ISO 27001: Information Security Is a Business Issue, Not Just an IT Issue

Information security is often handed to the IT team, but your biggest risks can exist across HR, finance, operations, suppliers and everyday working practices. This guide explores why ISO 27001 should be treated as a business-wide responsibility, how an effective Information Security Management System can help, and the benefits of an ISO consultant's support when…

ISO 27001: Information Security Is a Business Issue, Not Just an IT Issue

Primary keyword: ISO 27001 information security
Secondary keyword: Benefits of an ISO consultant’s support

The biggest information security risk may not be sitting in your IT department

When people hear the words “information security”, many immediately think about IT.

Passwords. Computers. Firewalls. Hackers. Software.

That makes sense. Technology plays a big part in keeping information safe.

But there is a problem with treating information security as an IT issue alone.

Your IT team cannot control every email that gets sent. They cannot decide who should have access to every document. They cannot stop a member of staff leaving sensitive paperwork on a desk. They cannot make sure every supplier handles your information correctly. And they cannot decide how your business should respond when something goes wrong.

Those are business issues.

Information moves through almost every part of an organisation.

Finance holds payment and banking information.

HR handles personal and sensitive employee information.

Sales teams collect customer details.

Managers have access to reports, contracts and business plans.

Operations teams may hold information about suppliers, processes and customers.

Senior leaders make decisions about who can access information, how risks are managed and how much the business invests in protecting itself.

Information security therefore belongs to everyone.

That is one of the important lessons behind ISO 27001 information security.

ISO 27001 is not simply about protecting computers. It is about creating a structured way to identify information risks, decide what needs protecting and put suitable controls in place.

And that requires much more than the IT department.

Information is one of your business assets

Think about what would happen if your business lost access to its information tomorrow morning.

Could you contact your customers?

Could your employees work?

Could you raise invoices?

Could you pay suppliers?

Could you access contracts?

Would you know what work was due to be completed?

Could you prove what had already been done?

For many organisations, losing access to important information would quickly affect normal business.

Now consider another problem.

What if you could still access the information, but someone else could access it too?

Customer records might be seen by someone who should not see them.

Commercial information could be shared outside the business.

An employee could accidentally send sensitive information to the wrong person.

A supplier could have access to more information than they need.

Again, these are not simply IT problems.

They can affect customers, employees, contracts, reputation and the ability of the organisation to operate.

This is why information needs to be treated as a valuable business asset.

You protect your buildings.

You protect your equipment.

You protect your money.

Your information deserves the same thought.

What does ISO 27001 actually help a business do?

ISO 27001 provides a framework for an Information Security Management System, often shortened to ISMS.

That might sound complicated.

The basic idea is much simpler.

An organisation needs to understand what information it has, what could happen to it and what needs to be done to protect it.

The aim is to protect three important things: confidentiality, integrity and availability.

Confidentiality means information is only available to people who should be able to see it.

Integrity means information stays correct and is not changed in an unauthorised way.

Availability means information is there when authorised people need it.

All three matter.

There is little benefit in having perfectly confidential information if nobody in the business can access it when it is needed.

Equally, information being available is not enough if it has been changed and can no longer be trusted.

ISO 27001 encourages organisations to look at information security as a whole.

That means considering people, processes, technology, suppliers, physical locations and leadership decisions.

Technology is part of the picture.

It is not the whole picture.

Your people are part of information security

Imagine a business spends heavily on security software.

It has secure systems, strong technical controls and experienced IT staff.

Then an employee receives an email that appears to come from their manager.

The email asks for sensitive information.

The employee sends it.

The technology may have been strong, but the information was still put at risk.

Now imagine somebody leaves confidential paperwork in a meeting room.

Or a former employee still has access to a system because nobody told IT that their access should be removed.

Perhaps an employee saves business documents somewhere they should not because it is quicker and easier.

These situations show why information security has to involve people.

Employees need to understand what is expected of them.

They need clear processes.

They need suitable training.

Most importantly, they need to understand why the rules exist.

Simply telling people not to do something is rarely enough.

Good information security should help people make better decisions.

If an unusual email arrives, do they know what to do?

If they accidentally send information to the wrong person, do they know who to tell?

If they see something that does not look right, are they comfortable reporting it?

If somebody asks for access to information, do employees know whether they are allowed to provide it?

These everyday decisions matter.

A strong Information Security Management System helps make those decisions clearer.

Senior management cannot hand information security over to IT

Leadership is another reason ISO 27001 cannot sit entirely within the IT department.

Senior management has an important role in deciding how information security fits with the organisation.

Leaders decide priorities.

They approve resources.

They decide who has responsibility.

They help determine how much risk the business is prepared to accept.

They also set the tone.

If senior managers ignore information security processes because they are inconvenient, employees may start doing the same.

If leaders treat information security as important, staff are more likely to understand that it matters.

This does not mean directors need to become cybersecurity experts.

They do need to understand the risks facing their organisation.

Management should be able to ask sensible questions.

What information is most important to us?

What would happen if we lost it?

Who has access to it?

What are our biggest risks?

What happens when somebody leaves the business?

How do we manage information held by suppliers?

What would we do if there were an information security incident?

These are business questions.

IT may help answer some of them, but responsibility cannot simply be passed to IT.

Information security reaches every department

One of the most useful exercises an organisation can do is follow information through the business.

Take HR as an example.

HR may hold names, addresses, bank information, employment records, absence information and other personal details.

Who can see those records?

Where are they stored?

How are they shared?

What happens when somebody leaves?

How long is information kept?

How is old information safely removed?

Now look at finance.

There may be bank details, invoices, payment information and commercially sensitive records.

Sales may hold customer contact information, proposals and contracts.

Operations may hold supplier information, project documents and customer records.

Marketing may use customer information or online systems.

Even reception staff may handle visitor details, deliveries and calls asking for information.

Information security touches all of these areas.

That is why creating an ISMS in isolation can cause problems.

If the system is designed by one department without understanding how everybody else works, it may look good on paper but fail in practice.

Good information security has to fit the organisation.

Do you actually know where your information is?

This question can be harder to answer than many businesses expect.

Information can exist in many places.

It may be stored on company servers, laptops, mobile phones, cloud systems, email accounts, shared folders, paper files or third-party platforms.

Copies may also exist.

Someone downloads a document.

Another person emails it.

A third person saves a copy elsewhere.

Before long, the business has several versions of the same information.

Which one is correct?

Who can access each copy?

Does every copy need to exist?

This is where taking a structured approach to ISO 27001 information security can provide real value.

It encourages businesses to understand their information and the risks connected to it rather than simply buying another security product and assuming the problem has been solved.

You cannot properly protect something if you do not know it exists.

Access should be based on need, not convenience

Another common issue is access.

Giving everybody access to everything can seem easier.

People do not have to keep requesting permission.

Nobody gets held up waiting for a file.

But easier does not always mean safer.

Employees should normally have access to the information and systems they need to do their jobs.

That access should also be reviewed when things change.

Someone moves departments.

Their role changes.

They take on new duties.

They leave the business.

Each change can affect what access they need.

Consider an employee who moves from finance into another part of the organisation.

Do they still need access to all the finance records they used previously?

Perhaps not.

Or consider somebody leaving the organisation.

Removing access should form part of the leaving process, rather than relying on someone remembering to send an email to IT.

Again, this demonstrates why information security needs joined-up business processes.

HR knows when an employee is leaving.

The employee’s manager understands their role.

IT can remove technical access.

Different teams need to work together.

Suppliers can create information security risks too

Your information security does not stop at your own front door.

Many organisations rely on external suppliers.

You might use cloud software, outsourced IT support, payroll services, accountants, marketing platforms or other businesses that process or store information for you.

That creates another question.

What happens to your information when another organisation handles it?

Businesses can spend a great deal of time protecting their own systems while giving a third party access to important information without giving the risk enough thought.

ISO 27001 encourages organisations to consider supplier relationships as part of information security.

That does not mean every supplier presents the same risk.

A company supplying office furniture is very different from a company storing customer records.

The important point is to understand the difference.

What information does the supplier have?

Why do they need it?

How is it protected?

What happens if something goes wrong?

What happens to your information when the relationship ends?

Thinking about these questions before there is a problem is far easier than trying to answer them during an incident.

Risk assessment should be about your real business

Risk sits at the heart of ISO 27001.

But risk assessments can easily become paperwork exercises.

A document is created because somebody believes the standard requires one.

Several risks are added.

Some scores are entered.

The document is saved.

Then nobody looks at it until an audit approaches.

That misses the point.

A useful risk assessment should help the business think.

What could actually go wrong?

How likely is it?

What would the effect be?

What are we already doing about it?

Do we need to do more?

The answers will not be identical for every organisation.

A small professional services company may have very different information risks from a manufacturer, medical business or technology provider.

That is why copying another company’s risk assessment is rarely useful.

Your risks need to reflect your organisation.

Your people.

Your systems.

Your customers.

Your suppliers.

And the information you depend on.

Information security is not about trying to remove every risk

No organisation can remove every possible risk.

Trying to do so could make normal work almost impossible.

Imagine a security system that protected information so tightly that employees could barely access anything.

Technically, information might be well protected.

Operationally, the business could grind to a halt.

Good information security needs balance.

The organisation needs to understand its risks and decide how those risks will be treated.

Some risks can be reduced.

Some may be avoided.

Some can be shared or transferred.

Others may be accepted when the remaining level of risk is understood and authorised.

The important part is making informed decisions.

That is very different from simply hoping nothing happens.

What happens when something does go wrong?

Even organisations with strong controls can experience incidents.

A member of staff might make a mistake.

Equipment could fail.

A supplier could experience a problem.

An attacker may find a way through existing controls.

The question is not only whether an incident can happen.

It is also whether your business is ready to respond.

Employees need to know what should be reported.

They need to know who to report it to.

The organisation needs a way to assess what happened, limit the damage and learn from it.

This is another reason information security needs wider business involvement.

An incident may require input from IT, senior management, HR, operations, legal advisers, communications teams or other people.

Waiting until an incident happens to work out everyone’s role can waste valuable time.

Planning in advance creates a clearer response.

ISO 27001 should support the business, not create paperwork for the sake of it

Some businesses worry that ISO 27001 will mean endless documents, complicated processes and rules that make everyday work harder.

That should not be the goal.

Documentation has a purpose when it helps people understand what needs to happen, provides useful evidence or helps the organisation control risk.

Creating documents simply to fill a folder adds little value.

A good ISMS should fit the size and needs of the organisation.

Processes should make sense.

Responsibilities should be clear.

Records should provide useful evidence.

Employees should understand the parts that relate to their work.

The system should help the business manage information security consistently, rather than becoming something everybody ignores until an audit is due.

The benefits of an ISO consultant’s support

ISO 27001 can feel overwhelming when an organisation first looks at it.

This is especially true when the business has good information security practices already but has never put them into a structured management system.

It can be difficult to know where to begin.

This is where the benefits of an ISO consultant’s support can become clear.

A consultant can help an organisation understand what the requirements mean in practical terms.

Rather than simply producing documents, good support should help the business examine what it already does.

Some processes may already work well.

Others may need small changes.

There may be gaps the organisation has not noticed.

The aim should be to build a system around the real business, not force the business into a generic set of templates.

An experienced consultant can also help bring different departments into the process.

That matters because ISO 27001 should not become an IT project.

HR may need to look at joining and leaving processes.

Managers may need to review access and responsibilities.

Procurement may need to consider suppliers.

Senior leaders need to understand risk and their own responsibilities.

IT will still have an important role, but it becomes part of a wider approach.

Consultant support can also provide an outside view.

When people work with the same processes every day, gaps can become difficult to see.

“We’ve always done it that way” can hide risk.

An outside person can ask why a process works in a certain way, what evidence exists and what would happen if something went wrong.

Those questions can be uncomfortable.

They can also be extremely useful.

The best support should leave the organisation with greater understanding, not greater dependence.

Your team should know how the system works and why it exists.

Training should create understanding, not fear

Information security training can sometimes become a list of things employees must not do.

Do not click this.

Do not share that.

Do not use this.

Do not open that.

Rules matter, but understanding matters too.

Employees are more likely to make good decisions when they understand the reason behind a process.

Training should be relevant to their work.

A finance employee may face different risks from someone working in operations.

A manager may have different responsibilities from a new employee.

Senior leaders need a different level of understanding again.

The goal is not to turn everybody into an IT specialist.

It is to help people recognise information security risks and know what action to take.

Internal audits should help you find weaknesses before somebody else does

Internal audits are another important part of an effective management system.

They should not be treated as a test designed to catch people out.

A useful internal audit asks whether the system is working as intended.

Are processes being followed?

Are they effective?

Do employees understand their responsibilities?

Is evidence available?

Have changes created new risks?

Are previous problems really fixed?

Finding an issue internally can be valuable.

It gives the organisation an opportunity to investigate and improve before the weakness causes a bigger problem.

An internal audit that reports “everything is perfect” every year may sound reassuring.

But it should also raise questions.

Businesses change.

People change.

Technology changes.

Suppliers change.

Risks change.

A healthy management system should be capable of finding opportunities to improve.

Information security needs to change with the business

Achieving ISO 27001 certification should not be viewed as the finish line.

The business will continue changing.

New employees join.

Others leave.

New software is introduced.

Suppliers change.

Customers ask for different things.

New threats appear.

Working practices develop.

The ISMS needs to keep pace.

This is why review and continual improvement matter.

A process that worked two years ago may no longer be suitable today.

A risk that once seemed small may have become important.

A system that once held little sensitive information may now contain thousands of customer records.

Information security needs regular attention.

Not panic.

Not constant disruption.

Just consistent review and improvement.

Stop asking whether IT has information security covered

A better question is:

Does our business understand how it protects its information?

That changes the conversation.

It moves information security away from one department and places it where it belongs: across the organisation.

IT remains important.

But so do HR, finance, operations, procurement, managers, employees and senior leaders.

Everyone handles information.

Everyone can affect how well it is protected.

ISO 27001 provides a structured way to bring those pieces together.

It can help an organisation understand its information, identify risks, set clear responsibilities, improve processes and respond more effectively when something goes wrong.

The real value is not simply having a certificate on the wall.

It is knowing that information security is being considered as part of normal business decisions.

Because information security is not something that belongs in the server room.

It belongs in the boardroom, in meetings, in everyday processes and in the choices people make.

A useful next step

Before thinking about certification, take a simple look around your own organisation.

Choose one important piece of information and follow it.

Where does it come from?

Where is it stored?

Who can access it?

Who is responsible for it?

Is it shared with anybody outside the business?

What would happen if it disappeared tomorrow?

What would happen if the wrong person saw it?

And would your employees know what to do if something went wrong?

Those questions can reveal far more than another piece of security software ever could.

If the answers are unclear, that is a useful place to begin.

Information security becomes stronger when it is understood across the whole business, supported by leadership and built into everyday working practices.

That is the real lesson behind ISO 27001.

It is not just an IT issue.

It is a business issue.

Get Started

There has never been a better time to invest in ISO certification. Show your commitment to quality management, the environment or occupational health & safety performance with a UKAS certified ISO certification from Compliant.
Get in Touch

Free Download

Download our free “The ISO process and ongoing Support pdf”