Chapter 4
04The ISO 27001 Framework: The Information Security Management System
“A system does not prevent every incident, but it ensures the same incident never surprises us twice.”
ISO 27001 is the international standard for establishing, implementing, maintaining and continually improving an information security management system (ISMS). It gives creative and software organisations a structured approach to managing their information security, strengthening their security posture and embedding a culture of continual improvement. This chapter takes an in-depth look at the 2022 edition, its components, and why it suits the creative sector in particular.
What Is an Information Security Management System?
An ISMS is a systematic approach to managing an organisation’s sensitive information so that it stays secure. It covers people, processes and IT systems, and rests entirely on a risk management process. It suits any organisation of any size in any sector, protecting information assets in a systematic and cost-effective way. Its aim is to reduce the risk of security breaches and ensure business continuity by proactively limiting the impact of any breach that does occur.
A management system is not a tool you buy; it is a way of making decisions that repeats every day.
Key Components of ISO 27001:2022
The standard is built around a series of clauses (4 to 10) that guide the construction of the system, followed by Annex A with its list of reference controls. These are the key components:


Text in this figure
Context · Clause 4 · Leadership · Clause 5 · Planning · Clause 6 · Support · Clause 7 · Operation · Clause 8 · Evaluation · Clause 9 · Improvement · Clause 10 · Annex A · 93 controls · Clauses 4–10 are mandatory for every management system; Annex A is the control reference · Figure 5
- ISMS scope: The first step is identifying the information that needs protection: creative content, client data, code and everything else operations depend on. The scope is clearly documented and takes into account the organisation’s context, requirements and risk appetite.
- Leadership and commitment: The system’s success depends on leadership commitment: driving the initiative, providing resources, approving policies, participating in earnest, and embedding information security in the organisation’s culture rather than its drawers.
- Planning: Identifying potential threats to assets and exploitable vulnerabilities, then a systematic assessment of the likelihood and impact of risks, then a treatment plan that decides whether to mitigate, transfer, avoid or accept.
- Support and operation: Allocating resources in people, technology and budget, training and awareness programmes so everyone understands their responsibilities, then implementing the processes and procedures defined in planning.
- Performance evaluation: Regular review of the system’s effectiveness and its adaptation to new challenges: internal audits, monitoring security metrics, and management reviews from which areas for improvement emerge.
- Improvement: Corrective actions for nonconformities, updating the risk assessment and treatment plan, and every adjustment needed to strengthen the system.
Benefits of Adopting ISO 27001 in the Creative Industries
- Protecting intellectual property: A robust framework for securing designs, scripts, films, code and digital files against theft, misuse and sabotage.
- Enhancing client trust: Compliance with an internationally recognised standard builds stronger trust with clients increasingly concerned about their data.
- Regulatory compliance: It helps meet data protection laws such as the EU GDPR and reduces the risk of penalties.
- Competitive advantage: Certification is a differentiator in a crowded market, and often a condition for qualifying in large clients’ tenders.
- Operational efficiency: The systematic approach streamlines processes, reduces inefficiencies and improves overall performance.
2026 Update
Every valid certificate today is on the 2022 edition since the transition period ended in October 2025. The main changes from 2013: controls reorganised from 114 in 14 domains to 93 in four themes, and 11 new controls added, including threat intelligence, security for cloud services, secure coding and data leakage prevention.
By adopting this framework, a creative organisation not only protects its assets but builds a resilient, agile security culture that suits its dynamic nature. And with every new challenge, the standard’s principles remain a steady approach to securing its cyberspace.
Lessons Learned
- 1An ISMS is a risk-based approach covering people, processes and technology.
- 2Clauses 4 to 10 are the system’s structure, and Annex A is the list of reference controls.
- 3Certification protects intellectual property and opens the doors of major clients.
- 4The 2022 edition is the only reference for certification today.
Tip: use ← → to move between sections.

