Skip to content

Standards

ISO 27001 Information Security Consultancy

ISO 27001 is the international standard for information security management. It sets out how an organisation should identify the risks to the information it holds, decide how to treat them, and keep those controls effective as the business and the threat landscape change. For many organisations, certification has become a practical requirement: customers ask for it in due diligence questionnaires, public sector and defence buyers expect it, and insurers increasingly take it into account.

The standard is often misunderstood as an IT project. In reality it is a management system that covers people, processes, suppliers and physical security as much as technology. Hillscom approaches ISO 27001 as a business risk exercise, so the controls you implement are the ones your organisation needs.

ISO 27001:2022

The current edition is ISO 27001:2022, and the transition period for the previous 2013 version has now closed. The 2022 edition reorganised the Annex A controls into 93 controls across four themes: organisational, people, physical and technological. It also introduced new controls covering areas such as threat intelligence, cloud services, data masking, secure coding, configuration management and monitoring activities.

The management clauses follow the same Harmonized Structure as ISO 9001 and ISO 14001, which means information security can be integrated with quality and environmental management rather than run as a separate system.

What certification involves

Scope and context. Defining what the information security management system covers, including locations, systems, services and interfaces with third parties. A well-defined scope keeps the system focused and certification costs proportionate.

Risk assessment and treatment. A repeatable method for identifying risks to confidentiality, integrity and availability, evaluating them against defined criteria, and deciding how each will be treated.

Statement of Applicability. A reasoned record of which Annex A controls apply, which are excluded and why, and how each applicable control is implemented. This is one of the documents auditors examine most closely.

Policies and controls. Proportionate policies and procedures covering access control, supplier security, incident management, asset management, secure development, business continuity and more, sized to your organisation.

Awareness, audit and review. Staff awareness, internal audit, management review and corrective action, so the system keeps working after certification.

How Hillscom supports ISO 27001

Hillscom holds ISO 27001 Lead Implementer certification and brings experience from security-conscious aerospace and defence environments. Support covers first-time implementation, readiness assessments ahead of certification audits, remediation after audit findings, and integration with existing quality or environmental systems.

For smaller organisations and fast-growing businesses, the priority is a system that fits: policies people can follow, a risk assessment that reflects the exposure you face, and controls that work alongside existing tools rather than fighting them. For organisations with existing security practice, the work is usually about structuring and evidencing what is already there, closing specific gaps and preparing for the certification audit.

Information security also overlaps naturally with business continuity. Organisations considering both ISO 27001 and ISO 22301 can often address them together, sharing risk assessment, incident management and review processes.

Security that supports the business

A good information security management system should make it easier to win work, not harder to do it. Hillscom focuses on controls that reduce risk and demonstrate trustworthiness to customers, without adding bureaucracy that slows the business down.

Get in touch to discuss ISO 27001 certification.

Start a conversation

Talk to Hillscom

Tell us a little about your organisation and what you are trying to achieve. The first conversation is free and straightforward.

Name