Glossary / frameworks

ISO/IEC 27001

A management system standard. The certificate is proof you run the system, not that you are unbreachable.

ISO 27001 PDCAISO/IEC 27001 as Plan-Do-Check-Act: Plan (Statement of Applicability and risk), Do (operate), Check (audit), Act (improve). Annex A controls are a menu, not a shopping list.PPlanSoA + riskDDooperateCCheckauditAActimproveISO/IEC 27001 / PDCAAnnex A is a menu, not a shopping list.The certificate proves you run the ISMS — not that you are unbreachable.

ISO/IEC 27001 specifies an information security management system: scope, risk assessment, Statement of Applicability, internal audit, management review, improvement.

Annex A is a menu of controls. Treating it as a shopping list is how you get 114 tick-boxes and an open RDP server.

Useful when customers demand it. Insufficient alone for Australian government work, where ISM and Essential Eight still apply.