ISO/IEC 27001 is the world’s most widely adopted standard for managing information security, yet it is frequently misunderstood. Many Australian organisations assume it is a checklist of technical controls or a one-off audit. It is neither. It is a framework for building and continually improving a management system that keeps your information secure as your business and threat landscape change.
This guide explains what ISO 27001 actually requires, how its parts fit together, and what it means specifically for organisations operating in the Australian regulatory and commercial environment.
What ISO 27001 actually is
ISO/IEC 27001 is published jointly by the International Organization for Standardization and the International Electrotechnical Commission. The current edition is ISO/IEC 27001:2022. At its heart, the standard requires you to establish, implement, maintain and continually improve an Information Security Management System, commonly abbreviated to ISMS.
An ISMS is not a piece of software. It is the set of policies, processes, roles, risk decisions and records that together govern how your organisation protects the confidentiality, integrity and availability of its information. The standard is technology-neutral and sector-neutral by design, which is why it is used by banks, councils, software vendors, hospitals and manufacturers alike.
A crucial point that trips up many newcomers: certification is granted against the management-system clauses of the standard, not against a fixed control list. You are being assessed on whether your ISMS is genuinely operating and improving, not merely on whether you have ticked off controls.
The structure: clauses and Annex A
ISO 27001 is built in two parts. The numbered management clauses (clauses 4 through 10) contain the mandatory requirements, and Annex A provides a reference set of security controls.
- Clause 4 – Context of the organisation: understand internal and external issues, interested parties and the scope of your ISMS.
- Clause 5 – Leadership: top management must demonstrate commitment, set policy and assign responsibilities.
- Clause 6 – Planning: conduct risk assessment and risk treatment, and set security objectives.
- Clause 7 – Support: resources, competence, awareness, communication and documented information.
- Clause 8 – Operation: actually run the risk treatment and operational controls.
- Clause 9 – Performance evaluation: monitoring, internal audit and management review.
- Clause 10 – Improvement: handle nonconformities and drive continual improvement.
These clauses are non-negotiable. You cannot pick and choose among them. Annex A, by contrast, is a menu of controls you select from based on your risk assessment.
The four control themes and 93 controls
The 2022 version reorganised Annex A into 93 controls grouped under four themes. This was a significant change from the 2013 edition, which had 114 controls across 14 domains. If your organisation is still working from the older structure, our overview of what changed between the 2022 and 2013 versions explains the differences and your transition obligations.
The four themes are:
- Organizational controls (37 controls): policies, supplier relationships, threat intelligence, incident management and information classification.
- People controls (8 controls): screening, terms of employment, awareness training, disciplinary processes and remote-working arrangements.
- Physical controls (14 controls): secure areas, equipment protection, clear desk and clear screen, and secure disposal.
- Technological controls (34 controls): access control, cryptography, logging, network security, secure development and data leakage prevention.
This grouping deliberately broadens the focus beyond technology. Information security failures in Australian organisations are at least as likely to stem from a misconfigured supplier relationship or an untrained employee as from a missing firewall rule.
A point worth emphasising is that Annex A is a reference set, not a mandatory checklist. You do not have to implement all 93 controls. You implement the controls your risk assessment tells you are necessary, and you justify any you exclude. This is the opposite of how many people first imagine the standard works. It is what makes ISO 27001 scalable from a ten-person consultancy to a multinational bank: the control set flexes to the organisation’s actual risk profile rather than imposing a fixed template.
The Plan-Do-Check-Act cycle
Underpinning the whole standard is a philosophy of continual improvement, often described through the Plan-Do-Check-Act cycle. You plan your security objectives and controls, you implement and operate them, you check performance through monitoring and internal audit, and you act to correct problems and improve. The management clauses map onto this cycle directly.
This matters because it explains why an ISMS is never finished. A certificate is a snapshot that the cycle is turning, not a permanent declaration that you are secure. Threats evolve, your business changes, and the system is expected to adapt with them. Organisations that internalise this tend to get far more genuine security value from certification than those that treat it as a one-time hurdle.
Risk assessment and the Statement of Applicability
The engine of an ISMS is risk. You cannot select controls sensibly until you understand what you are protecting and what could go wrong. A structured cybersecurity risk assessment identifies your information assets, the threats and vulnerabilities they face, and the likelihood and impact of each risk.
From that assessment you produce a risk treatment plan: for each significant risk you decide whether to treat it (apply controls), accept it, avoid it or transfer it. The controls you select to treat risks are then documented in the Statement of Applicability, or SoA.
The SoA is one of the most important documents in the entire system. It lists every Annex A control, states whether it applies, and justifies any exclusions. Auditors scrutinise it closely because it demonstrates that your control selection is driven by genuine risk decisions rather than copied from a template.
Why ISO 27001 matters in the Australian context
While ISO 27001 is voluntary and not Australian law, it has become a practical requirement in several markets. Government procurement at federal, state and local levels increasingly favours or mandates certified suppliers. Enterprises conducting cyber due diligence on vendors routinely ask for evidence of certification before signing contracts.
It also sits alongside Australia’s domestic frameworks rather than competing with them. The Australian Signals Directorate’s Essential Eight maturity model maps neatly into the technological controls of Annex A, and for regulated financial entities, the controls support obligations under APRA CPS 234. Many organisations find that one well-designed ISMS lets them satisfy several of these expectations at once.
For councils and agencies in particular, certification provides independent assurance to constituents and oversight bodies that information is being handled responsibly. We work extensively with the public sector on government and council cybersecurity programs that use ISO 27001 as their backbone.
One practical consideration unique to the Australian setting is data residency and privacy. The controls you select must account for obligations under the Privacy Act and, where relevant, state-based information privacy legislation. An ISMS scope that includes personal information should explicitly address where that data is stored and processed, particularly when cloud services route data offshore. ISO 27001 does not dictate these answers, but it forces you to make and document deliberate decisions about them, which is exactly what Australian regulators and enterprise clients increasingly expect to see.
Common misconceptions to avoid
Before committing to a program, it is worth clearing up the misunderstandings that most often derail Australian organisations:
- “It is an IT project.” It is a business management system. IT delivers many controls, but governance, HR, legal, facilities and procurement all have roles.
- “We need every control.” You need the controls your risk assessment justifies, and a defensible rationale for any you exclude.
- “Certification proves we cannot be breached.” It proves you manage security systematically. No certificate eliminates risk; it demonstrates that risk is being governed.
- “It is a once-off.” Surveillance audits and the improvement cycle make it an ongoing commitment over the three-year certificate life.
Getting these expectations right at the outset is half the battle. The organisations that struggle are almost always those that under-estimated the breadth of the standard and tried to run it solely out of the IT team.
Getting started
The most common mistake is to treat ISO 27001 as a documentation exercise to be rushed through before an audit. Certification bodies are well practised at spotting a system that exists only on paper. The system must actually be lived: risks reviewed, incidents logged, training delivered, management reviews held.
A realistic starting point is a gap assessment against the standard, followed by scoping and a risk assessment. From there you can build your control set, your SoA and the supporting records. If you are weighing up whether to build this capability in-house or bring in external expertise, our explanation of what a virtual CISO does may help you decide.
CISO Advisory helps Australian organisations design, implement and certify pragmatic information security management systems that match real risk rather than chase paperwork. If you would like to discuss where to begin, call 07 2112 8502 or get in touch via our contact page.
Frequently asked questions
Is ISO 27001 mandatory in Australia?
No. ISO 27001 is a voluntary international standard, not Australian law. However, many government tenders, financial services contracts and enterprise procurement processes now require or strongly prefer certified suppliers, so in practice it has become a commercial necessity for organisations selling into regulated markets.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard that specifies the requirements for an information security management system. ISO 27002 is a companion guidance document that provides detailed implementation advice for each of the Annex A controls. You certify against 27001 and use 27002 as a practical how-to reference.
How many controls are in ISO 27001:2022?
The 2022 version of Annex A contains 93 controls, reorganised into four themes: Organizational, People, Physical and Technological. This replaced the 114 controls across 14 domains in the 2013 version, with 11 new controls introduced and several older ones merged together.
Do small businesses need ISO 27001?
Not necessarily, but many do pursue it. The standard is deliberately scalable, so a small firm can implement a lean information security management system covering only its genuine risks. Smaller organisations often seek certification to win contracts with larger clients who mandate it as a condition of doing business.
How is ISO 27001 different from the Essential Eight?
The Essential Eight is a prescriptive set of eight technical mitigation strategies from the Australian Signals Directorate. ISO 27001 is a broader management-system standard covering governance, people and physical security as well as technology. They complement each other; the Essential Eight can sit inside an ISO 27001 control set.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.