Information security isn’t just an IT problem anymore. Ransomware attacks, data breaches, and supply chain compromises hit companies of every size, and the average cost per incident keeps climbing year after year. The regulatory bar has gotten higher too. Between the Office of the Data Protection Commissioner’s growing enforcement under the Data Protection Act, fines running up to 3 percent of annual turnover or KES 5 million, sector-specific overlays from the CBK, IRA, and other regulators, and enterprise buyers asking harder security questions in every RFP, more and more Kenyan companies are pursuing ISO 27001 certification through KEBS, often alongside the same data protection compliance work.
In this article, we’ll break down what ISO 27001 actually is, why it matters, how it’s structured, and why it’s become the global benchmark for managing information security—no matter your size or industry.
What is ISO 27001?
ISO 27001 (officially, ISO/IEC 27001) is the international standard that lays out the requirements for setting up, running, and improving an Information Security Management System (ISMS) inside a company. In plain English: it defines how to organise everything your company does to protect its information—from who can access which documents, to how passwords are managed, to what happens when an employee loses a company laptop. The dual name comes from the fact that the standard is jointly developed by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC).
In practice, the goal is to protect the three pillars of information against internal and external threats:
- Confidentiality: only authorised people access each piece of data.
- Integrity: information isn’t altered or deleted without permission.
- Availability: data is accessible when it’s needed.
To pull this off, ISO 27001 doesn’t just recommend technical fixes like antivirus or backups. It lays out a complete management framework covering policies, processes, people, and technology—so security stops depending on one person’s heroics and gets baked into how the company operates day to day.
Although it’s voluntary, in industries like tech, financial services, and healthcare—and especially when selling to government agencies or large enterprise customers—certification has become a de facto requirement.
Where ISO 27001 came from
ISO 27001 didn’t appear out of thin air. Its roots go back to BS 7799, a British standard published by BSI in 1995 that compiled information security best practices. In 2005, ISO adopted that foundation and published the first official version of the standard. Since then, it’s been through two major updates:
- ISO 27001:2005: the first international version.
- ISO 27001:2013: a full overhaul of the structure and controls.
- ISO 27001:2022: the current version, updated for modern digital risks like cloud, remote work, supply chain attacks, and AI.
Each revision reflects how the cybersecurity landscape has evolved. The 2022 version introduces specific controls for cloud environments, continuous monitoring, and supply chain threat management—scenarios that were just emerging in 2013.
Key differences between ISO 27001:2013 and ISO 27001:2022
The 2022 version keeps the overall structure of the standard but completely reworks Annex A, the official list of concrete security measures the standard proposes to protect information. Each of these measures is called a “control” (for example, requiring strong passwords or encrypting laptop hard drives). Here are the biggest changes:
- The total number of controls drops: from 114 down to 93, though the bar hasn’t been lowered. Many controls were merged or rewritten, and 11 new ones were added to cover threats that didn’t exist before.
- The grouping changes: the previous 14 thematic groups (called “domains”) were reorganised into 4 clearer categories: organisational controls (policies, procedures, roles), people controls (training, responsibilities, employee management), physical controls (office access, equipment protection), and technological controls (encryption, backups, access management).
- Modern controls show up: threat intelligence (collecting and analysing information about ongoing attacks), cloud security, data leak prevention, and secure software development are among the most notable additions.
- Each control gets attribute tags: a new system that lets you filter controls by type (preventive, detective, or corrective), area of application, or the property they protect (confidentiality, integrity, or availability). In practice, this makes it easier to figure out which controls apply in each situation.
The transition period from the 2013 version ended on October 31, 2025. Since that date, certificates issued under the previous version are no longer valid, and all certified companies must be aligned with the 2022 version.
Why companies pursue ISO 27001
Companies that get certified usually do it for a mix of external pressure and internal opportunity. Here are the most common reasons:
- Access to enterprise deals and RFPs: more and more large companies—especially in financial services, healthcare, and tech—now require ISO 27001 as a prerequisite to even start a vendor evaluation. Without it, your sales reps are out of the deal before the first call.
- Differentiation from competitors: in categories where every vendor claims to “take security seriously,” certification turns a marketing promise into something a third party has actually verified.
- Faster compliance with related frameworks: SOC 2, HIPAA, PCI DSS, and most state privacy laws share a substantial portion of their controls with ISO 27001. Having the standard in place gives you a head start on the rest, instead of duplicating work.
- International expansion: if you’re selling to customers outside Kenya, in the UK, Germany, the Netherlands, or anywhere in the EU, ISO 27001 is often taken for granted in vendor evaluations. Not having it closes doors that never even come up in conversation.
- A real risk assessment: the process forces you to inventory assets, evaluate threats, and prioritise controls. A lot of companies find serious vulnerabilities they’d never quantified, simply because no one had been formally responsible for looking.
- Documented incident response: when something goes wrong, the procedures are written down, the owners are assigned, and the response times are defined. That cuts the financial and operational impact of every incident—and it also strengthens your hand when negotiating with cyber insurance carriers, who often reward certified companies with better premiums and broader coverage.
Which companies should consider ISO 27001?
ISO 27001 is a voluntary standard built to be universal. It applies to any company that handles sensitive information, regardless of size or industry. No law requires certification, but in plenty of contexts it’s gone from “nice to have” to “table stakes.”
Any size, any industry
The standard doesn’t set a minimum company size or exclude any industry. A 5-person startup and a Fortune 500 company can both get certified, because each organisation defines the scope of its ISMS based on its size, risks, and resources. An SMB won’t implement the same controls at the same level of detail as an enterprise with thousands of employees, but both can be fully compliant.
That’s why certification has spread across very different industries. Any company that depends on its information—customer data, intellectual property, source code, contracts, patient records—has a reason to put it in place. And since pretty much every company today runs on digital information, the addressable audience is huge.
Industries where it’s basically required
In some industries, operating without ISO 27001 keeps getting harder:
- Technology: SaaS, hosting, cybersecurity, MSPs, and software companies regularly face enterprise prospects who won’t sign without it. Certification runs through KEBS, and many Kenyan tech firms pair ISO 27001 with SOC 2 when courting international clients.
- Financial services and insurance: banks, fintechs, saccos, and insurers handle high-stakes data and operate under the supervision of bodies like the Central Bank of Kenya (CBK), the Capital Markets Authority (CMA), the Insurance Regulatory Authority (IRA), and the Sacco Societies Regulatory Authority (SASRA). CBK’s ICT Risk Management and cybersecurity guidelines already lean on ISO 27001-aligned controls, and the sector now reports incidents through the Banking Sector Cybersecurity Operations Centre (BS-SOC) under CBK’s Cyber Fusion Unit.
- Healthcare: hospitals, clinics, labs, and digital health platforms handle patient data subject to the Data Protection Act, 2019, the Digital Health Act, 2023, and oversight from both the Office of the Data Protection Commissioner and the Digital Health Agency. Insurers and providers are increasingly expected to show documented governance and board-level accountability for health data specifically.
- Government contractors: agencies and county governments increasingly require ICT Authority standards compliance and Data Protection Act alignment as a condition of tender. ISO 27001 doesn’t replace these requirements, but it accelerates due diligence and signals maturity in the bid.
- Critical infrastructure: energy, water, transport, and telecom operators fall under Communications Authority oversight and the Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cybersecurity) Regulations, 2024, with incident reporting routed through KE-CIRT/CC. Kenya’s 2026 National Cybersecurity Agency Order is now consolidating oversight of exactly this category, and these operators need to demonstrate a high level of security maturity.
Beyond these sectors, it’s also common for Kenyan companies selling into international enterprise accounts to pursue certification as a commercial requirement. Any business with customers in Europe, the UK, or the US eventually hears the question: “Are you ISO 27001 certified?”
The benefits of implementing ISO 27001
Getting ISO 27001 in place delivers benefits that go well beyond hanging a certificate on the wall. Some are immediate—like clearing a vendor risk assessment that was blocking a deal. Others show up over the medium term: fewer incidents, fewer parallel audits, and a more mature security organisation.
- Builds trust with customers, partners, and employees: the certificate serves as third-party validation of how your company handles sensitive information, so you don’t have to walk every prospect through every control.
- Opens doors to government contracts, enterprise deals, and international markets: more and more companies and agencies require ISO 27001 as a baseline, especially in regulated industries and when selling into Europe or Asia-Pacific.
- Reduces the likelihood and impact of security incidents: preventive controls stop attacks that would otherwise land, and response and continuity plans cut recovery time when something does break through.
- Accelerates compliance: ISO 27001 covers a substantial portion of these frameworks, so your legal and security teams reuse policies, evidence, and controls instead of duplicating them.
- Builds a security culture across the company: mandatory employee training and clear ownership of security responsibilities mean security stops being “the IT team’s problem” and becomes part of how every department works.
- Integrates cleanly with other management systems: ISO 27001 shares the same structural backbone as ISO 9001 (quality) and ISO 22301 (business continuity), so if you already have other certifications, you can unify policies, audits, and documentation.
- Can lower your cyber insurance premiums: more carriers factor certification into their underwriting, because it signals a high level of risk management maturity—and that often translates into better premiums or broader coverage.
How ISO 27001 is structured
ISO 27001 is organised around a main body of 11 clauses (numbered 0 through 10) and an Annex A with 93 concrete security controls a company can apply. The first four clauses are introductory; the audit focuses on the next seven (4 through 10), which contain the mandatory ISMS requirements:
- 0: Introduction. Lays out the goal of the standard, its risk-based approach, and how it lines up with other management systems.
- 1: Scope. Explains what the standard is for and what kinds of organisations it applies to.
- 2: Normative references. Lists documents to consult alongside ISO 27001, primarily ISO/IEC 27000.
- 3: Terms and definitions. The official glossary of concepts used in the standard.
- 4: Context of the organisation. Requires understanding what the company does, who its interested parties are (customers, employees, vendors, regulators), and what information it protects. This is where the ISMS scope is defined.
- 5: Leadership. Top management has to commit to security, assign roles, and approve the security policy. Without that commitment, ISO 27001 doesn’t work.
- 6: Planning. Where the risk assessment happens, security objectives are set, and changes are planned.
- 7: Support. Covers resources (people, budget, infrastructure), training, communication, and ISMS documentation.
- 8: Operation. The day-to-day. Apply the defined controls, manage identified risks, and handle incidents as they come up.
- 9: Performance evaluation. Internal audits, metrics, and management review. The check that the ISMS is actually working as designed.
- 10: Improvement. Address nonconformities, apply corrective actions, and roll out continuous improvements.
The seven mandatory clauses follow the PDCA cycle (Plan, Do, Check, Act)—the backbone of every modern management standard and what lets the ISMS evolve alongside the company. The 93 Annex A controls, which we’ll break down next, are the ones the company chooses to apply based on the risks identified in Clause 6.
➡️Explore the ISO 27001 framework in more detail in our dedicated article.
Annex A of ISO 27001
Annex A is the section of the standard that lists the official security controls a company can apply to protect its information. In the 2022 version, there are 93 controls, grouped into four broad categories by the type of measure they cover. You don’t have to implement all of them—each company picks the controls that match the risks identified during ISMS planning and documents the exclusions in a document called the Statement of Applicability (SoA).
- Organisational controls (37 controls): the largest group. Covers everything related to policies, processes, roles, and third-party relationships. Includes the overall security policy, information classification, vendor management, incident response, threat intelligence, and business continuity.
- People controls (8 controls): focused on the human factor—how you screen, train, and manage people with access to sensitive information. Includes background checks before hiring, confidentiality agreements, security training, post-employment responsibilities, and disciplinary action for violations.
- Physical controls (14 controls): protect tangible assets and the environment where information is processed. Cover access control to offices and data centers, measures against theft or natural disasters, cabling security, equipment maintenance, and removable media management.
- Technological controls (34 controls): the technical controls applied to systems, networks, and devices. Includes access management, encryption, authentication, backups, data loss prevention (DLP), web filtering, activity monitoring, and secure software development.
How to implement ISO 27001 step by step
Standing up an ISMS that meets ISO 27001 typically takes six months to two years, depending on company size, the scope you define, and your existing security maturity. The full process breaks down into six steps.
1. Get executive buy-in and define your scope
Without explicit leadership backing, no ISMS holds up over time. Top management has to approve the project, allocate budget, and assign an internal owner (usually a CISO, security lead, or ISMS coordinator).
At the same time, you need to define the scope—which parts of the company the standard will apply to. Common options:
- The entire organisation.
- A specific business unit.
- A specific product or service (for example, just your SaaS platform).
- A specific office or subsidiary.
The broader the scope, the heavier the implementation lift and the higher the audit cost.
2. Inventory and classify your information assets
Before you can protect something, you need to know what you’re protecting. In this phase, you build a detailed inventory of all the company’s information assets and assign each a criticality level. Assets can include:
- Data: customer databases, intellectual property, contracts, source code.
- Software: applications, operating systems, SaaS tools.
- Hardware: servers, laptops, mobile devices, networking equipment.
- Services: cloud, hosting, connectivity.
- People: employees with privileged access, system administrators.
Each asset is typically classified into three or four tiers (public, internal, confidential, restricted) based on the impact a loss or leak would have.
3. Analyse and assess your risks
This is probably the most technical step. For each asset you’ve identified, you need to figure out which threats it faces (an attack, human error, hardware failure), which vulnerabilities could be exploited, and what the impact of an incident would be. The combination of likelihood and impact gives you the risk level.
Based on that, the company decides how to treat each risk. There are four options: mitigate it by applying controls, transfer it (for example, by buying cyber insurance), accept it if it falls within your risk tolerance, or avoid it by stopping the activity that creates it. The decision gets documented in the risk treatment plan.
4. Select and implement controls
With the risk treatment plan in hand, it’s time to pick the Annex A controls you’ll apply. Every selected control needs to be justified and tied to one or more of the risks identified in the previous step. Same goes for exclusions.
The result is captured in the Statement of Applicability (SoA), a document that, for each of the 93 controls, indicates whether it applies, how it’s been implemented, and—if excluded—why. It’s one of the documents auditors scrutinise most closely during the external audit.
Once the SoA is approved, theory becomes practice. You write the security policies, configure the technical controls (disk encryption, MFA, access management, monitoring), sign confidentiality agreements with employees and vendors, and kick off the ISMS operational processes.
5. Train and educate your team
Most security breaches start with a click—so training isn’t optional, it’s a mandatory piece of the ISMS. Every employee needs to understand what information they handle, how to protect it, and who to alert if they spot something off. Sessions typically cover password best practices, phishing recognition, responsible use of company devices, and the incident response process.
6. Run an internal audit and pursue certification
Before going for certification, the company has to audit itself. The internal audit is run by qualified personnel (internal or external, but independent of the ISMS) and confirms that:
- Documentation is complete and up to date.
- Controls work the way they’re described.
- Evidence is traceable and verifiable.
- Any nonconformities found have been addressed.
Then top management reviews the overall state of the ISMS, looks at the metrics, and approves the improvement actions.
Next comes the external audit, performed by an independent accredited certification body (in Kenya, this is typically KEBS through its Certification Body, KEBSCB, alongside international bodies accredited to operate locally such as SGS Kenya, Bureau Veritas, TÜV Rheinland, and DNV). It happens in two stages. In Stage 1, the auditor reviews the ISMS documentation, confirms the scope is well defined, and prepares for the on-site audit. In Stage 2, they evaluate the actual implementation of the controls through interviews, evidence review, and system testing.
If everything checks out, you get the certificate, which is valid for three years. During that period, surveillance audits happen annually, and at the three-year mark, you go through a full recertification audit.
➡️ Discover how to get ISO 27001 certification.
Common mistakes when implementing ISO 27001
Most implementations that stall do so because of approach mistakes. These are the six that come up most often.
- Treating the standard as a one-time project: ISO 27001 isn’t something you pass like an exam—it’s something you maintain. Companies that ease off after getting certified show up to the next audit with half their ISMS out of date.
- Defining too narrow a scope: limiting scope to the most prepared department makes the audit cheaper, but the certificate only covers that piece. Any sharp procurement team catches it on the first read.
- Documenting for the auditor instead of for operations: a policy nobody actually uses day to day is just there to pass the audit. When the next incident hits, that policy won’t help anyone.
- Underestimating device fleet management: without an up-to-date inventory and consistent controls across laptops and mobile devices, several Annex A controls fail together during the audit. An unmanaged endpoint is one of the easiest entry points for an attacker.
- Outsourcing everything to a consultant: a consultant supports your team, they don’t replace it. If the knowledge lives outside the company, the day the vendor walks out the door, you’re flying blind.
- Treating training like a checkbox: a 30-minute course once a year doesn’t change anyone’s behavior. You need role-based training, periodic refreshers, and live simulations (phishing, incident response).
How Factorial IT helps you get ISO 27001 certified
Factorial IT covers, from a single platform, the technical areas auditors dig into most during an ISO 27001 audit—identities, devices, SaaS access, antivirus, and employees—so the evidence auditors ask for generates itself through daily operations, without having to rebuild anything the day before. Here are the six blocks it automates:
- IT asset inventory: automatic catalog of devices, software, and access across the company, always up to date and exportable for the audit.
- Access control: centralised management of SaaS access, with permissions assigned and revoked automatically based on each employee’s role.
- Device security: encryption, passwords, and lock settings applied automatically to every device. Compatible with Mac, iOS, Windows, and Linux.
- Secure off-boarding: the moment a departure is recorded in HR, all the employee’s access is closed without manual intervention and with no lingering accounts.
- Malware protection: advanced antivirus deployed on every device, with detection for malware, ransomware, and zero-day threats.
- Audit evidence: compliance logs and reports generated automatically, ready to export and hand over to the auditor at any moment.

