Standards › ISO 27001

Certifiable standard

ISO 27001 — Information Security

The international standard for information security management systems: protecting the confidentiality, integrity and availability of the information you hold.

What it covers

Risk-based selection and operation of security controls across people, processes and technology, with leadership commitment, defined scope, and a cycle of audit and improvement.

Who it is for

Construction businesses handling BIM models and CDE contents, client-confidential designs, personal data, or bidding for public-sector and infrastructure work where security questionnaires now sit alongside safety ones.

Key requirement themes

  • Defined scope and information security risk assessment
  • A Statement of Applicability recording which controls apply and why
  • Access control, supplier security, incident management, continuity of security
  • Awareness and competence for the people handling information
  • Measurement, internal audit, management review, corrective action

Theme-level description in our own words — the standard itself defines the requirements, and no standard text is reproduced here.

Construction-sector relevance

Drawings, models, programmes and commercial records now move through common data environments and email daily. ISO 27001 gives a structure for who can access what, how project information is classified and shared with the supply chain, and what happens when a laptop or account is compromised.

Benefits

  • Answers security PQQ sections credibly
  • Reduces the chance and cost of data incidents
  • Client confidence for sensitive projects
  • Supports UK GDPR accountability

Common gaps we find

  • No asset or information inventory
  • Access never revoked when people leave
  • Supplier security unmanaged
  • No tested incident response
  • Risk assessment done once and shelved

Implementation process

  1. Gap analysis of current arrangements against the standard
  2. Prioritised closure plan with owners and dates
  3. Documents and registers built or adapted with the people who use them
  4. System operated: records, audits, review — evidence accumulating
  5. Readiness review and mock assessment
  6. Independent certification-body assessment (their decision, not ours)

Typical documents

  • Scope and security policy
  • Risk assessment and treatment plan
  • Statement of Applicability
  • Access control and supplier security procedures
  • Incident log and response plan
  • Audit and review records

Typical evidence

  • Access reviews
  • Incident records with lessons applied
  • Supplier assessments
  • Awareness training records

Certification-readiness route

We take organisations to the point where an accredited certification body can assess them with confidence: gap analysis → implementation → operating evidence → internal audit and management review → readiness review. The assessment and the certificate belong to the certification body; our role ends at prepared-and-ready, and continues afterwards only as support.

Related standards

Certifiable standard

ISO 9001 — Quality Management

The international standard for quality management systems: consistent processes, controlled documents, measured performance and evidenced improvement.

Certifiable standard

ISO 22301 — Business Continuity

The international standard for business continuity management systems: keep priority activities running through disruption, and recover in a planned way.

Implementation approach

IMS — Integrated Management Systems

One management system meeting several standards at once — commonly ISO 9001 + 14001 + 45001 — with one document set, one audit programme and one review, instead of parallel systems.

Questions we are actually asked

Is ISO 27001 overkill for a contractor?

Not if you exchange models, designs or personal data with clients — infrastructure and public-sector frameworks increasingly ask about it. Scope can be defined around the parts of the business that handle sensitive information.

Does ISO 27001 make us UK GDPR compliant?

No. It supports data-protection accountability but does not certify legal compliance; UK GDPR obligations apply independently.

What is a Statement of Applicability?

A record of which of the standard’s reference controls you apply, and why the others do not apply. Auditors treat it as the map of your system.

Professional disclaimer: this page is orientation, not advice on your specific circumstances, and not a reproduction of any standard. Implementation support, templates and platform tools do not confer certification or legal compliance; certification decisions rest solely with independent certification bodies, and legal duties apply regardless of certification.