CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting

Click The Image Below To Visit The Power Point

Picture
ISO 27001 is the international standard for building an Information Security Management System, usually shortened to ISMS.
In plain English, it is a structured way to protect the information your business holds and uses. That includes customer data, employee data, supplier data, financial information, contracts, designs, and anything else that would cause damage if it was lost, stolen, changed without permission, or unavailable when you need it.
ISO 27001 is not a piece of software and it is not just an IT standard. It is a business management system that covers people, processes, and technology.
What ISO 27001 actually helps you controlMost information security problems come from everyday things, not Hollywood hacking.
ISO 27001 helps you control:
  1. Who can access what information, and why
  2. How passwords, devices, and systems are managed
  3. How you prevent mistakes, leaks, and unauthorised access
  4. How you spot incidents quickly and respond properly
  5. How you keep operating if systems go down
  6. How you manage suppliers and outsourced IT
  7. How you prove to clients that you take security seriously

Who ISO 27001 is forISO 27001 is a strong fit if you:
  1. Handle personal data or sensitive client information
  2. Provide IT services, software, cloud services, or managed services
  3. Work in security, finance, healthcare, or any regulated environment
  4. Bid for contracts where information security is scored
  5. Want to reduce risk and win higher value clients
If you store customer data, you are already doing information security. ISO 27001 just makes it controlled, consistent, and auditable.

ISO 27001 and GDPR: what is the differenceGDPR is a legal requirement about personal data.
ISO 27001 is a management system that helps you control information security across the business.
They overlap, but they are not the same thing.
A simple way to think about it:
  1. GDPR tells you what you must protect and what rights people have
  2. ISO 27001 helps you build the system that proves you are protecting it properly

What auditors look for in ISO 27001Auditors are not looking for perfection. They are looking for control.
In practice, they want to see that you:
  1. Know what information you have and where it is
  2. Understand the risks to that information
  3. Have policies and procedures that match your real operations
  4. Apply controls consistently, not just on paper
  5. Train staff and manage access properly
  6. Monitor, review, and improve the system

The core building blocks of ISO 27001You do not need to memorise clause numbers. You need to understand the structure.
ISO 27001 is built around:
  1. Context: what you do, what you protect, and what matters to your clients
  2. Leadership: roles, responsibilities, and commitment
  3. Planning: risk assessment and risk treatment
  4. Support: competence, awareness, documentation
  5. Operation: how you run security day to day
  6. Performance evaluation: internal audits, monitoring, management review
  7. Improvement: corrective actions and continual improvement

The Statement of Applicability, explained simplyThe Statement of Applicability, usually called the SoA, is one of the most important documents in ISO 27001.
In plain English, it is your control list.
It shows:
  1. Which controls you have selected
  2. Which controls you have not selected
  3. Why you made those decisions
  4. How each control is implemented
If your SoA is weak, your ISO 27001 system will be weak. If your SoA is clear and honest, auditors can follow your logic.

Common ISO 27001 nonconformities we seeThese are the issues that regularly cause trouble in audits:
  1. Risk assessments that are generic or out of date
  2. Asset registers that do not match reality
  3. Access control not reviewed regularly
  4. Supplier controls missing for outsourced IT
  5. No evidence of security awareness training
  6. Incident process exists but nobody uses it
  7. Backups not tested, or restore evidence missing
  8. Policies written like templates, not like the business

How long ISO 27001 takesWith the right approach, ISO 27001 does not need to drag on for months.
Typical timelines:
  1. Simple business with low complexity: a few weeks
  2. More complex or regulated environments: 4 to 12 weeks depending on scope and readiness
The key is scoping it properly and building a system that fits how you actually work.

What you need to get startedTo start ISO 27001 properly, you need:
  1. A clear scope: sites, services, systems, and boundaries
  2. An asset list: what information and systems you rely on
  3. A risk assessment method: simple but consistent
  4. A plan for controls: your SoA and supporting procedures
  5. Evidence: training, access reviews, supplier checks, backups, incident logs

The plain-English ISO 27001 certification processMost certification bodies follow the same structure:
  1. Gap analysis and system build
  2. Implementation period: you start using the controls and collecting evidence
  3. Internal audit
  4. Management review
  5. Stage 1 audit: readiness review
  6. Stage 2 audit: full certification audit
  7. Annual surveillance audits
  8. Recertification every three years

How we make ISO 27001 simple at CAW ConsultancyWe keep it practical and fast.
What you get with us:
  1. A bespoke ISMS built around how you actually operate
  2. Plain-English policies and procedures, not generic templates
  3. Risk assessment and SoA that auditors can follow
  4. Staff training so the system works in real life
  5. Support through the audit, including fixes if anything is flagged

We are known for speed, value, and results - If you want ISO 27001 without the jargon, send me a message and I will tell you exactly what you need, what you do not need, and how fast we can get you through it. Email: [email protected]Phone: 01257 824481
Picture

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting