Cybersecurity Glossary
ISO 27001
The international standard for running an information security management system, with certification available.
What ISO 27001 means
ISO 27001 describes a management system: setting scope and objectives, assessing risk, selecting controls, measuring, auditing and improving. Certification is granted by an accredited body after an audit. The scope you choose determines both the effort and the value of the certificate.
Why ISO 27001 matters for small businesses and nonprofits
Certification is usually pursued because customers or tenders require it. For a small organisation it is a real commitment of months and money, so the question is whether it opens revenue that would otherwise be closed.
What to do about ISO 27001
- Define a narrow scope covering the services customers actually ask about
- Judge the cost against the contracts it would unlock, not against a general wish for maturity
- Consider adopting the practices first and deciding on certification later
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.