The Essential Eight is a focused set of technical controls; ISO 27001 is a full certifiable security management system. Here’s how they differ and which your business needs.
Tag: #iso27001
ISO 27001 Controls Explained (Annex A, 2022)
ISO 27001:2022 Annex A lists 93 controls across four themes. Here’s what they are, whether you must implement all of them, and how the Statement of Applicability works.
ISO 27001 vs SOC 2: Which Does Your Australian Business Need?
ISO 27001 and SOC 2 both prove you manage information security, but they suit different markets. Here’s the difference, and how one system can support both.
ISO 27001 Requirements: A Practical Checklist
What does ISO 27001 actually require? The mandatory clauses 4-10, the documents you must have, and a practical checklist to get certification-ready.
Preparing for an ISO 27001 Audit (Stage 1 and Stage 2)
ISO 27001 certification is a two-stage audit, preceded by your own internal audit and followed by annual surveillance. Here’s what each stage involves and how to prepare.
ISO 27001 Risk Assessment and the Statement of Applicability: The Gap Auditors Find
The most common finding on an ISO 27001 audit is not a missing control. It is a Statement of Applicability that does not reconcile with the risk assessment. Controls sit there marked applicable while treating no identified risk, and identified risks sit there with a treatment option chosen and nothing in the SoA actually doing […]
AUSTRAC Tranche 2: You’re Now Holding Clients’ ID Documents. Where Are Your Controls?
From 29 July 2026, around 80,000 Australian firms must enrol with AUSTRAC and hold clients’ identity documents. An ISO auditor on the security exposure most of them will miss.
Your Cyber Insurer Is Asking the Same Questions an ISO 27001 Auditor Does
Cyber insurers now underwrite on the controls ISO 27001 contains, and APRA’s CPS 230 pushes the same demands down financial-services supply chains. How certification answers both.
One Breach, 21 GP Practices: The Multi-Site Security Scope Problem in Healthcare
A cyber attack on one head office exposed patient data from 21 GP practices at once. An ISO auditor on multi-site ISMS scope, health data under APP 11, and how a clinic network closes the gap.
The Quick Guide to Australian Cyber Security Policies
Many State governments have recently undergone a change in policies surrounding cybersecurity as a result of increasing cybercrimes. Published in January 2020, the Australian Government Information Security Manual outlines a risk-based framework that organisations can apply to protect their systems and information from cyber risks. Its principles have been grouped into four key activities: Govern: Identify and […]












