What is ISO 27001? Information Security Simply Explained | DICIS AG
Why does ISO 27001 exist?
Information security and data protection are among the most important topics for organizations that want and need to professionalize themselves in the context of digitalization and digital transformation. ISO 27001 is based on a simple philosophy: information security and data protection must not be left to chance. There must be clear rules for,
ISO 27001 follows the PDCA cycle logic familiar from quality management: Plan, Do, Check, Act. In German: Planen, Umsetzen, Messen und Verbessern (Plan, Implement, Measure, and Improve).
The PDCA cycle is also known from other management systems such as quality management. The structure of ISO 27001 is also similar to that of ISO 9001. Therefore, management systems from the areas of quality, environmental protection, or information security can be very well combined in the form of integrated management systems.
DICIS® AG offers a modern solution for ISO 27001 certification that significantly reduces the effort. With the help of an AI assistant, the entire documentation can be created within a few hours – instead of several weeks as before.
Companies can test the solution for 30 days free of charge and be guided step-by-step through the certification process.
Benefits of a Quality Management System
Why should companies implement a quality management system? The short answer is: because it makes them more professional. But what does more professional mean?
Companies that have obtained ISO 9001 certification are reliable and valued business partners. Accordingly, they can expand their market share and scale their services. This means nothing less than: the company is prepared for growth. Companies that have established a quality management system benefit from greater growth potential while simultaneously reducing costs.
How is ISO 27001 structured?
ISO 27001 follows the so-called High Level Structure and is similarly structured to ISO 9001 or ISO 14001. The actual requirements are in chapters 4 to 10. Additionally, there is an Annex with 93 controls that you must implement or justify to fully cover information security.
The standard is structured so that you can easily proceed step by step. You start by understanding your company, define rules, and ensure that work is done securely in everyday operations. Afterwards, you regularly check if everything is working and improve your system.
The following overview simply shows you what you specifically need to do in each chapter:
| Chapter | What you specifically need to do in this chapter |
|---|---|
| Chapter 4 – ContextConsider: | Which data is important? What can happen? Where do you apply your security system? |
| Chapter 5 – Leadership | Ensure that the topic is important and everyone knows: data must be protected. |
| Chapter 6 – PlanningConsider: | What can go wrong and how do we prevent it? |
| Chapter 7 – Support | Ensure that your employees know what to do and have the right resources. |
| Chapter 8 – Operation | Define how data is handled securely in daily operations. |
| Chapter 9 – Performance Evaluation | Regularly check: Is everything working or are there problems? |
| Chapter 10 – Improvement | If something is not working well, improve it step by step. |
| Annex A – Controls | Implement specific protective measures: rules, training, securing access, and protecting IT. |
DICIS® AG has developed an innovative and particularly simple path to ISO 27001 certification – especially for small businesses. Instead of complex projects and weeks of preparation, you use an AI-powered tool that guides you step-by-step through the implementation.
Through targeted questions, the system automatically identifies the relevant requirements and creates the necessary documentation in a short time. Certification then takes place efficiently via an online audit.
This makes ISO 27001 certification significantly easier and faster. You can start immediately and test the certification tool for 30 days free of charge now.
What do I need to implement in ISO 27001 Chapter 4.1 (Context of the Organization)?
In Chapter 4.1, ISO 27001 lays the foundation for an Information Security Management System to be implemented at all. Organizations create a list of relevant internal and external issues for this purpose.
ISO 27001 does not specify which internal and external issues you must monitor and analyze. Ultimately, it is a matter of relevance. At its core, however, it is quite simple. You need to clarify what potential threats exist, what regulations you must observe, and which areas of your organization are affected.
Which interested parties are relevant for ISO 27001?
When it comes to information security, different groups have different interests.
Countless other interested parties could be listed. ISO 27001 requires organizations to actively address these different interests and identify potential areas of tension that exist in information security management.
How do I define the scope (Chapter 4.3) of ISO 27001?
Contrary to a widespread assumption, ISO 27001 does not automatically have to be implemented for an entire organization. It is even conceivable that you implement ISO 27001 only for a few processes, for example, for all processes and activities related to the use of a CRM system (Customer Relationship Management system). Therefore, it is necessary to clearly define the scope of ISO 27001.
What do I need to do in Chapter 4.4 (The Information Security Management System)?
This chapter is the concretization of 4.3. Which processes and procedures does your ISMS cover? Create a list of all relevant processes and procedures for your ISMS. There are classic standard procedures that affect practically every organization: for example,
Here, ISO 27001 requires clear processes and procedures. With Innolytics AG’s digital Information Security Management System, you can meet these requirements quickly and easily.
What does ISO 27001 require of leadership?
(Chapter 5.1)
Leaders play a special role within organizations. They are responsible for considering information security in all areas of daily work. They are the ones who define information security objectives, develop measures to implement them, and support employees in acquiring the necessary competencies. Chapter 5.1 explicitly lists the requirements for leaders in organizations.
What roles and responsibilities (Chapter 5.2) exist in ISO 27001?
ISO 27001, like all management systems, requires that there are fixed responsibilities and accountabilities for specific tasks. How these are structured in detail is not explicitly prescribed in the standard. However, it is important that roles and responsibilities are specifically named. It is therefore not enough to merely generally indicate that, for example, a certain department should think about information security. In an Information Security Management System (ISMS), specific individuals or functions are named.
What competencies do employees need regarding information security?
(Chapter 7.3)
Organizations must ensure that the responsible persons have the necessary know-how to fulfill their tasks. At its core, this is a very logical requirement. What good is it if organizations set information security goals, develop measures, and appoint responsible persons, but then no one has the necessary expertise to carry this out?
What does information security assessment mean?
(Chapter 8.2: Risk analysis and assessment)
ISO 27001 requires companies to regularly review their own IT infrastructure (which includes not only internal networks and devices connected to the internet, but also employees’ smartphones and even home workplaces in home offices). Everything can become an entry point for cybercriminals and thus represents a security risk.
ISO 27001 requires companies to regularly review their own IT infrastructure (this includes not only internal networks and internet-connected devices, but also employees’ smartphones and even home workstations). Everything can become a gateway for cybercriminals and thus represents a security risk.
ISO 27001 does not prescribe a specific form of risk analysis. However, there are security criteria listed in the standard. In addition, there are standards such as the BSI Standard that are compatible with ISO 27001.
What information security audits does ISO 27001 require (Chapter 9.2)?
ISO 27001 does not specify the form in which these audits must be carried out. For this, there is the specialist standard ISO 19011 (Auditing management systems), which sets out certain criteria. The most important are the professional competence of internal auditors and independence. Requirements that should really go without saying: What good is a glossed-over audit that fails to uncover security risks—for example, for internal political reasons—if it means vulnerabilities for potential attacks on information security remain?
How do I improve information security? (ISO 27001 Chapter 10.1)
ISO 27001 – like all certifiable standards in the ISO family – is based on the philosophy of “learning from mistakes.” Chapter 10.1 therefore establishes a binding approach to identified weaknesses and security flaws. They are intended to improve the overall system.
This list is not exhaustive. In practice, it is supplemented by security criteria. However, it provides a good overview of how the management system is structured and what requirements are placed on companies seeking ISO 27001 certification.




