ASSURANCE DNA · INFORMATION SECURITY

ISO/IEC 27001

A risk-based information-security management system for preserving confidentiality, integrity and availability through governance, treatment, operation and improvement.

Which information risks could prevent the promised service from remaining confidential, accurate and available?
REFERENCEISO/IEC 27001:2022 + Amendment 1:2024CURRENT STATE · 26 JUL 2026Published and current. It specifies requirements for an information-security management system; control selection remains risk-based and context-specific.BID ENTRYQualify · Capture · Map · Assemble · Model · Story · Evidence · Mobilise · Measure

It is an organisational management standard. A certificate cannot prove that the architecture, cloud configuration, people or suppliers proposed in one tender are secure. Source-bounded interpretation: no certification, protected text reproduction or award prediction.

LIVING EXPERIMENT · JOURNEY

The Information Journey

A classified information object travels through bidder, partner, buyer and delivery boundaries. Unowned transfers break the path; verified controls preserve it.

MODEL STATESME · SENSE · APPLYDeterministic teaching model · no award prediction
Organisation size
Depth

ORIGIN × EVOLUTION × CURRENT PRACTICE

Why this reference exists—and what changed.

Technology, data, defence, financial, health, professional-services and public-sector supply organisations handling sensitive or operationally critical information.

01 · 1995–2000

BS 7799 lineage

British information-security practice separated a control code from certifiable management-system requirements.

02 · 2005

ISO/IEC 27001 established

The management-system requirements became an international reference for information-security risk governance.

03 · 2013

Context and risk alignment

The second edition aligned with modern management-system structure and made contextual risk treatment central.

04 · 2022–2024

Third edition and climate amendment

The current edition modernised terminology and alignment with the contemporary control reference; the 2024 amendment added climate consideration.

A certificate is not evidence that every proposed architecture or supplier interface is secure. The bid must map its actual data, risks and residual decisions.

OFFICIAL SOURCE FRESHNESS MONITOR

SOURCE CHECK PENDING

Monthly official-source reachability and change review.

LAST SOURCE CHECKloading…
What this date means

The check records source reachability and a content fingerprint. It does not silently change the page or claim that an edition changed.

PUBLICLY DESCRIBABLE ANATOMY

Every domain gets a specific bid-management translation.

These are navigational interpretations, not substitute clauses. Use the official publication for normative wording.

Open official source ↗
  1. 01

    Information-security context and scope

    Set the bid security scope around actual data, systems, interfaces, locations and parties.

    Evidence object
    Bid ISMS scope and information-flow diagram
    Decision test
    Are demo, transition, support and subcontractor environments inside the declared boundary where relevant?
  2. 02

    Leadership, policy and responsibilities

    Name security decision rights, risk acceptance authority and independent challenge.

    Evidence object
    Security governance and responsibility matrix
    Decision test
    Who may accept a residual risk on behalf of the proposed service?
  3. 03

    Risk assessment and treatment

    Assess threat, vulnerability, consequence and likelihood, then select proportionate treatment.

    Evidence object
    Contract security risk and treatment plan
    Decision test
    Does each selected control respond to a stated risk rather than a generic checklist?
  4. 04

    Competence, communication and controlled information

    Plan competence, awareness, communication and controlled security evidence.

    Evidence object
    Competence plan and security evidence register
    Decision test
    Is sensitive bid material accessible only to people with a current need and obligation?
  5. 05

    Operational security and change

    Operate secure design, supplier, access, change, incident and continuity controls.

    Evidence object
    Security operating model and supplier schedule
    Decision test
    Can a proposed control be performed with the named technology, people and timetable?
  6. 06

    Measurement, audit and management review

    Define monitoring, audit, management review and contract-security reporting.

    Evidence object
    Control-evidence and assurance calendar
    Decision test
    Which evidence proves the control operated—not merely that a policy exists?
  7. 07

    Nonconformity and continual improvement

    Contain incidents and nonconformities, remove causes and update risk treatment.

    Evidence object
    Incident and corrective-action learning record
    Decision test
    Does incident learning change design, supplier assurance or acceptance criteria?

BEFORE × INTERVENTION × AFTER

Worked case · cloud case-management platform

A fictional service processes special-category data across buyer, prime, cloud and support-provider boundaries.

A worked assurance map, not a security certification or penetration-test result.

BEFORE

What the team can observe

The response attaches a certificate and 94-control spreadsheet, but cannot show the data flow, risk owner or applicability of 17 inherited supplier controls.

ISO/IEC 27001 INTERVENTION

What changes in the operating system

The bid scopes the service, models data and trust boundaries, records risk treatment, checks supplier inheritance and names residual-risk acceptance.

Every security claim is linked to a risk, control owner, operating evidence and mobilisation test; non-applicable controls have an explicit rationale.

Data transfers with owner8 / 1515 / 15
Selected controls linked to risk41 / 5858 / 58
Inherited controls verified3 / 1717 / 17
Residual risks awaiting authority60 open

PROPORTIONATE IMPLEMENTATION

Scale the control—not the integrity of the decision.

It is an organisational management standard. A certificate cannot prove that the architecture, cloud configuration, people or suppliers proposed in one tender are secure.

WORKED CASEISO-27001–01Teaching scenario · no claimed outcome
Solo / micro

Use a scoped data-flow, risk register, secure evidence store and independent architecture review.

Flow map, treatment decisions, review note

Bid team

Integrate security owners into solution, supplier, commercial and mobilisation gates.

Risk treatment, SoA mapping, residual acceptance

Enterprise

Reuse ISMS evidence only after contract-specific applicability and freshness checks.

Control operation records, audits, management review

Mark only controls the worked team has actually completed.

01 · Requirement coverageNOT YET OBSERVABLECan every material requirement be located and owned?
02 · Evidence validityNOT YET OBSERVABLEIs proof current, relevant, approved and close to the claim?
03 · Decision integrityNOT YET OBSERVABLEAre authority, assumptions and trade-offs visible?
04 · Review effectivenessNOT YET OBSERVABLEDid independent challenge change the work before release?
05 · Rework exposureNOT YET OBSERVABLEHow much avoidable correction remains?
06 · Control driftNOT YET OBSERVABLECan commitments change without authorisation?
07 · Handover readinessNOT YET OBSERVABLECan delivery accept the promise without reinterpretation?
08 · Learning closureNOT YET OBSERVABLEDid feedback alter the next qualification, evidence or control?