ISO27001: 2005 – International Standard for Information Security

ISO27001 is the International Standard for Information Security. The Standard lays out the simple framework for an Information Security Management System, helping to deliver improved internal security arrangements within your business.

The Quality Assurance Consulting Team at Parker has extensive experience of working with businesses to achieve the standard, especially in financial services, debt recovery, data warehousing, and people search businesses.

Threats and damage to a company’s reputation can occur through information loss, whether deliberate or accidental.

As companies use more IT technologies for communication and data storage, its integrity is sadly often overlooked and rarely policed with dire consequences if it is lost or misused.

The benefits of a good security system include:

  • A more positive image with major customers, who wish to deal with an organisation with a proven security approach.
  • Reduction in security breaches.

Reduction in data loss

  • Improved IT security accountability and responsibility
  • Reductions in adverse publicity.

For many businesses ISO27001 is a prerequisite for winning public sector and large scale contracts. For those handling sensitive or personal data it’s an essential management tool.

How ISO27001 will improve your business

The Information Security Standard ISO27001 will help a business create a coherent Information Security Management System, relevant to the type of services offered by your organisation.

By applying ISO27001 within any organisation, large or small employee knowledge of the importance of data security will be enhanced.

Opportunities for security breaches will diminish through the application of sound security policies and controls.
By gaining registration to ISO27001 from a premier UKAS approved certification body your business will be able to demonstrate the highest levels of information security management in the world.

What is ISO27001?

  • ISO27001: 2005 was formally adopted by the International Standards Organizations as the internally recognized framework for information security management.
  • The Standard is designed to dovetail into other Standard such as ISO9001 the international standard for quality assurance.
  • The Standard is now in two parts. ISO/IEC 17799: 2005 (Part 1) provides a standard of good practices which may help in the creation of an effective information security management system.
  • ISO/IEC 27001 (Part 2) is the formal specification. This is the Standard by which UKAS approved certification bodies conduct audits for compliance and certification.
  • An appendix to the Standard called Annex A, list a variety of controls. Controls are selected that suit the business needs, and describe how systems and people issues are effectively managed, with regards to information security and good data handling techniques.

Who have we helped?

This selection of recent assignments provides a flavour of the kind of work we do:

  • Advised the first debt collection agency within the UK to obtain registration to ISO27001: 2005 the International Standard for Information Security.
  • Implemented ISO27001 within the first UK manned guarding company.
  • Implemented ISO27001 within a secure archive in Kent, providing off-site storage for major city law firms requiring high security storage. The company attained registration to ISO27001 from a major UKAS certification body.

For advice and information on ISO27001 call 0121 764 5161.


Parker Chartered Accountants and Financial Advisors, 1192 Warwick Road, Acocks Green, Birmingham. B27 6BT.
Tel: 0121 764 5161  Fax: 0121 764 7833  Email Parker Chartered Accountants here