RPG Excellence
Sign inBook
NEW STANDARDISO 9001:2026 is now publishedSee what changed and prepare your quality management system.
Read full update
ISO/IEC 27001 GUIDE

ISO/IEC 27001 — Information Security

Manage information-security risk through proportionate controls, accountable governance and continual evaluation of the ISMS.

Overview

What this management system is designed to achieve

A risk-based framework for protecting the confidentiality, integrity and availability of information.

The value comes from integrating requirements into normal governance and operations—not producing documents solely for an audit.

StructureClauses 4–10
ApproachRisk based
UseSingle or integrated
AssuranceEvidence led
Clause navigator

Key clauses explained

Open any clause to see practical application, possible evidence, common weaknesses and relevant RPG Excellence support.

Clause 4
Context of the organisation

Information-security context, interested parties, regulatory and contractual needs, ISMS scope, interfaces and dependencies.

Explain this clause

Practical application

Map internal and external issues, interested parties and the boundaries of the management system. Connect this analysis to decisions rather than keeping it as a static document.

For ISO/IEC 27001: Information-security context, interested parties, regulatory and contractual needs, ISMS scope, interfaces and dependencies.

Objective evidence to consider

Context review, interested-party register, scope statement, process map and records showing that changes were considered.

Common weakness

Generic SWOT lists that are not connected to risks, objectives, controls or the defined scope.

How RPG Excellence supports you

RPG Excellence supports facilitated context reviews, scope definition, integrated process mapping and evidence-based gap assessment.

Discuss Clause 4 support →
Clause 5
Leadership

Information-security policy, leadership accountability and clear roles for risk ownership and security governance.

Explain this clause

Practical application

Make accountability visible through objectives, resources, decisions and routine leadership oversight. Assign responsibilities without transferring top-management accountability.

For ISO/IEC 27001: Information-security policy, leadership accountability and clear roles for risk ownership and security governance.

Objective evidence to consider

Policy approval, leadership decisions, assigned responsibilities, resource approvals, communications and management-review actions.

Common weakness

Treating the system as the responsibility of one coordinator while operational leaders remain detached.

How RPG Excellence supports you

RPG Excellence supports leadership workshops, governance design, policy alignment and management-review preparation.

Discuss Clause 5 support →
Clause 6
Planning

Information-security risk assessment and treatment, objectives, planned changes and maintenance of the Statement of Applicability.

Explain this clause

Practical application

Use evidence to identify risks and opportunities, determine obligations, set measurable objectives and plan controlled action with owners, dates and evaluation methods.

For ISO/IEC 27001: Information-security risk assessment and treatment, objectives, planned changes and maintenance of the Statement of Applicability.

Objective evidence to consider

Risk registers, obligations, objectives, action plans, change assessments and records explaining prioritisation.

Common weakness

Scoring risks without defining actions, accountable owners, timescales or how effectiveness will be evaluated.

How RPG Excellence supports you

RPG Excellence provides risk-based planning, FMEA support, objective setting and three-year assurance programme design.

Discuss Clause 6 support →
Clause 7
Support

Security resources, competence, awareness, communication and controlled documented information.

Explain this clause

Practical application

Determine the people, competence, awareness, communication, infrastructure and documented information needed for reliable operation.

For ISO/IEC 27001: Security resources, competence, awareness, communication and controlled documented information.

Objective evidence to consider

Competence criteria, training and verification records, communication plans, document controls, resource reviews and retained knowledge.

Common weakness

Using attendance as proof of competence or allowing uncontrolled documents to become the real operating method.

How RPG Excellence supports you

RPG Excellence supports competence frameworks, auditor verification, document architecture and controlled evidence systems.

Discuss Clause 7 support →
Clause 8
Operation

Repeatable risk assessment and treatment processes, implementation of selected controls and retained evidence of operation.

Explain this clause

Practical application

Translate planned controls into repeatable operational practice, including outsourced activities, procurement, change and abnormal or emergency conditions.

For ISO/IEC 27001: Repeatable risk assessment and treatment processes, implementation of selected controls and retained evidence of operation.

Objective evidence to consider

Operational criteria, work controls, supplier controls, change records, inspection results, exercise records and retained operational evidence.

Common weakness

Procedures that describe an ideal process but do not match actual work, interfaces or outsourced activities.

How RPG Excellence supports you

RPG Excellence supports process control reviews, multisite audits, supplier assurance and practical operational-control design.

Discuss Clause 8 support →
Clause 9
Performance evaluation

Security monitoring, measurement, internal audit, management review and evaluation of whether controls and the ISMS are effective.

Explain this clause

Practical application

Define what must be monitored, analysed, audited and reviewed so leaders can determine whether the system is suitable, effective and delivering intended outcomes.

For ISO/IEC 27001: Security monitoring, measurement, internal audit, management review and evaluation of whether controls and the ISMS are effective.

Objective evidence to consider

Meaningful KPIs, evaluation results, internal-audit records, compliance reviews, trend analysis and management-review outputs.

Common weakness

Reporting activity counts without evaluating performance, trends, control effectiveness or the causes of weak results.

How RPG Excellence supports you

RPG Excellence provides clause-based assessments, integrated internal audits, dashboards and management-ready assurance reporting.

Discuss Clause 9 support →
Clause 10
Improvement

Security nonconformities, corrective action, lessons from events and continual improvement of the ISMS.

Explain this clause

Practical application

Control incidents and nonconformities, investigate proportionately, correct causes and verify that improvements are effective and sustained.

For ISO/IEC 27001: Security nonconformities, corrective action, lessons from events and continual improvement of the ISMS.

Objective evidence to consider

Corrections, cause analysis, CAPA-8D records, effectiveness checks, lessons learned and updated risks or controls.

Common weakness

Closing actions when tasks are completed rather than when objective evidence demonstrates sustained effectiveness.

How RPG Excellence supports you

RPG Excellence connects findings to CAPA-8D, accountable actions and independent effectiveness verification.

Discuss Clause 10 support →
RPG EXCELLENCE SUPPORT

Move from understanding to controlled implementation.

Use RPG Excellence for gap analysis, implementation support, internal auditing, evidence control, findings, CAPA-8D and management reporting across a single or integrated system.

Discuss ISO/IEC 27001 support →
ISO/IEC 27001 Practical Guide | RPG Excellence | RPG Excellence