What is ISO/IEC 27001?

unlock question

Information security and data privacy are becoming increasingly important for businesses of all sizes, and across all sectors. The rapid increase in cyber-related incidents in South Africa, particularly affecting smaller, more vulnerable organisations requires urgent attention. The purpose of information security is to protect information assets from unauthorised access, maintain accurate and complete records, and […]

Should you DIY your ISMS implementation?

diy your isms

Having made the decision to implement an information security management system (ISMS), your first big decision is on whether you should do it yourself or work with external specialist consultants. Key Takeaways It is possible to do this alone, but don’t underestimate the effort required to do so. There are a lot of resources available […]

ISO 27001 and the PDCA cycle

implementation

When it comes to improving your business’s information security, ISO/IEC 27001 is one of the most recognised standards in the world. But for many small or medium-sized organisations, the idea of implementing it can feel overwhelming. Where do you even start? That’s where the PDCA cycle comes in. Key Takeaways PDCA stands for Plan-Do-Check-Act, and […]

Should you use specialised GRC software?

GRC software

So, you’ve decided to implement an Information Security Management System (ISMS)? Great move! It’s a proactive way to protect your business, earn customer trust, and maybe even land those bigger contracts that ask for ISO/IEC 27001 certification. You’ve come to a fork in the road, deciding how you will actually manage your ISMS? Should you […]