Everything you need to know about ISO 27001?
ISO 27001 is one of the world’s most recognised information security standards. It gives organisations a structured way to protect information, manage cyber risk, assign responsibility, measure security performance and continually improve how information security works across the business.
The full name of the current standard is ISO/IEC 27001:2022. ISO confirms that it provides the requirements for an Information Security Management System, commonly called an ISMS. Organisations can implement the standard without seeking certification, or they can use an independent certification body to demonstrate conformity to customers and other interested parties.
ISO 27001 is not simply an IT standard. It covers leadership, employees, suppliers, risk, policies, business processes, physical security, technology, incident management, internal audit and management review.
That broad approach matters because information security problems rarely come from technology alone. A cyber incident can begin with a phishing message, an incorrectly configured cloud service, a supplier failure, an employee mistake, excessive access privileges or a poorly managed business process.
UK Cyber Compliance provides an automated and AI-driven platform designed to help organisations manage ISO 27001 certification activity, including risk management, control tracking, policies, evidence and audit readiness.
UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.
what is iso 27001
ISO 27001 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System.
An ISMS is the management framework that an organisation uses to protect information.
It helps management answer practical questions such as:
What information matters to the organisation?
What could go wrong?
How serious would the consequences be?
Which security controls already operate?
Which further controls do we need?
Who owns each risk?
Who is responsible for each control?
How do we know our security processes work?
What evidence can demonstrate that?
What should change when the business develops?
ISO describes certification to ISO/IEC 27001 as a way for organisations to demonstrate to customers and other interested parties that they can manage information securely. ISO itself does not carry out certification. Independent certification bodies perform that work.
Confidentiality, integrity and availability
ISO 27001 focuses heavily on three core information security principles.
Confidentiality
Confidentiality means information should only reach authorised people and systems.
Examples include protecting:
Customer information
Employee records
Financial information
Contracts
Passwords
Intellectual property
Business plans
Security information
Confidentiality controls can include access management, authentication, encryption, information classification and secure sharing.
Integrity
Integrity means information remains accurate, complete and trustworthy.
A business needs confidence that records have not received unauthorised changes.
Examples include:
Financial records
Customer information
Configuration information
Source code
Contracts
Orders
Security logs
Strong access controls, change management, logging and backup arrangements can all help protect integrity.
Availability
Availability means authorised users can access information and systems when they need them.
A cyber attack, failed cloud service, damaged equipment or supplier outage can disrupt business operations.
Organisations therefore need to consider resilience, backup, recovery, supplier dependency and continuity.
A strong ISMS considers all three principles rather than concentrating only on preventing hackers from gaining access.
ISO 27001 is a management system
This point separates ISO 27001 from many security frameworks.
ISO 27001 does not only ask whether security technology exists.
It asks how the organisation manages information security.
Management systems create repeatable processes.
For example, rather than asking only whether multi-factor authentication exists, the ISMS can also address:
Who decides which accounts need protection?
Who checks that MFA remains enabled?
What happens when employees join?
What happens when an employee changes role?
How does the organisation remove access when somebody leaves?
What happens when a control fails?
How does management review the risk?
That approach makes security sustainable.
The main requirements run from Clause 4 to Clause 10
BSI confirms that organisations seeking ISO/IEC 27001 certification need to meet the requirements contained within Clauses 4 through 10.
These requirements form the management framework around the ISMS.
Understanding the organisation
Clause 4 focuses on organisational context.
The business needs to understand factors that can affect its information security management system.
These may include:
Customers
Employees
Suppliers
Technology
Legal obligations
Contracts
Business objectives
Remote working
Cloud services
Critical information
Interested parties
The organisation also defines its ISMS scope.
Scope matters because it establishes the boundary of certification.
A scope may cover the entire business or a clearly defined part of it.
The scope should represent a meaningful information security boundary.
Trying to exclude important systems, people or processes purely to make certification easier can create problems during assessment.
Leadership needs to own information security
Clause 5 covers leadership.
Senior management needs to demonstrate commitment to the ISMS.
This includes establishing information security direction, supporting relevant roles and making sure information security aligns with business objectives.
Leadership should not simply give ISO 27001 to the IT department.
Management needs visibility of:
Important risks
Information security objectives
Audit findings
Incidents
Resource requirements
Improvement actions
Serious control weaknesses
Risk acceptance decisions
Leadership involvement helps information security become part of normal business governance.
Planning starts with information security risk
Clause 6 contains some of the most important ISO 27001 requirements.
The organisation needs a defined information security risk assessment process.
That process should produce consistent, valid and comparable results.
A practical method normally considers likelihood and business impact.
The organisation identifies risk scenarios and then evaluates them against its agreed risk criteria.
For example:
An employee may disclose credentials through phishing.
A cloud provider may suffer an extended outage.
A laptop containing confidential information may be lost.
A supplier may suffer a security incident.
An attacker may exploit an unpatched vulnerability.
An employee may receive excessive access privileges.
The organisation evaluates these scenarios and decides whether the risk remains acceptable.
UK Cyber Compliance’s current platform includes guided risk assessment, residual risk tracking, control management and real-time compliance visibility.
Risk acceptance criteria create consistency
Organisations need a clear way to decide which risks require further action.
Without acceptance criteria, managers may make inconsistent decisions.
One department may accept a risk that another department would treat immediately.
A straightforward approach can define likelihood, impact and risk thresholds.
Management can then establish rules covering:
Which risks may be accepted
Who can approve acceptance
Which risks require treatment
When senior management approval becomes necessary
How often accepted risks receive review
Risk acceptance should represent an informed decision.
It should never become a convenient way to avoid security work.
Risk treatment turns analysis into action
When a risk exceeds the organisation’s tolerance, management needs to decide what to do.
Treatment can include reducing the risk through additional controls.
The organisation might also avoid an activity that creates unacceptable exposure.
Some risk may remain after controls operate.
That remaining exposure is commonly called residual risk.
The relevant risk owner then determines whether the remaining exposure meets the organisation’s acceptance criteria.
This creates a clear journey from risk identification through treatment to management decision.
Annex A provides 93 information security controls
ISO/IEC 27001:2022 contains 93 Annex A controls arranged across four broad areas:
Organisational controls
People controls
Physical controls
Technological controls
UK Cyber Compliance’s current guidance also confirms the 93-control structure used by ISO/IEC 27001:2022.
These controls cover subjects such as:
Information security policies
Security responsibilities
Asset management
Information classification
Supplier security
Cloud services
Incident management
Business continuity
Employee awareness
Physical access
Authentication
Malware protection
Backup
Logging
Monitoring
Vulnerability management
Network security
Secure development
Annex A should not become a simple checklist where an organisation marks every control as complete.
Control selection should follow the organisation’s risks and other applicable requirements.
The four Annex A areas
Organisational controls
These controls address governance and business processes.
They include matters such as information security policies, responsibilities, segregation of duties, information classification, supplier relationships, cloud services, incident management and continuity.
They help answer questions about how the organisation manages security across the business.
People controls
Employees, contractors and other personnel can influence information security significantly.
These controls address subjects such as screening, employment responsibilities, awareness, confidentiality and responsibilities when employment changes or ends.
A strong technical environment still needs people who understand their responsibilities.
Physical controls
Information security also depends on the physical environment.
These controls consider areas such as secure locations, physical access, equipment security, environmental threats and secure disposal.
The controls should reflect how the organisation actually operates.
A business with remote employees may face different physical considerations from an organisation operating secure facilities.
Technological controls
These controls address digital systems and technical safeguards.
Subjects include authentication, privileged access, malware defence, configuration management, vulnerability management, backup, logging, monitoring, network security and development activity.
The organisation selects and operates controls according to its risks and requirements.
The Statement of Applicability connects the controls with the business
The Statement of Applicability, commonly shortened to SoA, is one of the most important ISO 27001 records.
It explains which controls the organisation considers necessary, why they are necessary, whether they have been implemented and why any Annex A controls have been excluded.
UK Cyber Compliance describes the SoA as a practical record connecting risk, legal responsibilities, customer expectations, supplier requirements and security controls.
The SoA should therefore align with the risk register.
If the risk register identifies serious supplier exposure, the SoA should show the relevant controls.
If account compromise creates significant risk, the SoA should reflect appropriate access and authentication measures.
The risk register and SoA should tell the same story.
Controls can come from outside Annex A
The 93 controls are a reference set.
An organisation may determine that it needs another control because of a specialist technology, customer requirement, contractual obligation or regulatory expectation.
That additional control can become part of the ISMS.
ISO 27001 provides flexibility because organisations do not all face identical risks.
A financial service provider, software company, manufacturer and professional consultancy may all need different security measures.
Support includes people, resources and documentation
Clause 7 addresses support for the ISMS.
Important areas include:
Resources
Competence
Awareness
Communication
Documented information
Employees need enough competence to perform responsibilities that affect information security.
People also need awareness of the information security policy, their contribution to the ISMS and the potential consequences of failing to follow requirements.
This makes employee awareness a genuine part of ISO 27001 rather than an optional extra.
Useful evidence can include training records, induction information, policy acknowledgements and records of specialist professional development.
Security needs to become operational
Clause 8 focuses on operation.
The organisation needs to carry out the processes it planned.
Risk assessment needs to happen in practice.
Treatment actions need completion.
Controls need to operate.
Changes need appropriate management.
A written process alone does not demonstrate that the ISMS works.
For example, an access control policy may require managers to review permissions periodically.
An auditor can then look for evidence that those reviews actually happened.
Completed access reviews provide stronger assurance than the policy alone.
Performance needs to be measured
Clause 9 covers performance evaluation.
The organisation needs to understand whether the ISMS works.
This includes monitoring and measurement, internal audit and management review.
Useful security information can include:
Security incidents
Audit findings
Training completion
Vulnerability remediation
Backup testing
Access reviews
Risk treatment progress
Supplier reviews
Security objectives
Management should receive information that supports decisions rather than large reports that nobody uses.
Internal audit tests the management system
Internal audit gives the organisation an opportunity to identify weaknesses before the external certification assessment.
An internal auditor may test whether:
Policies match working practice.
Risks remain current.
Control owners understand their responsibilities.
Access reviews happen.
Supplier assessments exist.
Security awareness remains current.
Evidence supports the Statement of Applicability.
Corrective actions receive proper management.
Internal audit should identify meaningful improvement opportunities.
It should not become an exercise designed only to avoid findings.
Management review keeps senior leaders involved
Management review gives leadership a formal opportunity to review the ISMS.
Management can consider:
Audit results
Information security objectives
Risks
Incidents
Changes affecting security
Corrective actions
Monitoring results
Resource requirements
Improvement opportunities
The review should create decisions where action is necessary.
This keeps ISO 27001 connected with business governance.
Improvement never stops after certification
Clause 10 addresses improvement.
An organisation should continually improve the suitability, adequacy and effectiveness of its ISMS.
That does not mean changing controls simply to show activity.
Improvement should follow evidence.
An incident might reveal weak authentication.
An audit might identify inconsistent supplier reviews.
A recovery exercise may expose a backup weakness.
Employee feedback may show that a policy creates confusion.
A customer contract may create a new security requirement.
The organisation learns from these events and improves the system.
UK Cyber Compliance provides functionality for connecting findings, risks, controls, corrective actions and supporting evidence.
Corrective action addresses underlying causes
Suppose an internal audit finds that a former employee still has an active account.
Disabling the account fixes the immediate issue.
A stronger response asks why it happened.
Perhaps human resources did not notify IT.
Maybe responsibility was unclear.
The organisation can then change the underlying leaver process.
That reduces the chance of the same problem happening again.
This difference between simply fixing an issue and addressing its cause is central to continual improvement.
ISO 27001 documentation should support the business
ISO 27001 requires documented information, but certification should not become a paperwork exercise.
Useful documents and records may include:
ISMS scope
Information security policy
Risk methodology
Risk register
Risk treatment plan
Statement of Applicability
Information security objectives
Access control records
Supplier assessments
Incident records
Internal audit records
Management review records
Training records
Corrective action records
The exact information needed depends on the organisation and its ISMS.
Documents should help employees understand responsibilities and help management operate the system.
Evidence proves the ISMS works
Certification auditors need evidence that controls operate in real business activity.
Consider an organisation that says it performs regular backup recovery tests.
The policy provides part of the evidence.
A completed recovery test provides much stronger assurance.
Similar examples include:
Access review records
Vulnerability remediation records
Supplier assessments
Incident exercises
Security awareness records
Risk approvals
Management decisions
Monitoring reports
Completed corrective actions
UK Cyber Compliance’s guidance highlights the distinction between policy documents and evidence of actual operation.
Who needs iso 27001 certification
ISO 27001 can benefit organisations that handle important information or need to demonstrate structured information security management.
This can include:
Technology businesses
Software providers
Managed service providers
Professional firms
Manufacturers
Healthcare suppliers
Financial organisations
Charities
Public sector suppliers
Defence supply-chain organisations
Cloud service providers
Certification may become valuable when customers ask for independent security assurance.
Tenders may request it.
Supply chains may expect it.
Management may want a recognised framework for improving security.
ISO confirms that organisations from many economic sectors use ISO/IEC 27001 and that certification can provide additional confidence to customers and other interested parties.
Certification is normally voluntary
ISO 27001 itself does not generally force an organisation to become certified.
Some organisations implement the standard without obtaining an independent certificate.
Others seek certification because customers, contractual arrangements, tenders or supply chains expect formal assurance.
ISO confirms that organisations can implement ISO/IEC 27001 without proceeding through independent certification.
Businesses should therefore understand why they want certification before beginning the project.
A clear reason helps management define scope, objectives and resources.
ISO 27001 Certification Levels
ISO 27001 does not have official achievement bands such as bronze, silver or gold.
An organisation either achieves certification for its defined ISMS scope or it does not.
Security maturity can still differ significantly between certified organisations.
A recently certified small business may operate a straightforward ISMS with proportionate controls.
A mature organisation may have advanced security monitoring, automated risk management, highly developed supplier assurance and years of audit evidence.
Both can hold ISO/IEC 27001:2022 certification.
The standard encourages organisations to continue improving rather than progressing through formal certification bands.
How the Certification Works
The certification journey normally begins with implementation.
The organisation needs to:
Understand its business context.
Identify interested parties.
Define the ISMS scope.
Establish policies and responsibilities.
Create the risk methodology.
Assess information security risk.
Determine treatment.
Select necessary controls.
Prepare the Statement of Applicability.
Operate the controls.
Train relevant employees.
Gather evidence.
Complete internal audit.
Hold management review.
Address significant gaps.
The business then engages an independent certification body.
ISO itself does not issue ISO 27001 certificates. Certification bodies carry out the independent assessment.
BSI describes ISO/IEC 27001 certification as involving a two-stage audit of the organisation’s system and supporting records.
Stage 1 checks readiness
The first certification assessment normally examines whether the organisation has established the required ISMS framework and is ready for the more detailed assessment.
The auditor may review:
Scope
Policies
Risk methodology
Risk assessment
Statement of Applicability
Internal audit activity
Management review
Key documented information
The goal is to understand whether the organisation has built a credible management system and whether major readiness issues remain.
Stage 2 checks operation
The second assessment goes deeper into implementation.
The auditor tests whether the organisation actually operates the system described in its documentation.
This may involve:
Employee interviews
Control sampling
Access records
Supplier records
Security incidents
Training evidence
Risk decisions
Technical evidence
Management records
Corrective actions
BSI confirms that certification involves a two-stage audit covering systems and documentation.
Successful completion can lead to certification by the certification body.
Accreditation adds another assurance layer
Organisations should understand the distinction between ISO, certification bodies and accreditation.
ISO writes and publishes standards.
Certification bodies assess organisations.
Accreditation bodies assess the competence and impartiality of certification bodies.
ISO explains that a certificate issued by an accredited conformity assessment body can provide an additional layer of confidence because the certification body’s competence has received independent confirmation.
In the UK, organisations can use the UKAS directory to identify accredited organisations.
This distinction can matter when customers or tenders specifically expect accredited certification.
Certification needs ongoing maintenance
ISO 27001 does not end when the certificate arrives.
The organisation needs to keep operating the ISMS.
Risks change.
Employees change.
Suppliers change.
Technology develops.
New customer requirements appear.
Security incidents provide lessons.
The organisation therefore continues conducting audits, management reviews, risk assessments and improvement activity.
A good ISMS should become part of everyday business management.
Cyber risk remains a major UK business issue
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of UK businesses identified a cyber breach or attack during the previous 12 months. That represents approximately 612,000 businesses.
The rate rose to 65 per cent among medium businesses and 69 per cent among large businesses. Small businesses reported 46 per cent.
The same survey estimated that 19 per cent of businesses had experienced at least one cyber crime during the year, representing approximately 267,000 businesses.
Only 30 per cent of businesses reported conducting a cyber security risk assessment during the previous year.
These figures help explain why structured information security governance matters.
Cyber security is not only a concern for large technology companies.
Organisations across the UK handle valuable information and depend heavily on digital systems.
ISO 27001 and Cyber Essentials serve different purposes
UK businesses often ask whether they should choose ISO 27001 or Cyber Essentials.
The schemes address different needs.
Cyber Essentials provides a focused technical baseline designed to protect organisations against common cyber attacks.
ISO 27001 establishes a wider information security management system.
It covers risk management, leadership, policies, controls, suppliers, people, audits and continual improvement.
An organisation may therefore hold both.
Cyber Essentials can demonstrate that core technical controls meet the scheme requirements.
ISO 27001 can demonstrate wider information security governance.
The two can complement each other.
ISO 27001 and business trust
Information security increasingly affects commercial relationships.
Customers want confidence that suppliers will protect information.
Larger organisations need visibility into supply-chain risk.
Procurement teams frequently ask questions about security governance.
ISO 27001 provides a recognised way to demonstrate that security receives structured management.
The certificate alone should not become the only objective.
The real business value comes from implementing an effective ISMS.
ISO 27001 can support supplier assurance
Suppliers create significant information security dependencies.
An organisation may rely on:
Cloud providers
Managed IT services
Software providers
Payment processors
Professional advisers
Telecommunications providers
Data processors
Security providers
The ISMS helps the organisation determine which suppliers create material security risk.
Management can then apply proportionate due diligence, contractual requirements and ongoing review.
This is increasingly important as businesses depend on interconnected digital services.
Cloud security still needs customer responsibility
Using Microsoft 365, Google Workspace, AWS, Azure or another cloud platform does not remove information security responsibility from the customer.
Cloud providers manage parts of the environment.
The business still needs to manage:
Accounts
Permissions
Authentication
Sharing
Data handling
Configuration
Supplier risk
Business continuity
Contractual requirements
ISO 27001 helps organisations make those responsibilities visible and manageable.
Employee awareness remains essential
Cyber security technology cannot eliminate human risk.
Employees can encounter:
Phishing
Impersonation
Payment fraud
Credential theft
Unsafe document sharing
Suspicious MFA requests
Social engineering
Information handling errors
Security awareness should help people recognise these situations and know what to do.
Training should also reflect the employee’s role.
Finance employees need awareness of payment fraud.
Administrators need stronger knowledge of privileged access.
Managers need to understand risk and approval responsibilities.
Business continuity connects with information security
Availability forms one of the core information security principles.
Organisations should understand what happens when critical technology or suppliers become unavailable.
Useful questions include:
Which services matter most?
How long can they remain unavailable?
Which systems support them?
Which suppliers create dependencies?
What information needs backup?
Can the organisation restore it?
Has recovery received testing?
These questions help information security support wider business resilience.
Information security objectives make improvement measurable
ISO 27001 requires information security objectives.
Good objectives connect security with business need.
Examples might include:
Improving MFA coverage
Reducing overdue vulnerabilities
Completing supplier security reviews
Improving employee awareness
Reducing excessive administrator access
Improving recovery testing
Closing audit actions more quickly
An objective should provide enough information for management to determine whether progress happened.
This turns improvement into something visible.
Common ISO 27001 mistakes
Businesses can make ISO 27001 harder than necessary.
One mistake involves treating it as a documentation project.
Another involves copying generic policies that do not reflect actual working practices.
Other weaknesses include:
Poorly defined scope
Weak management involvement
Generic risk registers
No clear risk owners
Unclear acceptance criteria
Annex A treated as a checklist
Controls marked complete without evidence
Internal audit performed only as a formality
Management review with no meaningful decisions
Employee awareness ignored
Supplier security overlooked
Corrective actions left open
Successful ISO 27001 implementation should make the organisation’s security easier to understand, not more confusing.
Start with a gap review
A gap review can help the organisation understand its current position.
Compare existing arrangements against ISO 27001 requirements.
Identify what already works.
Determine which processes need improvement.
Review existing security technology.
Look at policies.
Assess risk management.
Review supplier arrangements.
Check training.
Examine evidence.
This prevents organisations from replacing good existing processes unnecessarily.
The objective should involve building the ISMS around the business rather than building a parallel compliance operation.
Keep control ownership clear
Controls work better when somebody understands responsibility for them.
The risk owner and control owner do not always need to be the same person.
For example, a senior manager may own the business risk associated with customer service availability.
An IT manager may own backup and recovery controls.
A procurement manager may own supplier assessment activity.
Human resources may own employee screening and leaver processes.
Clear ownership helps ensure that controls continue operating after certification.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from specialist information security consultancies, managed service providers, audit professionals and platform-led compliance providers.
UK Cyber Compliance provides ISO 27001 certification support through an automated and AI-driven platform.
Its current platform provides guided risk management, control tracking, live compliance visibility and audit-ready documentation.
The platform also helps businesses manage the relationship between risk assessments, controls, policies, evidence and ongoing compliance activity.
A capable consultancy partner should help the organisation understand ISO 27001 rather than simply produce documents on its behalf.
Management should still understand:
Scope
Risk
Control decisions
Responsibilities
Evidence
Audit findings
Improvement activity
The strongest result is an ISMS that the organisation can continue operating after certification.
How UK Cyber Compliance supports ISO 27001
Traditional ISO 27001 projects can become difficult when risk registers, policies, control records, audit findings and evidence sit in separate spreadsheets and folders.
A central platform can simplify the work.
UK Cyber Compliance states that its platform uses AI-powered automation to reduce manual compliance activity and provide real-time insights. It supports ISO 27001 through risk management and audit-ready documentation.
Current platform information also describes guided risk assessment, residual risk tracking and control management.
This can help organisations understand:
Which requirements remain incomplete
Which risks need treatment
Who owns actions
Which controls apply
What evidence exists
Where gaps remain
How close the organisation is to audit readiness
Technology can organise the process, but accountable people still need to make information security decisions.
A practical ISO 27001 readiness checklist
Before seeking certification, ask whether the organisation can answer these questions clearly:
- Have we defined our ISMS scope?
- Do we understand the needs of relevant interested parties?
- Does senior management support the ISMS?
- Have we defined security responsibilities?
- Do we have a consistent risk assessment method?
- Have we identified meaningful information security risks?
- Have we established risk acceptance criteria?
- Does every important risk have an owner?
- Have we planned treatment for unacceptable risks?
- Have we determined the controls we need?
- Have we reviewed all 93 Annex A controls?
- Have we prepared the Statement of Applicability?
- Can we justify our control decisions?
- Do our policies reflect real working practices?
- Have relevant employees received appropriate awareness?
- Can we demonstrate that controls actually operate?
- Do we monitor information security performance?
- Have we completed internal audit?
- Has management reviewed the ISMS?
- Do nonconformities receive corrective action?
- Can we demonstrate continual improvement?
- Is audit evidence organised and accessible?
Clear answers indicate that the business has moved beyond documentation and developed a working management system.
Making ISO 27001 useful for the business
Everything you need to know about ISO 27001? ultimately comes back to one idea: information security should operate as a managed business process.
Understand what information matters.
Understand what could go wrong.
Assess the risk.
Decide which exposure requires action.
Select appropriate controls.
Give people clear responsibilities.
Create policies that employees can actually follow.
Protect information through organisational, people, physical and technological measures.
Keep evidence.
Measure performance.
Audit the system.
Give management visibility.
Correct problems.
Improve as the organisation changes.
ISO/IEC 27001:2022 gives organisations an internationally recognised framework for doing exactly that. ISO confirms that certification can provide additional confidence to customers and other interested parties, while implementation itself can deliver value even when an organisation does not seek certification.
UK Cyber Compliance provides an automated and AI-driven platform that helps businesses bring the different parts of ISO 27001 together, including risks, controls, policies, evidence and audit readiness.
When implemented properly, ISO 27001 gives a business much more than an audit certificate. It creates a repeatable way to understand information security risk, protect valuable information, respond to changing threats, demonstrate assurance to customers and continuously strengthen the organisation’s security management.

