each risk, you estimate its likelihood and impact, then compare the result against the risk-acceptance thresholds validated by management.

The output is a prioritised treatment plan. For every significant risk you choose to reduce it (by applying a control), transfer it (through insurance or contract), avoid it (by dropping the activity) or accept it (with a documented, signed decision). This traceability is precisely what an auditor looks for — and what turns security into a management discipline rather than a collection of tools.

Write a Statement of Applicability that means something

The Statement of Applicability, or SoA, is the document that links your risks to the Annex A controls. For each control you state whether it applies, why, and where it stands in terms of implementation. A control excluded without justification is a red flag; a control declared applicable but never deployed is a non-conformity waiting to happen. Kept honest, the SoA becomes the map that guides your remediation effort and the reference the auditor returns to again and again.

Start with the controls that carry the most weight

You do not need to deploy every control at once. In our experience, a handful deliver disproportionate value early and reassure both auditors and clients:

  • A clear, endorsed information security policy that gives the whole system its direction.
  • Rigorous access management, with the principle of least privilege and regular reviews of who can reach what.
  • A tested backup and business-continuity capability, because resilience is what clients feel first.
  • An incident response process, so that a breach is detected, contained and learned from.
  • Structured supplier management, since much of your risk now sits with your partners.

These controls form a credible baseline. The rest can be phased in as the management system matures.

Bring people with you

No ISMS survives if it lives only in the security team. The standard explicitly requires leadership commitment and staff awareness, and for good reason: the vast majority of incidents involve human factors. Short, concrete awareness sessions, clear reporting channels and visible management sponsorship do more for your security posture than any additional tool. This is where our communication and training practices join forces with our cybersecurity experts.

Plan the journey in stages

A realistic first certification cycle runs over several months, not weeks. A typical rhythm looks like this: scoping and gap analysis, then building the documentation and deploying priority controls, then an internal audit and management review to confirm the system works, and finally the certification audit in two stages. Treating the internal audit as a rehearsal rather than a formality is often what separates a smooth certification from a stressful one.

ISO 27001 is not a finish line but a discipline: a system that turns scattered security efforts into decisions you can explain, defend and improve.

Starting well means resisting the urge to do everything at once. Define a defensible scope, assess your real risks, document your choices honestly and secure what matters most first. From there, continuous improvement does the rest — and the certificate becomes the visible proof of a security culture that was already in place.

Keep reading

Related articles

Ready to start your ISO 27001 journey?

Our cybersecurity experts scope, guide and support you all the way to certification.