
A Practical Guide to ISO 27001 Controls for SMEs
- Tony Atiba
- Jul 12
- 6 min read
A lost laptop, an over-permissioned shared folder or a supplier with weak security can create far more than an IT inconvenience. For a growing business, the outcome may include disrupted operations, damaged customer confidence and a difficult conversation during a tender or client audit. This guide to ISO 27001 controls explains how to turn the standard’s security expectations into practical measures your business can operate and evidence.
ISO 27001 is often misunderstood as a long checklist of technical safeguards. It is not. It is a risk-based management system standard. Its purpose is to help an organisation identify information security risks, decide how they will be treated and demonstrate that the chosen controls are working. The controls in Annex A support that process, but they do not replace it.
What ISO 27001 controls are designed to achieve
The ISO 27001:2022 standard includes 93 Annex A controls. They are grouped into four themes: organisational controls, people controls, physical controls and technological controls. Together, they address the conditions that allow information to remain confidential, accurate and available when it is needed.
This structure matters because information security is not solely an IT responsibility. A strong password policy will not solve a risk created by unclear ownership of customer data. Equally, a well-written procedure offers limited protection if a former employee can still access business systems. Effective control selection brings people, processes, premises and technology together.
The controls are not automatically mandatory in every case. Your organisation must assess its risks, determine which controls are necessary and justify any exclusions. This decision-making is captured in the Statement of Applicability, commonly called the SoA. It is one of the most important documents in an ISO 27001 management system because it shows which Annex A controls apply, why they apply, how they are implemented and whether they are operating effectively.
A sensible approach avoids two common errors. The first is adopting every control without considering whether it fits the business. The second is excluding controls simply because they appear inconvenient. Certification auditors will expect clear, risk-based reasoning either way.
A guide to ISO 27001 controls by control theme
Organisational controls
Organisational controls establish the framework for managing security. They cover areas such as information security policies, roles and responsibilities, asset management, supplier relationships, incident management, business continuity and legal requirements.
For SMEs, the practical starting point is clarity. Decide who owns information security at management level, who approves key policies and who can make decisions during an incident. A small business may not need a dedicated security department, but it does need defined accountability. If responsibility sits vaguely with “the IT person”, gaps are likely to appear when decisions need to be made quickly.
Supplier controls deserve particular attention. Many businesses rely on cloud software, outsourced IT support, payroll providers and marketing platforms. You remain accountable for understanding how suppliers affect the confidentiality and availability of your information. This does not mean every supplier needs a lengthy audit. It does mean risk-proportionate checks, appropriate contractual terms and a process for reviewing critical providers.
People controls
People controls recognise that security depends on everyday behaviour. They include screening where appropriate, employment terms, awareness training, remote working arrangements and the management of responsibilities when people leave or change roles.
Training should be relevant to the work people actually perform. A generic annual presentation may satisfy a basic requirement, but it is unlikely to change behaviour on its own. Staff handling customer information need to understand secure sharing and verification practices. Managers need to know how to report suspected incidents. Employees working remotely need clear expectations for devices, screens, home networks and printed information.
Offboarding is a high-value control that is frequently overlooked. Access should be removed promptly, company equipment returned and shared passwords or security credentials changed where needed. A documented leaver checklist provides simple, repeatable evidence that these actions take place.
Physical controls
Physical controls protect offices, equipment and records from unauthorised access, damage, theft or environmental threats. The right measures depend on your premises and the sensitivity of the information you hold.
A business operating from a serviced office will have different needs from one running a warehouse, clinic or production site. Controls may include visitor sign-in, locked storage, clear desk arrangements, secure disposal bins, alarm arrangements and protection for equipment used away from the office. The question is not whether a control looks impressive on paper. The question is whether it reduces a relevant risk in the way your organisation works.
For example, if staff regularly take laptops to client sites, encrypted devices and a clear lost-device reporting process may be more valuable than an elaborate visitor policy. If hard-copy records contain personal or commercially sensitive information, secure storage and confidential waste arrangements may need greater focus.
Technological controls
Technological controls include identity and access management, authentication, malware protection, backups, logging, vulnerability management, secure configuration, encryption and network security. They are often the most visible part of an information security programme, but technology must be supported by defined processes and ownership.
Access control is a useful example. Start with the principle of least privilege: people should receive only the access they need for their role. Use individual user accounts rather than shared logins, apply multi-factor authentication where practical and review access regularly, especially for privileged accounts. Documented approval for access changes helps demonstrate control and makes errors easier to identify.
Backups also require more than simply enabling a cloud setting. You need to know what is being backed up, how frequently, where copies are held, who can restore them and whether restoration has been tested. A backup that has never been tested is an assumption, not evidence of resilience.
Patch and vulnerability management should be proportionate and planned. Keep an inventory of important devices and software, define who receives security alerts and establish timescales for applying updates based on risk. Critical vulnerabilities affecting internet-facing systems will usually need faster action than low-risk updates on isolated equipment.
Build control selection from your risk assessment
The most efficient route to implementation begins with the information your business needs to protect. Identify key assets such as client records, financial data, intellectual property, operational systems, employee data and essential supplier platforms. Then consider realistic threats, existing weaknesses and the potential effect on confidentiality, integrity and availability.
A risk assessment does not need to be excessively complex. What matters is that it is consistent, understood and capable of driving decisions. A simple scoring method can work well when it considers likelihood, impact, existing safeguards and the action required. Record the risk owner and review date so that important issues do not disappear into a spreadsheet.
From there, decide whether to reduce, avoid, transfer or accept each risk. Where reducing risk is the appropriate treatment, select controls that address the cause rather than merely the symptom. If phishing is a concern, for example, awareness training, multi-factor authentication, email filtering and incident reporting may work together. Relying on one measure alone may leave a significant gap.
Evidence matters as much as implementation
Auditors will want to see more than policies. They will look for evidence that controls are operating in practice. The best evidence is usually generated through normal business activity, not created hurriedly before an audit.
Useful records may include access review results, training attendance and assessment results, supplier review notes, incident logs, backup restoration tests, vulnerability reports, maintenance records and internal audit findings. Keep them organised, controlled and available for the relevant retention period.
Avoid creating documentation that your team cannot maintain. A concise procedure followed consistently is stronger than a detailed manual that nobody uses. The level of documentation should reflect your risks, complexity and business size, while still showing that the management system is controlled.
Review controls and improve them over time
ISO 27001 certification is not a one-off project. New clients, new software, remote working changes, acquisitions and emerging threats can all change your risk profile. Regular internal audits, management reviews and corrective action processes help keep the system relevant.
When a control fails, focus on the underlying cause. If access reviews are repeatedly late, the answer may not be another reminder. It may be unclear ownership, an impractical review frequency or no reliable source of user access data. Corrective action should improve the system, not merely close an audit finding.
For businesses pursuing certification, early planning makes a material difference. Establish the scope carefully, secure management commitment, complete a realistic gap assessment and prioritise the controls that reduce the most significant risks. Specialist support can be particularly valuable where internal resources are limited or where a client deadline is approaching.
The most credible ISO 27001 system is one your people can use without unnecessary friction. When controls reflect real risks and normal working practices, compliance becomes evidence of a well-managed business rather than a folder prepared for audit day.

Comments