ISO 27001:2022 Annex A lists 93 controls across four themes. Here’s what they are, whether you must implement all of them, and how the Statement of Applicability works.
Tag: #informationsecurity
What is SOC 2? A Plain-English Guide for Australian Businesses
SOC 2 is a US attestation report on your security controls, increasingly asked for by US customers. Here’s what it is, Type I vs Type II, and how to get it from Australia.
ISO 27001 vs SOC 2: Which Does Your Australian Business Need?
ISO 27001 and SOC 2 both prove you manage information security, but they suit different markets. Here’s the difference, and how one system can support both.
ISO 27001 Requirements: A Practical Checklist
What does ISO 27001 actually require? The mandatory clauses 4-10, the documents you must have, and a practical checklist to get certification-ready.
What is TISAX? The Security Standard for Automotive Suppliers
TISAX is the automotive industry’s information security assessment, based on the VDA ISA and aligned to ISO 27001. Here’s what it is, the assessment levels, and how to prepare.
Preparing for an ISO 27001 Audit (Stage 1 and Stage 2)
ISO 27001 certification is a two-stage audit, preceded by your own internal audit and followed by annual surveillance. Here’s what each stage involves and how to prepare.
Staying Informed: The Alerts and Groups Worth Following
Threats, standards and laws change constantly. Here are the free alerts and special-interest groups worth subscribing to, led by cyber.gov.au, and why staying informed is a control in your management system.
ISO 27001 Risk Assessment and the Statement of Applicability: The Gap Auditors Find
The most common finding on an ISO 27001 audit is not a missing control. It is a Statement of Applicability that does not reconcile with the risk assessment. Controls sit there marked applicable while treating no identified risk, and identified risks sit there with a treatment option chosen and nothing in the SoA actually doing […]
AUSTRAC Tranche 2: You’re Now Holding Clients’ ID Documents. Where Are Your Controls?
From 29 July 2026, around 80,000 Australian firms must enrol with AUSTRAC and hold clients’ identity documents. An ISO auditor on the security exposure most of them will miss.
Your Cyber Insurer Is Asking the Same Questions an ISO 27001 Auditor Does
Cyber insurers now underwrite on the controls ISO 27001 contains, and APRA’s CPS 230 pushes the same demands down financial-services supply chains. How certification answers both.












