The 27kay Blog

The 27kay Blog

The 27kay Blog

ISO 27001:2022 Amendment 1 - Climate Action for Businesses

Mar 6, 2024

Discover how the new ISO 27001:2022 Amendment 1 introduces climate action requirements & why startups & businesses must adapt for future success.

ISO 27001 Clause 8.1: ​Operational planning and control

Mar 5, 2024

Learn how to achieve ISO 27001 compliance with expert guidance on operational planning and control (clause 8.1). Get actionable tips, process mapping, and expert consulting advice for a secure ISMS.

ISO 27001 Clause 7.5.3: Control of documented information

Dec 19, 2023

Master Clause 7.5.3 of ISO 27001 & secure your sensitive docs! Startups, SMBs, remote teams - learn essential document control for compliance & infosec. Tips, tools, & FAQs inside!

ISO 27001 Clause 7.5.2: Documented Information - Creating and Updating

Dec 14, 2023

Learn how to appropriately identify, format, review, and approve documents to enhance security, continuity, and compliance outcomes. Outsource documentation to ease the process for startups and small businesses.

ISO 27001 Clause 7.5.1: Documented Information - General Requirements

Dec 12, 2023

Learn what documentation is required by ISO 27001 and how to tailor your ISMS documentation to address your unique information security risks. Understand the consequences of non-compliance and how to effectively review and update your documentation. Get examples of supplemental documentation and seek guidance from an ISO 27001 consultant for thorough compliance.

ISO 27001: A Brief History of the Information Security Standard

Dec 8, 2023

Delve into the fascinating history of ISO 27001, the global gold standard for information security management. Discover its origins, evolution, and enduring relevance in today's dynamic cyber landscape.

ISO 27001 Clause 7.4: Communication

Dec 7, 2023

Ensure data protection and compliance with ISO 27001 by implementing robust internal and external communication strategies outlined in Clause 7.4.

ISO 27001 Clause 7.3: Awareness

Dec 5, 2023

Discover how ISO 27001 Clause 7.3 emphasizes the crucial role of employee awareness in information security. Learn how to transform your workforce into a formidable defense against cyberattacks.

ISO 27001 Clause 7.2: Competence

Nov 30, 2023

Master ISO 27001's Clause 7.2 and build a competent workforce to safeguard your organization's valuable data. Learn how to identify competence gaps, develop effective training programs, and retain evidence of compliance.

ISO 27001 Clause 7.1: Resources

Nov 28, 2023

Discover how to allocate resources effectively for ISO 27001 implementation, avoiding common mistakes and maximizing ROI. Optimize resourcing for long-term ISMS success.

ISO 27001 Clause 6.3: Planning of Changes

Nov 23, 2023

Learn how to plan, document, and execute ISO 27001 ISMS changes in compliance with Clause 6.3 requirements, ensuring ongoing security and compliance.

ISO 27001 Clause 6.2: Information security objectives and planning to achieve them

Nov 16, 2023

Learn how to establish clear, measurable information security objectives for your business to meet ISO 27001 compliance requirements.

ISO 27001 Clause 6.1: Actions to address risks and opportunities

Nov 14, 2023

Learn how to manage risks and opportunities for ISO 27001 compliance, including essential steps such as conducting an information security risk assessment and implementing controls.

Simplify Your ISO 27001 SoA Journey with Our Handy Notion Template

Nov 9, 2023

Overcome the complexity of ISO 27001 SoA creation with our comprehensive Notion template. Streamline your SoA development, collaborate seamlessly, and track progress effortlessly.

ISO 27001 Clause 5.3: Organisational roles, responsibilities and authorities

Nov 2, 2023

Clause 5.3 in ISO 27001 and best practices for assigning, communicating and reporting on information security roles and responsibilities.

ISO 27001 Clause 5.2: Information Security Policy for Your Business

Oct 31, 2023

Learn how to craft an ISO 27001 compliant information security policy. Follow our 7 step guide to meet the requirements in ISO 27001 clause 5.2.

ISO 27001 Clause 5.1: Demonstrating Leadership for Information Security Management

Oct 26, 2023

Learn how leaders establish strategic objectives, allocate resources, communicate importance, ensure outcomes, and promote continual improvement.

ISO 27001 Clause 4.4: Establishing an Information Security Management System

Oct 24, 2023

Learn how to establish an information security management system (ISMS) that complies with ISO 27001 requirements for certification.

ISO 27001 Clause 4.3: Determining the scope of the information security management system

Oct 19, 2023

Learn how to establish the optimal scope for your ISO 27001 ISMS. Follow our 5-step process to define boundaries that align with your business requirements per Clause 4.3.

ISO 27001 Clause 4.2: Understanding the Needs and Expectations of Interested Parties

Oct 17, 2023

Clause 4.2 is key for ISO 27001. Learn how to identify interested parties, determine their security needs, and address requirements through your ISMS.

ISO 27001 Clause 4.1: Understanding Your Organisation's Context

Oct 11, 2023

Clause 4.1 of ISO 27001 requires determining your organisation's internal and external context. This guide explains how to do the assessment right.

Turn Your Team Into Cyber Security Superstars

Oct 5, 2023

This article explores practical tips on improving cyber security through employee awareness training, simulations, policies and rewards.

How to Create an ISO 27001-Compliant Information Security Policy

Sep 28, 2023

Learn the steps to develop an effective information security policy that meets ISO 27001 requirements.

The PDCA Cycle: Guide to Implementing it for ISO 27001

Sep 21, 2023

Learn how the PDCA cycle provides a simple framework for startups and small businesses to implement ISO 27001.

Secure Your Information Assets with the CIA Triad in ISO 27001

Sep 14, 2023

Learn how the confidentiality, integrity, and availability (CIA) triad provides a framework for implementing ISO 27001 information security controls.

ISO 27018 - Strengthening Cloud Data Privacy and Security

Sep 7, 2023

Learn how ISO 27018 works with ISO 27001 and ISO 27002 to provide robust data privacy and security controls tailored for public cloud environments.

Notion: Free ISO/IEC 27001:2022 Update Kit

Sep 5, 2023

The ISO/IEC 27001:2022 Update Kit in Notion includes changes to ISMS, 11 new controls in Annex A, mappings between 2013 and 2022, and a list of merged controls.

ISO 27017 - The Code of Practice for Cloud Security

Aug 31, 2023

ISO 27017 provides guidelines to implement cloud security controls. This guide explores ISO 27017 to help organisations apply it effectively.

C5: A Complete Guide to the Cloud Computing Compliance Criteria Catalogue

Aug 24, 2023

Learn everything you need to know about C5 cloud security attestation - from its purpose and origins to documentation, implementation steps and key takeaways.

Free Tool to Simplify Your ISO 27001:2022 Migration

Aug 18, 2023

Struggling to migrate to ISO 27001:2022? This free customisable Notion template simplifies the transition with step-by-step guidance and key info.

Crafting an Effective Statement of Applicability for ISO 27001 📜

Aug 17, 2023

Learn how to craft an effective ISO 27001 Statement of Applicability (SoA) that fully scopes your information security management system + template.

Demystifying the Context of the Organisation for ISO 27001 📝

Aug 10, 2023

Learn what the Context of the Organisation is in ISO 27001 and how to create one. This guide covers tips for documenting context to inform your ISMS.

The Cultural Revolution in Information Security: Startups, Meet ISO 27001 👋

Jul 19, 2023

Explore how startups can cultivate an infosec culture and bolster defences with ISO 27001, improving business efficiency and trust.

The Rise of AI in Information Security: A Game Changer for Startups and Remote Businesses 🚀

Jul 18, 2023

Explore how AI and ISO 27001 transform information security, bolster data privacy, and help detect cyberattacks for startups and remote businesses.

ISO 27001 for IoT Security: A Guide to Securing Your Connected World

Jul 5, 2023

Learn how ISO 27001 can help you secure your IoT devices and data in an increasingly connected world. This comprehensive guide covers the risks, controls, and benefits of ISO 27001 compliance for IoT deployments.

Document Your Way to ISO 27001:2022 Compliance

May 10, 2023

Key steps for documenting ISO 27001:2022. Learn about mandatory records, ISMS scope, risk management, and tips for effective documentation.

From Information Security to Data Privacy: The Next Level with ISO 27701 Integration

Mar 13, 2023

Learn how to enhance personally identifiable information (PII) protection by integrating ISO 27701 with ISO/IEC 27001 and ISO/IEC 27002.

Embracing Change: Navigating the Key Updates in ISO 27001:2022 for Enhanced Information Security Management

Mar 1, 2023

Discover key updates in ISO 27001:2022, transition roadmap, and how to enhance your organisation's information security management practices.

Boost Your Organisation's Information Security with ISO 27001

Feb 17, 2023

Learn how to implement ISO 27001 and enhance your organisation's information security with this comprehensive guide. Improve data protection, gain a competitive edge, and achieve certification.

Key Data Privacy Standards and Frameworks for Organisations

Jan 31, 2023

Protect your customers' data, safeguard your reputation, and avoid hefty fines by understanding key data privacy regulations, standards, and compliance best practices.

ISO 27001 and GDPR: Protecting Sensitive Information and Ensuring Privacy

Jan 30, 2023

Discover the power of ISO 27001 & GDPR compliance, boosting data protection, trust, business opportunities. Unlock the secrets of cybersecurity.

Master ISO 27001 & SOC 2: Boost Security and Defeat Cybercriminals!

Jan 27, 2023

Discover how to effectively harness ISO 27001 & SOC 2 compliance to enhance business security, protect sensitive data, and outwit cyber threats.

Fortify Your Business: Mastering Information Security with ISO 27001 and Cyber Essentials Certification

Jan 26, 2023

Discover the power of ISO 27001 and Cyber Essentials to safeguard your business against cyber threats and ensure robust information security.

Integrating ISO 27001 and ISO 22301: Aligning Information Security and Business Continuity Management

Jan 25, 2023

Integrating ISO 27001 and ISO 22301 can align information security and business continuity management to optimise resources and manage risks.

New EU Cybersecurity Measures Take Effect: NIS2 Directive and CER Directive Raise the Bar for Information Security Standards

Jan 24, 2023

The NIS2 Directive and CER Directive have entered into force, bringing new rules for cybersecurity for organisations operating within the EU.

Unlock the Benefits of ISO 27001 Certification for Your Small to Medium Business: A Short Summary

Jan 23, 2023

ISO 27001 certification helps SMBs establish robust security measures, gain credibility, manage risks, and comply with regulations.

Understanding the Differences between ISO 31700 and ISO 27701: A Guide to Implementing Comprehensive Privacy Management Systems

Jan 20, 2023

Learn about the key differences and benefits of implementing both standards for comprehensive data protection.

International Privacy Standard: ISO Adopts Privacy by Design as ISO 31700, Offers New Guidelines for Consumer Data Protection

Jan 19, 2023

ISO adopts Privacy by Design as ISO 31700, an international privacy standard, offering new guidelines for consumer data protection.

Why ISO 27001 Certification is a Must-Have for Businesses

Jan 18, 2023

ISO 27001 certification is essential for businesses handling sensitive information. It helps with regulations and builds trust with partners.

The Importance of Security Awareness in the Workplace

Jan 17, 2023

Reduce the risk of cyber attacks with a robust security awareness program. Learn how to build a culture of security and protect your business.

Don't Share Your Personal Information with the Grinch: A Guide to Staying Safe Online this Holiday Season

Nov 24, 2022

Don't share your personal information online! Stay safe online by being cautious of sites, securing your devices, and using VPNs on public Wi-Fi.

Foil the Grinch's Phishing Plans: A Guide to Protecting Yourself from Scams this Holiday Season

Dec 23, 2022

Foil the Grinch plans and protect your sensitive information from scams this holiday season! Learn how to spot and avoid phishing mails and links.

Lock Down Your Accounts with Two-Factor Authentication: A Grinch-Proof Guide for the Holidays

Dec 22, 2022

Lock down your accounts this holiday season with two-factor authentication! Learn how to enable 2FA and protect yourself from phishing attacks.

Don't Let the Grinch Steal Your Data​: Password Managers for a Secure Holiday Season

Dec 21, 2022

Stay jolly & protect your sensitive info with a password manager! Learn about popular options - LastPass, Dashlane, 1Password, Keeper & Bitwarden.

Don't Let the Grinch Steal Your Data​: Tips for a Holly Jolly and Secure Holiday Season

Dec 20, 2022

Keep your sensitive information safe this holiday season with these tips! Use strong passwords, enable 2fa, and avoid phishing.

Coming soon

Dec 6, 2022

Get the latest insights and knowledge on ISO 27001 with 27kay. Stay informed with in-depth articles, news analysis, and valuable resources.

ISO 27001:2022 Amendment 1 - Climate Action for Businesses

Mar 6, 2024

Discover how the new ISO 27001:2022 Amendment 1 introduces climate action requirements & why startups & businesses must adapt for future success.

ISO 27001 Clause 8.1: ​Operational planning and control

Mar 5, 2024

Learn how to achieve ISO 27001 compliance with expert guidance on operational planning and control (clause 8.1). Get actionable tips, process mapping, and expert consulting advice for a secure ISMS.

ISO 27001 Clause 7.5.3: Control of documented information

Dec 19, 2023

Master Clause 7.5.3 of ISO 27001 & secure your sensitive docs! Startups, SMBs, remote teams - learn essential document control for compliance & infosec. Tips, tools, & FAQs inside!

ISO 27001 Clause 7.5.2: Documented Information - Creating and Updating

Dec 14, 2023

Learn how to appropriately identify, format, review, and approve documents to enhance security, continuity, and compliance outcomes. Outsource documentation to ease the process for startups and small businesses.

ISO 27001 Clause 7.5.1: Documented Information - General Requirements

Dec 12, 2023

Learn what documentation is required by ISO 27001 and how to tailor your ISMS documentation to address your unique information security risks. Understand the consequences of non-compliance and how to effectively review and update your documentation. Get examples of supplemental documentation and seek guidance from an ISO 27001 consultant for thorough compliance.

ISO 27001: A Brief History of the Information Security Standard

Dec 8, 2023

Delve into the fascinating history of ISO 27001, the global gold standard for information security management. Discover its origins, evolution, and enduring relevance in today's dynamic cyber landscape.

ISO 27001 Clause 7.4: Communication

Dec 7, 2023

Ensure data protection and compliance with ISO 27001 by implementing robust internal and external communication strategies outlined in Clause 7.4.

ISO 27001 Clause 7.3: Awareness

Dec 5, 2023

Discover how ISO 27001 Clause 7.3 emphasizes the crucial role of employee awareness in information security. Learn how to transform your workforce into a formidable defense against cyberattacks.

ISO 27001 Clause 7.2: Competence

Nov 30, 2023

Master ISO 27001's Clause 7.2 and build a competent workforce to safeguard your organization's valuable data. Learn how to identify competence gaps, develop effective training programs, and retain evidence of compliance.

ISO 27001 Clause 7.1: Resources

Nov 28, 2023

Discover how to allocate resources effectively for ISO 27001 implementation, avoiding common mistakes and maximizing ROI. Optimize resourcing for long-term ISMS success.

ISO 27001 Clause 6.3: Planning of Changes

Nov 23, 2023

Learn how to plan, document, and execute ISO 27001 ISMS changes in compliance with Clause 6.3 requirements, ensuring ongoing security and compliance.

ISO 27001 Clause 6.2: Information security objectives and planning to achieve them

Nov 16, 2023

Learn how to establish clear, measurable information security objectives for your business to meet ISO 27001 compliance requirements.

ISO 27001 Clause 6.1: Actions to address risks and opportunities

Nov 14, 2023

Learn how to manage risks and opportunities for ISO 27001 compliance, including essential steps such as conducting an information security risk assessment and implementing controls.

Simplify Your ISO 27001 SoA Journey with Our Handy Notion Template

Nov 9, 2023

Overcome the complexity of ISO 27001 SoA creation with our comprehensive Notion template. Streamline your SoA development, collaborate seamlessly, and track progress effortlessly.

ISO 27001 Clause 5.3: Organisational roles, responsibilities and authorities

Nov 2, 2023

Clause 5.3 in ISO 27001 and best practices for assigning, communicating and reporting on information security roles and responsibilities.

ISO 27001 Clause 5.2: Information Security Policy for Your Business

Oct 31, 2023

Learn how to craft an ISO 27001 compliant information security policy. Follow our 7 step guide to meet the requirements in ISO 27001 clause 5.2.

ISO 27001 Clause 5.1: Demonstrating Leadership for Information Security Management

Oct 26, 2023

Learn how leaders establish strategic objectives, allocate resources, communicate importance, ensure outcomes, and promote continual improvement.

ISO 27001 Clause 4.4: Establishing an Information Security Management System

Oct 24, 2023

Learn how to establish an information security management system (ISMS) that complies with ISO 27001 requirements for certification.

ISO 27001 Clause 4.3: Determining the scope of the information security management system

Oct 19, 2023

Learn how to establish the optimal scope for your ISO 27001 ISMS. Follow our 5-step process to define boundaries that align with your business requirements per Clause 4.3.

ISO 27001 Clause 4.2: Understanding the Needs and Expectations of Interested Parties

Oct 17, 2023

Clause 4.2 is key for ISO 27001. Learn how to identify interested parties, determine their security needs, and address requirements through your ISMS.

ISO 27001 Clause 4.1: Understanding Your Organisation's Context

Oct 11, 2023

Clause 4.1 of ISO 27001 requires determining your organisation's internal and external context. This guide explains how to do the assessment right.

Turn Your Team Into Cyber Security Superstars

Oct 5, 2023

This article explores practical tips on improving cyber security through employee awareness training, simulations, policies and rewards.

How to Create an ISO 27001-Compliant Information Security Policy

Sep 28, 2023

Learn the steps to develop an effective information security policy that meets ISO 27001 requirements.

The PDCA Cycle: Guide to Implementing it for ISO 27001

Sep 21, 2023

Learn how the PDCA cycle provides a simple framework for startups and small businesses to implement ISO 27001.

Secure Your Information Assets with the CIA Triad in ISO 27001

Sep 14, 2023

Learn how the confidentiality, integrity, and availability (CIA) triad provides a framework for implementing ISO 27001 information security controls.

ISO 27018 - Strengthening Cloud Data Privacy and Security

Sep 7, 2023

Learn how ISO 27018 works with ISO 27001 and ISO 27002 to provide robust data privacy and security controls tailored for public cloud environments.

Notion: Free ISO/IEC 27001:2022 Update Kit

Sep 5, 2023

The ISO/IEC 27001:2022 Update Kit in Notion includes changes to ISMS, 11 new controls in Annex A, mappings between 2013 and 2022, and a list of merged controls.

ISO 27017 - The Code of Practice for Cloud Security

Aug 31, 2023

ISO 27017 provides guidelines to implement cloud security controls. This guide explores ISO 27017 to help organisations apply it effectively.

C5: A Complete Guide to the Cloud Computing Compliance Criteria Catalogue

Aug 24, 2023

Learn everything you need to know about C5 cloud security attestation - from its purpose and origins to documentation, implementation steps and key takeaways.

Free Tool to Simplify Your ISO 27001:2022 Migration

Aug 18, 2023

Struggling to migrate to ISO 27001:2022? This free customisable Notion template simplifies the transition with step-by-step guidance and key info.

Crafting an Effective Statement of Applicability for ISO 27001 📜

Aug 17, 2023

Learn how to craft an effective ISO 27001 Statement of Applicability (SoA) that fully scopes your information security management system + template.

Demystifying the Context of the Organisation for ISO 27001 📝

Aug 10, 2023

Learn what the Context of the Organisation is in ISO 27001 and how to create one. This guide covers tips for documenting context to inform your ISMS.

The Cultural Revolution in Information Security: Startups, Meet ISO 27001 👋

Jul 19, 2023

Explore how startups can cultivate an infosec culture and bolster defences with ISO 27001, improving business efficiency and trust.

The Rise of AI in Information Security: A Game Changer for Startups and Remote Businesses 🚀

Jul 18, 2023

Explore how AI and ISO 27001 transform information security, bolster data privacy, and help detect cyberattacks for startups and remote businesses.

ISO 27001 for IoT Security: A Guide to Securing Your Connected World

Jul 5, 2023

Learn how ISO 27001 can help you secure your IoT devices and data in an increasingly connected world. This comprehensive guide covers the risks, controls, and benefits of ISO 27001 compliance for IoT deployments.

Document Your Way to ISO 27001:2022 Compliance

May 10, 2023

Key steps for documenting ISO 27001:2022. Learn about mandatory records, ISMS scope, risk management, and tips for effective documentation.

From Information Security to Data Privacy: The Next Level with ISO 27701 Integration

Mar 13, 2023

Learn how to enhance personally identifiable information (PII) protection by integrating ISO 27701 with ISO/IEC 27001 and ISO/IEC 27002.

Embracing Change: Navigating the Key Updates in ISO 27001:2022 for Enhanced Information Security Management

Mar 1, 2023

Discover key updates in ISO 27001:2022, transition roadmap, and how to enhance your organisation's information security management practices.

Boost Your Organisation's Information Security with ISO 27001

Feb 17, 2023

Learn how to implement ISO 27001 and enhance your organisation's information security with this comprehensive guide. Improve data protection, gain a competitive edge, and achieve certification.

Key Data Privacy Standards and Frameworks for Organisations

Jan 31, 2023

Protect your customers' data, safeguard your reputation, and avoid hefty fines by understanding key data privacy regulations, standards, and compliance best practices.

ISO 27001 and GDPR: Protecting Sensitive Information and Ensuring Privacy

Jan 30, 2023

Discover the power of ISO 27001 & GDPR compliance, boosting data protection, trust, business opportunities. Unlock the secrets of cybersecurity.

Master ISO 27001 & SOC 2: Boost Security and Defeat Cybercriminals!

Jan 27, 2023

Discover how to effectively harness ISO 27001 & SOC 2 compliance to enhance business security, protect sensitive data, and outwit cyber threats.

Fortify Your Business: Mastering Information Security with ISO 27001 and Cyber Essentials Certification

Jan 26, 2023

Discover the power of ISO 27001 and Cyber Essentials to safeguard your business against cyber threats and ensure robust information security.

Integrating ISO 27001 and ISO 22301: Aligning Information Security and Business Continuity Management

Jan 25, 2023

Integrating ISO 27001 and ISO 22301 can align information security and business continuity management to optimise resources and manage risks.

New EU Cybersecurity Measures Take Effect: NIS2 Directive and CER Directive Raise the Bar for Information Security Standards

Jan 24, 2023

The NIS2 Directive and CER Directive have entered into force, bringing new rules for cybersecurity for organisations operating within the EU.

Unlock the Benefits of ISO 27001 Certification for Your Small to Medium Business: A Short Summary

Jan 23, 2023

ISO 27001 certification helps SMBs establish robust security measures, gain credibility, manage risks, and comply with regulations.

Understanding the Differences between ISO 31700 and ISO 27701: A Guide to Implementing Comprehensive Privacy Management Systems

Jan 20, 2023

Learn about the key differences and benefits of implementing both standards for comprehensive data protection.

International Privacy Standard: ISO Adopts Privacy by Design as ISO 31700, Offers New Guidelines for Consumer Data Protection

Jan 19, 2023

ISO adopts Privacy by Design as ISO 31700, an international privacy standard, offering new guidelines for consumer data protection.

Why ISO 27001 Certification is a Must-Have for Businesses

Jan 18, 2023

ISO 27001 certification is essential for businesses handling sensitive information. It helps with regulations and builds trust with partners.

The Importance of Security Awareness in the Workplace

Jan 17, 2023

Reduce the risk of cyber attacks with a robust security awareness program. Learn how to build a culture of security and protect your business.

Don't Share Your Personal Information with the Grinch: A Guide to Staying Safe Online this Holiday Season

Nov 24, 2022

Don't share your personal information online! Stay safe online by being cautious of sites, securing your devices, and using VPNs on public Wi-Fi.

Foil the Grinch's Phishing Plans: A Guide to Protecting Yourself from Scams this Holiday Season

Dec 23, 2022

Foil the Grinch plans and protect your sensitive information from scams this holiday season! Learn how to spot and avoid phishing mails and links.

Lock Down Your Accounts with Two-Factor Authentication: A Grinch-Proof Guide for the Holidays

Dec 22, 2022

Lock down your accounts this holiday season with two-factor authentication! Learn how to enable 2FA and protect yourself from phishing attacks.

Don't Let the Grinch Steal Your Data​: Password Managers for a Secure Holiday Season

Dec 21, 2022

Stay jolly & protect your sensitive info with a password manager! Learn about popular options - LastPass, Dashlane, 1Password, Keeper & Bitwarden.

Don't Let the Grinch Steal Your Data​: Tips for a Holly Jolly and Secure Holiday Season

Dec 20, 2022

Keep your sensitive information safe this holiday season with these tips! Use strong passwords, enable 2fa, and avoid phishing.

Coming soon

Dec 6, 2022

Get the latest insights and knowledge on ISO 27001 with 27kay. Stay informed with in-depth articles, news analysis, and valuable resources.

ISO 27001:2022 Amendment 1 - Climate Action for Businesses

Mar 6, 2024

Discover how the new ISO 27001:2022 Amendment 1 introduces climate action requirements & why startups & businesses must adapt for future success.

ISO 27001 Clause 8.1: ​Operational planning and control

Mar 5, 2024

Learn how to achieve ISO 27001 compliance with expert guidance on operational planning and control (clause 8.1). Get actionable tips, process mapping, and expert consulting advice for a secure ISMS.

ISO 27001 Clause 7.5.3: Control of documented information

Dec 19, 2023

Master Clause 7.5.3 of ISO 27001 & secure your sensitive docs! Startups, SMBs, remote teams - learn essential document control for compliance & infosec. Tips, tools, & FAQs inside!

ISO 27001 Clause 7.5.2: Documented Information - Creating and Updating

Dec 14, 2023

Learn how to appropriately identify, format, review, and approve documents to enhance security, continuity, and compliance outcomes. Outsource documentation to ease the process for startups and small businesses.

ISO 27001 Clause 7.5.1: Documented Information - General Requirements

Dec 12, 2023

Learn what documentation is required by ISO 27001 and how to tailor your ISMS documentation to address your unique information security risks. Understand the consequences of non-compliance and how to effectively review and update your documentation. Get examples of supplemental documentation and seek guidance from an ISO 27001 consultant for thorough compliance.

ISO 27001: A Brief History of the Information Security Standard

Dec 8, 2023

Delve into the fascinating history of ISO 27001, the global gold standard for information security management. Discover its origins, evolution, and enduring relevance in today's dynamic cyber landscape.

ISO 27001 Clause 7.4: Communication

Dec 7, 2023

Ensure data protection and compliance with ISO 27001 by implementing robust internal and external communication strategies outlined in Clause 7.4.

ISO 27001 Clause 7.3: Awareness

Dec 5, 2023

Discover how ISO 27001 Clause 7.3 emphasizes the crucial role of employee awareness in information security. Learn how to transform your workforce into a formidable defense against cyberattacks.

ISO 27001 Clause 7.2: Competence

Nov 30, 2023

Master ISO 27001's Clause 7.2 and build a competent workforce to safeguard your organization's valuable data. Learn how to identify competence gaps, develop effective training programs, and retain evidence of compliance.

ISO 27001 Clause 7.1: Resources

Nov 28, 2023

Discover how to allocate resources effectively for ISO 27001 implementation, avoiding common mistakes and maximizing ROI. Optimize resourcing for long-term ISMS success.

ISO 27001 Clause 6.3: Planning of Changes

Nov 23, 2023

Learn how to plan, document, and execute ISO 27001 ISMS changes in compliance with Clause 6.3 requirements, ensuring ongoing security and compliance.

ISO 27001 Clause 6.2: Information security objectives and planning to achieve them

Nov 16, 2023

Learn how to establish clear, measurable information security objectives for your business to meet ISO 27001 compliance requirements.

ISO 27001 Clause 6.1: Actions to address risks and opportunities

Nov 14, 2023

Learn how to manage risks and opportunities for ISO 27001 compliance, including essential steps such as conducting an information security risk assessment and implementing controls.

Simplify Your ISO 27001 SoA Journey with Our Handy Notion Template

Nov 9, 2023

Overcome the complexity of ISO 27001 SoA creation with our comprehensive Notion template. Streamline your SoA development, collaborate seamlessly, and track progress effortlessly.

ISO 27001 Clause 5.3: Organisational roles, responsibilities and authorities

Nov 2, 2023

Clause 5.3 in ISO 27001 and best practices for assigning, communicating and reporting on information security roles and responsibilities.

ISO 27001 Clause 5.2: Information Security Policy for Your Business

Oct 31, 2023

Learn how to craft an ISO 27001 compliant information security policy. Follow our 7 step guide to meet the requirements in ISO 27001 clause 5.2.

ISO 27001 Clause 5.1: Demonstrating Leadership for Information Security Management

Oct 26, 2023

Learn how leaders establish strategic objectives, allocate resources, communicate importance, ensure outcomes, and promote continual improvement.

ISO 27001 Clause 4.4: Establishing an Information Security Management System

Oct 24, 2023

Learn how to establish an information security management system (ISMS) that complies with ISO 27001 requirements for certification.

ISO 27001 Clause 4.3: Determining the scope of the information security management system

Oct 19, 2023

Learn how to establish the optimal scope for your ISO 27001 ISMS. Follow our 5-step process to define boundaries that align with your business requirements per Clause 4.3.

ISO 27001 Clause 4.2: Understanding the Needs and Expectations of Interested Parties

Oct 17, 2023

Clause 4.2 is key for ISO 27001. Learn how to identify interested parties, determine their security needs, and address requirements through your ISMS.

ISO 27001 Clause 4.1: Understanding Your Organisation's Context

Oct 11, 2023

Clause 4.1 of ISO 27001 requires determining your organisation's internal and external context. This guide explains how to do the assessment right.

Turn Your Team Into Cyber Security Superstars

Oct 5, 2023

This article explores practical tips on improving cyber security through employee awareness training, simulations, policies and rewards.

How to Create an ISO 27001-Compliant Information Security Policy

Sep 28, 2023

Learn the steps to develop an effective information security policy that meets ISO 27001 requirements.

The PDCA Cycle: Guide to Implementing it for ISO 27001

Sep 21, 2023

Learn how the PDCA cycle provides a simple framework for startups and small businesses to implement ISO 27001.

Secure Your Information Assets with the CIA Triad in ISO 27001

Sep 14, 2023

Learn how the confidentiality, integrity, and availability (CIA) triad provides a framework for implementing ISO 27001 information security controls.

ISO 27018 - Strengthening Cloud Data Privacy and Security

Sep 7, 2023

Learn how ISO 27018 works with ISO 27001 and ISO 27002 to provide robust data privacy and security controls tailored for public cloud environments.

Notion: Free ISO/IEC 27001:2022 Update Kit

Sep 5, 2023

The ISO/IEC 27001:2022 Update Kit in Notion includes changes to ISMS, 11 new controls in Annex A, mappings between 2013 and 2022, and a list of merged controls.

ISO 27017 - The Code of Practice for Cloud Security

Aug 31, 2023

ISO 27017 provides guidelines to implement cloud security controls. This guide explores ISO 27017 to help organisations apply it effectively.

C5: A Complete Guide to the Cloud Computing Compliance Criteria Catalogue

Aug 24, 2023

Learn everything you need to know about C5 cloud security attestation - from its purpose and origins to documentation, implementation steps and key takeaways.

Free Tool to Simplify Your ISO 27001:2022 Migration

Aug 18, 2023

Struggling to migrate to ISO 27001:2022? This free customisable Notion template simplifies the transition with step-by-step guidance and key info.

Crafting an Effective Statement of Applicability for ISO 27001 📜

Aug 17, 2023

Learn how to craft an effective ISO 27001 Statement of Applicability (SoA) that fully scopes your information security management system + template.

Demystifying the Context of the Organisation for ISO 27001 📝

Aug 10, 2023

Learn what the Context of the Organisation is in ISO 27001 and how to create one. This guide covers tips for documenting context to inform your ISMS.

The Cultural Revolution in Information Security: Startups, Meet ISO 27001 👋

Jul 19, 2023

Explore how startups can cultivate an infosec culture and bolster defences with ISO 27001, improving business efficiency and trust.

The Rise of AI in Information Security: A Game Changer for Startups and Remote Businesses 🚀

Jul 18, 2023

Explore how AI and ISO 27001 transform information security, bolster data privacy, and help detect cyberattacks for startups and remote businesses.

ISO 27001 for IoT Security: A Guide to Securing Your Connected World

Jul 5, 2023

Learn how ISO 27001 can help you secure your IoT devices and data in an increasingly connected world. This comprehensive guide covers the risks, controls, and benefits of ISO 27001 compliance for IoT deployments.

Document Your Way to ISO 27001:2022 Compliance

May 10, 2023

Key steps for documenting ISO 27001:2022. Learn about mandatory records, ISMS scope, risk management, and tips for effective documentation.

From Information Security to Data Privacy: The Next Level with ISO 27701 Integration

Mar 13, 2023

Learn how to enhance personally identifiable information (PII) protection by integrating ISO 27701 with ISO/IEC 27001 and ISO/IEC 27002.

Embracing Change: Navigating the Key Updates in ISO 27001:2022 for Enhanced Information Security Management

Mar 1, 2023

Discover key updates in ISO 27001:2022, transition roadmap, and how to enhance your organisation's information security management practices.

Boost Your Organisation's Information Security with ISO 27001

Feb 17, 2023

Learn how to implement ISO 27001 and enhance your organisation's information security with this comprehensive guide. Improve data protection, gain a competitive edge, and achieve certification.

Key Data Privacy Standards and Frameworks for Organisations

Jan 31, 2023

Protect your customers' data, safeguard your reputation, and avoid hefty fines by understanding key data privacy regulations, standards, and compliance best practices.

ISO 27001 and GDPR: Protecting Sensitive Information and Ensuring Privacy

Jan 30, 2023

Discover the power of ISO 27001 & GDPR compliance, boosting data protection, trust, business opportunities. Unlock the secrets of cybersecurity.

Master ISO 27001 & SOC 2: Boost Security and Defeat Cybercriminals!

Jan 27, 2023

Discover how to effectively harness ISO 27001 & SOC 2 compliance to enhance business security, protect sensitive data, and outwit cyber threats.

Fortify Your Business: Mastering Information Security with ISO 27001 and Cyber Essentials Certification

Jan 26, 2023

Discover the power of ISO 27001 and Cyber Essentials to safeguard your business against cyber threats and ensure robust information security.

Integrating ISO 27001 and ISO 22301: Aligning Information Security and Business Continuity Management

Jan 25, 2023

Integrating ISO 27001 and ISO 22301 can align information security and business continuity management to optimise resources and manage risks.

New EU Cybersecurity Measures Take Effect: NIS2 Directive and CER Directive Raise the Bar for Information Security Standards

Jan 24, 2023

The NIS2 Directive and CER Directive have entered into force, bringing new rules for cybersecurity for organisations operating within the EU.

Unlock the Benefits of ISO 27001 Certification for Your Small to Medium Business: A Short Summary

Jan 23, 2023

ISO 27001 certification helps SMBs establish robust security measures, gain credibility, manage risks, and comply with regulations.

Understanding the Differences between ISO 31700 and ISO 27701: A Guide to Implementing Comprehensive Privacy Management Systems

Jan 20, 2023

Learn about the key differences and benefits of implementing both standards for comprehensive data protection.

International Privacy Standard: ISO Adopts Privacy by Design as ISO 31700, Offers New Guidelines for Consumer Data Protection

Jan 19, 2023

ISO adopts Privacy by Design as ISO 31700, an international privacy standard, offering new guidelines for consumer data protection.

Why ISO 27001 Certification is a Must-Have for Businesses

Jan 18, 2023

ISO 27001 certification is essential for businesses handling sensitive information. It helps with regulations and builds trust with partners.

The Importance of Security Awareness in the Workplace

Jan 17, 2023

Reduce the risk of cyber attacks with a robust security awareness program. Learn how to build a culture of security and protect your business.

Don't Share Your Personal Information with the Grinch: A Guide to Staying Safe Online this Holiday Season

Nov 24, 2022

Don't share your personal information online! Stay safe online by being cautious of sites, securing your devices, and using VPNs on public Wi-Fi.

Foil the Grinch's Phishing Plans: A Guide to Protecting Yourself from Scams this Holiday Season

Dec 23, 2022

Foil the Grinch plans and protect your sensitive information from scams this holiday season! Learn how to spot and avoid phishing mails and links.

Lock Down Your Accounts with Two-Factor Authentication: A Grinch-Proof Guide for the Holidays

Dec 22, 2022

Lock down your accounts this holiday season with two-factor authentication! Learn how to enable 2FA and protect yourself from phishing attacks.

Don't Let the Grinch Steal Your Data​: Password Managers for a Secure Holiday Season

Dec 21, 2022

Stay jolly & protect your sensitive info with a password manager! Learn about popular options - LastPass, Dashlane, 1Password, Keeper & Bitwarden.

Don't Let the Grinch Steal Your Data​: Tips for a Holly Jolly and Secure Holiday Season

Dec 20, 2022

Keep your sensitive information safe this holiday season with these tips! Use strong passwords, enable 2fa, and avoid phishing.

Coming soon

Dec 6, 2022

Get the latest insights and knowledge on ISO 27001 with 27kay. Stay informed with in-depth articles, news analysis, and valuable resources.

Let's get to know each other.

Let's get to know each other.

Let's get to know each other.