To give it its full title, ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements’ is an international standard which was published by the International Organisation for Standardisation (ISO).  The purpose of the Standard is provide the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS) within the context of your organisation.  This is the Standard organisations can certify against.

The current version of the Standard replaced the 2013 version on 25 October 2022 and is applicable to all organisations, irrespective of type, size or sector.

Download our FREE White Paper “ISO 27001 Essentials”

It’s one thing having the required technical knowledge, it’s another thing for a consultant to apply that knowledge to the context of our organisation. To use a sporting analogy, we view cyber and information security as a marathon not a sprint. I am not a believer in doing everything all at once. Our approach has been risk based and incremental, remediating our biggest risks first before moving on. I believe this approach is far more sustainable and effective. And URM’s consultants fully understand this and are very pragmatic and tailored in their guidance and advice. They know we are not implementing ISO 27001 purely for the certificate, but more as a framework for continual improvement, and at a pace where new systems and processes can be fully understood and absorbed by our team and be business as usual.
Brand distributor
Contact the ISO 27001 Experts Today

5 Must-Dos of Effective ISO 27001 Risk Management

Published on
7 Aug
2026

URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
7/8/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
4/8/2026
ISO 27001 Clause 10.2: Nonconformity and corrective action

URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
30/7/2026
ISO 27001 Clause 7.4: Communication

URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

Read more
"
We've been using URM for our PCI DSS assessments for the last 5 years and we are pleased with their service. The assessment is always completed promptly, the price is competitive, and communication is great. We'll keep using them and are happy to recommend URM to anyone.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.