AceQu

ISO 27001 certification process steps from risk assessment to certification audit.

What Is ISO 27001? A Complete Guide to Information Security

A tender comes in from a bank or an international client, and buried in the requirements is a line asking for proof of ISO 27001 certification. Nobody on the team quite knows what that means, only that its absence might cost the contract. That scenario plays out more often than most businesses admit, and it's usually the first time anyone actually looks up what ISO 27001 requires.

ISO 27001 is the international standard for information security management, and it's become less of a nice-to-have and more of a baseline expectation for organisations handling sensitive data, whether that's customer records, financial information, or intellectual property. Here's what it actually covers, what certification involves, and why it's become particularly relevant for organisations in Kenya.

What ISO 27001 Actually Is

ISO 27001 sets out the requirements for an Information Security Management System, usually shortened to ISMS. It isn't a piece of software or a single security tool — it's a structured, documented approach to identifying information security risks and putting controls in place to manage them.

The standard is built around three core principles, often referred to as the CIA triad: confidentiality (only authorised people can access information), integrity (information stays accurate and isn't tampered with), and availability (information and systems are accessible when needed). An ISMS built to ISO 27001 exists to protect all three, consistently, not just after an incident forces the issue.

What Getting Certified Actually Involves

Certification isn't a one-off audit. It starts with a risk assessment — identifying what information assets exist, what could go wrong, and how severe the impact would be. From there, an organisation selects and implements controls from the standard's reference set (covering areas like access control, supplier relationships, and incident response), documents how those controls work in practice, and demonstrates through an external audit that the system is genuinely operating, not just written down on paper.

Once certified, annual surveillance audits keep the certification current, which is part of why ISO 27001 is treated as an ongoing commitment rather than a one-time badge.

ISO 27001 vs Other ISO Standards

Organisations already familiar with ISO 9001 or ISO 22301 sometimes assume ISO 27001 overlaps entirely with what they already have. It shares the same high-level management system structure, but the focus is different.

StandardWhat It's Actually AboutTypical Trigger
ISO 27001Information security management \u2014 protecting data and systemsClient or tender requirement; handling sensitive data; a security incident
ISO 9001Quality management \u2014 consistently meeting customer requirementsTender requirement; scaling past informal processes
ISO 22301Business continuity \u2014 staying operational through disruptionRegulatory pressure; reliance on uptime-critical systems

Because all three standards share the same underlying management system structure, organisations that already hold one tend to find the next one faster to implement, since documentation practices and internal audit routines carry over.

what ISO 27001 covers versus common misconceptions about the standard.

Why This Matters for Kenyan and East African Organisations

Information security certification has moved beyond a small circle of multinational tech firms. Co-operative Bank of Kenya became the first bank in East Africa to achieve ISO 27001 certification, and has since transitioned to the updated 2022 version of the standard. The Communications Authority of Kenya has also achieved ISO/IEC 27001 certification through the Kenya Bureau of Standards (KEBS), covering its headquarters and regional offices as part of its national cybersecurity mandate.

What both examples point to is the same underlying shift: regulators, banks, and large clients increasingly expect proof of a managed security framework, not just a verbal assurance that data is "taken seriously." For a business bidding on contracts with banks, government bodies, or international partners, that expectation is becoming difficult to work around.

If you're weighing up ISO consultant vs certification body options for an ISO 27001 project, the same considerations that apply to other ISO standards apply here — the right consultant helps you get certified without unnecessary rework, while the certification body issues the actual accredited certificate.

team reviewing an ISO 27001 information security policy document.

Getting Started

Most organisations approaching ISO 27001 for the first time benefit from understanding the general certification process before diving into the specifics of information security controls. Our guide to ISO certification audit stages covers what the two-stage audit actually looks like, and documents required for ISO certification gives a practical checklist of what to prepare in advance, both of which apply to an ISO 27001 project as much as any other standard.

Need to demonstrate information security to a client, regulator, or tender board?

AceQu works with organisations across Kenya and East Africa on ISO 27001 implementation, from initial risk assessment through to certification and ongoing surveillance support.

Talk to the AceQu team about ISO 27001 →

Frequently Asked Questions

What does ISO 27001 actually cover?

ISO 27001 sets out requirements for an Information Security Management System (ISMS) \u2014 the policies, risk assessments, and controls an organisation puts in place to protect the confidentiality, integrity, and availability of its information, whether that's customer data, financial records, or internal documents.

Is ISO 27001 only for IT and tech companies?

No. While technology companies pursue it often, ISO 27001 applies to any organisation that handles sensitive information, including banks, law firms, healthcare providers, and government bodies. Several Kenyan organisations outside the tech sector, including banks and law firms, have already achieved certification.

How is ISO 27001 different from ISO 9001?

ISO 9001 covers quality management \u2014 consistently meeting customer requirements. ISO 27001 covers information security specifically \u2014 protecting data and systems from unauthorised access, loss, or damage. An organisation can hold either standard independently or both together.

How long does ISO 27001 certification take?

Timelines vary by organisation size and existing documentation, but most projects run 3 to 6 months from gap analysis through to the certification audit. Organisations with an existing management system in place, such as ISO 9001, often move faster.

Who certifies ISO 27001 in Kenya?

Certification is issued by accredited certification bodies, which in Kenya includes bodies working with or recognised by the Kenya Bureau of Standards (KEBS), as well as international certification bodies operating locally.

For the standard's own description of ISO/IEC 27001, iso.org's page on ISO/IEC 27001 is the primary source behind the requirements referenced above.

Add Comment