What processes are required for ISO27001 and what should be in them?
ISO 27001 is often described as a documentation standard, but that description misses an important point. Certification depends on processes that actually operate inside the business.
A policy can explain what should happen. A process explains how the organisation makes it happen consistently.
ISO/IEC 27001:2022 requires an organisation to establish, implement, maintain and continually improve an Information Security Management System, normally shortened to ISMS. ISO describes the standard as a framework for managing information security risk through a combination of people, policies, processes and technology.
That means your organisation needs working processes for understanding its context, assessing information security risk, treating risk, setting objectives, managing competence, monitoring performance, conducting internal audits, completing management reviews and dealing with weaknesses.
Other processes become necessary because of the controls your organisation selects through risk treatment.
These can include access management, supplier security, incident response, backup, vulnerability management, logging, business continuity and secure development.
The important point is that ISO 27001 does not require every process to become a long standalone procedure.
Some processes may operate through an online compliance platform, business workflow, ticketing system, management meeting, HR workflow or technical system.
What matters is consistency, ownership, appropriate evidence and the ability to demonstrate that the process works.
UK Cyber Compliance supports organisations through an automated and AI-driven platform that connects ISO 27001 risk assessment, controls, policies, tasks, evidence and audit readiness within one structured environment.
UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.
Start by understanding what a process means in ISO 27001
A process is a repeatable way of carrying out an activity.
For ISO 27001, it should normally answer several practical questions.
What triggers the activity?
Who owns it?
Who performs it?
What information does that person need?
What steps happen?
What decision needs making?
What evidence remains afterwards?
When does the organisation repeat the activity?
What happens if something goes wrong?
A process does not need unnecessary complexity.
A small business might operate a leaver process through a simple HR notification, an IT checklist and confirmation that access has been removed.
A larger organisation may use an integrated HR and identity management workflow.
Both approaches can work when they achieve the required security outcome and retain appropriate evidence.
what is iso 27001
ISO 27001 is the international requirements standard for information security management systems.
It helps organisations establish a structured approach to protecting the confidentiality, integrity and availability of information.
Confidentiality means information reaches authorised people.
Integrity means information remains accurate and protected against unauthorised alteration.
Availability means authorised people can access information and services when required.
ISO/IEC 27001:2022 uses risk management as a central principle.
An organisation needs to understand what information security risks it faces, evaluate those risks, decide what needs treatment, select appropriate controls and then monitor whether those controls remain effective.
ISO states that organisations across sectors can use ISO 27001 and adapt their risk management approach to their own circumstances.
Processes turn those requirements into normal business activity.
Context review should come before security controls
Clause 4 asks the organisation to understand itself and its operating environment.
This should not become a one-off document created before certification and forgotten afterwards.
Your organisation needs a process for reviewing issues that can affect the ISMS.
That process should consider relevant business changes, technology changes, customer expectations, regulatory developments, contractual commitments, supply-chain dependencies and significant threats.
Following the 2024 amendment, the organisation also needs to determine whether climate change represents a relevant issue for the management system.
What should the context review process include?
The process should identify who carries out the review, what information gets considered, when the review happens and how important changes reach the risk assessment or wider ISMS.
Management meetings can provide a practical route.
For example, an organisation may review context annually and also trigger another review when it acquires another business, moves office, launches a major service, changes an important supplier or enters a new regulated market.
The result should influence the ISMS rather than sitting in isolation.
Interested parties need an ongoing review process
ISO 27001 requires organisations to understand relevant interested parties and their information security requirements.
These parties can include customers, employees, regulators, suppliers, investors, insurers and public-sector clients.
The process should identify relevant parties, capture their information security expectations and determine which requirements the ISMS needs to address.
For example, a customer contract may impose security requirements.
A regulator may create legal obligations.
A cloud supplier may introduce dependency risks.
The organisation should also review the information when circumstances change.
A new major customer with stronger contractual security requirements may affect risk, controls and objectives.
Scope determination needs a controlled process
The ISMS scope establishes the boundary of ISO 27001 certification.
Your organisation needs a reliable process for determining and reviewing that boundary.
The process should consider organisational functions, services, locations, information, systems, interfaces, dependencies and relevant interested party requirements.
Do not artificially exclude something simply because it makes certification harder.
If an excluded system materially affects the security of the services inside scope, the auditor may question the boundary.
Review the scope after significant organisational change.
Acquisitions, new offices, new services, outsourcing decisions and technology changes can all affect it.
Leadership and responsibility need a working governance process
ISO 27001 expects top management to demonstrate leadership and commitment.
That needs more than signing the Information Security Policy.
Your organisation should have a governance process that ensures management receives enough information to make security decisions.
It should also establish clear responsibility for the ISMS.
Management needs visibility of significant risks, incidents, audit findings, objectives, resources and improvement needs.
The organisation should know who owns the ISMS, who owns significant risks and who operates important controls.
Where responsibilities are unclear, security tasks can easily fall between teams.
A good governance process makes ownership visible.
Risk assessment is one of the most important ISO 27001 processes
Risk assessment sits at the heart of the ISMS.
ISO 27001 does not force every organisation to use one particular assessment method. ISO committee guidance makes clear that the organisation needs a method that identifies, analyses and evaluates risk in a consistent way.
UK Cyber Compliance’s current guidance also describes risk assessment as a connected process involving methodology, likelihood, impact, acceptance criteria, ownership, treatment and residual risk.
What should the risk assessment process include?
It should explain how the organisation identifies information security risks.
It should define how likelihood and impact receive assessment.
The method should establish risk acceptance criteria.
Risk owners need assignment.
Results should remain consistent enough to allow comparison.
The organisation also needs to decide when reassessment happens.
Useful triggers include major system changes, serious incidents, important supplier changes, new legal requirements, organisational restructuring and scheduled ISMS review.
Risk assessment should not consist of copying generic threats into a spreadsheet.
Each risk should make sense in the context of the organisation.
Risk acceptance needs its own decision process
Not every risk needs reducing to zero.
Businesses routinely accept some residual risk.
ISO 27001 requires this decision to happen through defined criteria rather than personal opinion.
Your process should establish who can accept risk and at what level.
Lower risks may receive approval from operational owners.
Higher risks might require senior management.
Some risks may not qualify for acceptance because legal, regulatory or contractual obligations require action.
A sensible process should also place a review date on accepted risks.
Risk changes over time.
What seemed reasonable twelve months ago may no longer be acceptable after a technology change or new threat.
Risk treatment turns risk assessment into action
Risk treatment decides what the organisation will do about risks that need further attention.
The organisation determines necessary controls and compares those controls with Annex A to check that relevant measures have not been overlooked.
The process should connect risk directly with action.
For each risk requiring treatment, management should know the chosen action, responsible owner, target date, required control and expected residual risk.
Progress also needs monitoring.
An action that remains open for months without review weakens the credibility of the ISMS.
UK Cyber Compliance describes this relationship as a sequence from risk assessment, through treatment and necessary controls, into the Statement of Applicability and supporting evidence.
Statement of Applicability management is an ongoing process
The Statement of Applicability, or SoA, should not become a static spreadsheet produced just before audit.
It needs management.
ISO/IEC 27001:2022 Annex A contains 93 controls. UKAS states that the current control set contains 93 controls organised across four areas, including 11 controls introduced with the 2022 revision.
Your SoA process should keep control applicability, justification, implementation position and exclusions aligned with the organisation’s current risks.
When a risk changes, the SoA may need review.
When a new control becomes necessary, the SoA needs updating.
When a control no longer applies, management should record a credible reason.
UK Cyber Compliance describes the SoA as a central connection between risk, treatment, business requirements, legal duties, contracts and operational controls.
Information security objectives need a management process
ISO 27001 requires information security objectives.
The process should go beyond writing goals in an annual document.
Management needs to decide what it wants to improve, how it will measure progress, who owns the objective and when performance receives review.
An objective might focus on reducing overdue security actions, improving access review completion, increasing staff awareness or improving supplier security review.
The process should identify the target, responsible owner, measurement method and follow-up action.
Management should then review performance.
If an objective repeatedly misses its target, the organisation should determine why and decide what needs changing.
Change planning protects the ISMS from uncontrolled decisions
Changes can affect information security even when they appear primarily operational.
New systems, suppliers, business services, offices, acquisitions and working practices can all alter risk.
Your ISMS therefore needs a way to consider security when significant changes occur.
A practical change process should ask whether the change affects scope, risks, controls, legal obligations, suppliers, documentation or evidence.
The earlier security becomes part of the decision, the easier it becomes to manage.
Adding security after a major system has already gone live creates unnecessary difficulty.
Resource allocation should become part of normal planning
Security controls need people, time and technology.
Senior management should have a process for identifying what the ISMS requires and approving appropriate resources.
This might happen through annual budgeting, management review, project approval or risk treatment planning.
The key issue is traceability.
If a high risk needs treatment but management has provided no resources to address it, the ISMS may struggle to demonstrate effective risk management.
Resource decisions should connect with business priority and risk.
Competence needs more than awareness training
Clause 7 requires organisations to ensure that people performing work affecting information security have appropriate competence.
The organisation needs a process for determining what competence each relevant role requires.
That may involve qualifications, experience, internal training, professional development or role-specific instruction.
The process should identify gaps and address them.
For example, an employee responsible for internal audit needs enough audit knowledge to perform the role effectively.
An administrator may need technical security competence.
Managers who accept information security risks need to understand the implications of those decisions.
Evidence should demonstrate relevant competence.
Security awareness needs to operate throughout the year
Awareness should not stop after an annual online course.
Employees need to understand the Information Security Policy, their responsibilities and how their behaviour contributes to the ISMS.
A useful awareness process can include induction, regular security communications, phishing exercises, team briefings and reminders following significant incidents.
The process should also measure whether people understand the messages.
Training completion alone does not always demonstrate understanding.
An auditor may speak directly with employees about incident reporting, information handling or security responsibilities.
Communication needs structure
ISO 27001 requires the organisation to determine relevant internal and external communications relating to the ISMS.
This means deciding what needs communicating, when, to whom and by whom.
The process might cover security incidents, policy changes, customer notifications, regulator communications, supplier issues and internal security alerts.
Responsibility matters.
During a serious incident, confusion over who communicates with customers or authorities can cause delays.
Predefined communication responsibilities make response easier.
Documented information needs control
An ISMS generates policies, procedures, risk records, audit reports, meeting records, evidence and many other documents.
Your organisation needs a process for controlling this information.
The process should make current information identifiable and accessible to authorised people.
It should also manage review, approval, access, retention, protection and disposal where relevant.
Conflicting copies create risk.
If employees can find three versions of the same security procedure, they may follow the wrong one.
Central management helps reduce this problem.
Operational planning connects management decisions with real work
Clause 8 moves the ISMS from planning into operation.
The organisation needs to operate the processes required to meet information security requirements and carry out the actions established through planning.
This means risk treatment cannot stop at a plan.
Controls have to operate.
Responsibilities must be carried out.
Evidence needs to show that the organisation follows its processes.
For example, if the organisation’s controls require access reviews, those reviews need to happen.
If supplier assessments are necessary, they need completion.
If backups require testing, recovery testing should take place.
Access management is a major supporting process
Access control often becomes one of the most important operational processes in an ISMS.
The process should govern how access receives approval, modification, periodic review and removal.
It should cover normal user accounts and privileged access.
Joiners need appropriate access.
Employees moving roles need permissions reviewed.
Leavers need access removed promptly.
Administrator access should remain limited according to business need.
Evidence can include approvals, access reviews, account records and removal confirmation.
The policy describes the rules.
The process makes those rules happen.
Supplier security needs a lifecycle process
Suppliers can create direct and indirect information security risk.
The organisation should manage that risk from supplier selection through termination.
A suitable process begins with understanding what the supplier will access and how important the service is.
Higher-risk suppliers normally need deeper security due diligence.
Contractual security requirements should reflect the risk.
The organisation then needs ongoing review where appropriate.
Significant supplier changes should trigger reassessment.
The exit process also matters.
Access should be removed and organisational information returned or securely deleted where required.
Incident management must work before an incident happens
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous twelve months, representing approximately 612,000 UK businesses. Medium businesses reported 65 per cent and large businesses 69 per cent.
Only 25 per cent of businesses reported having a formal incident response plan.
Those figures make incident management an important practical process.
The organisation should establish how employees report suspected incidents.
Someone needs responsibility for assessment.
The process should cover escalation, containment, investigation, recovery and communication.
It should also include learning afterwards.
An incident should lead to risk review or corrective action when it reveals a weakness.
Vulnerability management turns technical weaknesses into managed risk
Technology changes constantly.
New vulnerabilities appear in operating systems, applications, cloud services and network equipment.
A vulnerability management process helps the organisation identify and respond to those weaknesses.
The process should establish information sources, responsibilities, assessment criteria, remediation priorities and exception handling.
High-risk weaknesses should receive faster attention than minor issues.
Where remediation cannot happen immediately, the organisation may need a formal risk decision and additional controls.
Tracking matters.
Finding vulnerabilities without managing remediation does not reduce risk.
Backup and recovery need a repeatable process
Backups are only useful when recovery works.
A good process identifies what information needs protection, how frequently backup happens and who monitors successful completion.
Failures need investigation.
Access to backup information needs protection.
Recovery testing should happen at planned intervals.
The organisation should record test results and improvement actions.
A dashboard saying that a backup job succeeded provides useful information.
A successful recovery test gives stronger evidence that the organisation can restore the information when required.
Logging and monitoring need a response process
Many organisations collect large volumes of logs but do little with them.
ISO 27001 security monitoring works best when the organisation knows what it needs to observe and what happens when something unusual appears.
The process should establish relevant event sources, responsibilities, alert handling, escalation and retention expectations.
An alert needs an owner.
Important events should enter incident management when appropriate.
Monitoring can also provide evidence that other controls work.
Asset management provides the foundation for many controls
It is difficult to protect information and technology that nobody knows exists.
Asset management should therefore establish how the organisation identifies important information and associated assets, assigns ownership and keeps records current.
The process can cover equipment, applications, cloud services and information.
New assets should enter the inventory.
Retired assets should receive appropriate disposal.
Ownership changes should be recorded.
Regular review helps identify forgotten systems and services.
Human resources processes should connect with security
Employees move through a lifecycle from recruitment to departure.
Security needs to connect with that lifecycle.
Before employment, relevant checks and contractual requirements may apply.
During employment, people need awareness and appropriate access.
Role changes need permission review.
Termination needs prompt access removal and return of organisational assets.
HR and IT should coordinate.
A leaver process fails when HR closes its records but cloud accounts remain active.
Business continuity should include information security
Operational resilience is closely connected with information security.
An organisation should understand which systems, information and suppliers support critical services.
The continuity process should identify responsibilities, recovery priorities, communications and testing.
Security should not disappear during disruption.
Emergency workarounds can create new risks if nobody considers authentication, information handling or access control.
Testing provides valuable evidence.
Exercises also identify weaknesses before a real disruption.
Secure development becomes important where software is created
Organisations involved in software or system development may need a secure development process.
Security requirements should enter development activity early.
The process can address security requirements, coding practice, testing, change control, access to source code, external components and release approval.
Security testing should match risk.
Development environments also need appropriate separation from live services where relevant.
If your organisation performs no relevant development activity, some controls may not apply.
The Statement of Applicability should explain the reasoning.
Internal audit is a mandatory management process
Internal audit gives the organisation an independent check on whether the ISMS meets its own requirements and ISO 27001.
The process should establish an audit programme based on importance, previous findings, change and risk.
Auditors need appropriate objectivity.
Each audit should have a defined scope and criteria.
Evidence should receive sampling.
Findings need recording.
Nonconformities require follow-up.
Internal audit should challenge the management system rather than merely confirm that documents exist.
UK Cyber Compliance guidance also treats internal audit as a key part of checking whether controls, the risk register and the Statement of Applicability remain aligned.
Management review gives leadership formal oversight
Management review should bring the major elements of the ISMS together.
Senior management needs a planned process for reviewing performance and deciding what needs attention.
The review should consider relevant changes, objectives, monitoring information, audit results, risk status, treatment progress, incidents, interested party feedback, resources and improvement opportunities.
The result should include decisions.
Those decisions may involve additional resources, changed objectives, new treatment actions or improvements to the ISMS.
A meeting record showing that management reviewed meaningful security information provides much stronger evidence than a document signed without discussion.
Monitoring and measurement tell management whether the ISMS works
The organisation should decide what information it needs to evaluate performance.
Useful measures depend on the business.
One organisation may monitor overdue high-risk actions.
Another may track access review completion, security incident trends, vulnerability remediation or supplier assessment completion.
The process should identify what gets measured, who owns the measure, how often management reviews it and what happens when performance falls below expectation.
Metrics need a purpose.
Collecting large volumes of data that nobody uses does not strengthen the ISMS.
Nonconformity and corrective action drive improvement
Problems will occur.
ISO 27001 does not require an organisation to pretend otherwise.
What matters is how it responds.
The corrective action process should identify the problem, address immediate effects where necessary and determine whether action is required to prevent recurrence.
The organisation should consider the cause rather than merely fixing the visible symptom.
An owner needs assignment.
Actions need completion.
The organisation should then check whether the corrective action worked.
Repeated findings can indicate that previous corrective action failed to address the real cause.
Continual improvement should become normal business behaviour
Continual improvement is not one annual project.
It comes from risk reviews, incidents, internal audits, management review, monitoring, customer feedback and corrective action.
When the organisation identifies a weakness, it should decide how to improve.
When new risks emerge, it should reassess controls.
When business changes make an existing process inefficient, it should adapt.
ISO states that continual improvement forms part of the core purpose of ISO/IEC 27001.
This keeps the ISMS relevant rather than allowing it to become a static certification exercise.
Who needs iso 27001 certification
ISO 27001 can support organisations across the private, public and voluntary sectors.
It can become particularly useful for businesses that handle sensitive customer information, depend heavily on digital services, work in regulated supply chains or need to demonstrate information security assurance to customers.
Technology providers commonly pursue certification, but ISO states that the standard applies across economic sectors.
Certification may also help where customer contracts, procurement processes or tender requirements ask for independent information security assurance.
Not every organisation needs certification.
Some businesses implement ISO 27001 principles without pursuing an external certificate.
The decision should reflect risk, customer expectations and commercial requirements.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assessment of an organisation’s ISMS against ISO/IEC 27001.
ISO publishes the standard but does not certify individual organisations.
An independent certification body conducts the assessment.
In the UK, organisations often seek certification from a body accredited by UKAS.
Certification examines whether the ISMS meets the requirements within the stated certification scope and whether the organisation operates the system effectively.
The certificate therefore represents more than a collection of policies.
It demonstrates that an independent auditor has assessed the organisation’s management system.
ISO 27001 Certification Levels
ISO 27001 does not use formal bronze, silver, gold or similar certification levels.
The organisation defines its certification scope and demonstrates conformity against the standard.
The external audit process usually progresses through Stage 1 and Stage 2, followed by ongoing surveillance and later recertification.
Stage 1 examines readiness and core ISMS arrangements.
Stage 2 looks more deeply at implementation and effectiveness.
Ongoing assessment then checks that the management system continues to operate.
The organisation should therefore build processes that work continuously rather than processes created only for the initial audit.
How the Certification Works
The organisation normally starts by understanding its context, interested parties and ISMS scope.
Leadership establishes direction and responsibility.
The organisation creates a risk assessment method, evaluates information security risks and decides what needs treatment.
Necessary controls are selected and compared with Annex A.
The Statement of Applicability records those decisions.
Processes and controls then need implementation.
Evidence begins to accumulate through normal operation.
The organisation monitors performance, completes internal audit and conducts management review.
Corrective actions should address identified weaknesses.
An external certification body then carries out the certification assessment.
Stage 1 focuses on readiness.
Stage 2 tests operation.
The auditor can sample records, interview employees and trace processes from requirement through to evidence.
A strong organisation can explain not only what its process says but also how it works in everyday business.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers, internal audit professionals and platform-led providers.
Useful support should help the organisation understand its own ISMS rather than create a system only the consultant understands.
A capable provider can support context assessment, ISMS scope, risk assessment, treatment, controls, the Statement of Applicability, policies, processes, evidence, internal audit readiness and management review.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform.
Its current published information describes guided risk assessment, residual risk tracking, control management, AI-supported policy generation, evidence management and audit readiness.
The platform also helps connect risks, controls, ownership, documentation and evidence rather than leaving them spread across unrelated spreadsheets and folders.
Do not build separate processes when integration works better
ISO 27001 becomes much easier when information security fits into existing business routines.
You do not always need to create a completely separate ISO process.
Employee onboarding can include access approval.
The leaver process can include account removal.
Procurement can include supplier security review.
Project management can include information security risk assessment.
Change management can include security impact review.
Management meetings can include security objectives and risk.
UK Cyber Compliance’s current guidance also recommends integrating ISMS activities into normal business routines rather than creating unnecessary parallel administration.
This approach makes ISO 27001 more sustainable.
Keep each process simple enough to use
A beautifully documented process has little value if employees ignore it.
Processes should fit the organisation.
Clear ownership matters.
Triggers should be obvious.
Steps should make sense.
Evidence should be easy to retain.
Escalation should be understandable.
Review points should be defined.
The best process often feels like normal business activity with information security built into it.
Build one connected ISMS rather than isolated workflows
ISO 27001 processes should support one another.
Context influences risk.
Risk determines treatment.
Treatment determines necessary controls.
Controls influence the Statement of Applicability.
Processes operate those controls.
Evidence shows that processes happened.
Monitoring measures performance.
Internal audit checks conformity.
Management review evaluates the whole system.
Corrective action addresses weaknesses.
Improvement then feeds back into the ISMS.
That connection is what turns ISO 27001 from a set of documents into a working management system.
The UK Government’s latest cyber security survey provides a useful reminder of why this matters. Forty-three per cent of UK businesses identified a cyber breach or attack during the previous twelve months, while 29 per cent of businesses that experienced breaches or attacks said incidents happened at least weekly.
Strong ISO 27001 processes give an organisation a structured way to identify risk, make decisions, operate controls and respond when something changes.
UK Cyber Compliance helps businesses manage these activities through an automated and AI-driven ISO 27001 platform.
The aim should not be to create the greatest possible number of processes.
The aim should be to make every necessary process clear, repeatable, owned, measurable and supported by evidence.
When those processes become part of normal business operation, certification becomes easier to manage and the ISMS becomes genuinely useful beyond audit day.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

