Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Security frameworks

    ISO 27001

    ISO/IEC 27001 is the international standard for information security management systems. It specifies requirements for establishing, operating and continually improving an ISMS, including risk assessment, a statement of applicability against Annex A controls, internal audit and management review, and it can be independently certified.

    What ISO 27001 means in practice

    ISO 27001 differs from the Essential Eight in kind rather than degree. The Essential Eight prescribes specific technical mitigations. ISO 27001 specifies a management system: a documented, risk-driven way of deciding which controls apply, implementing them, checking that they work, and improving them. Two certified organisations can have quite different control sets, both legitimately.

    The core requirements cover context and scope, leadership commitment, information security objectives, risk assessment and treatment methodology, a statement of applicability recording which Annex A controls apply and why any are excluded, competence and awareness, documented operating procedures, performance monitoring, internal audit, management review, and corrective action.

    Certification involves a certification body performing a Stage 1 documentation review and a Stage 2 implementation audit, followed by annual surveillance audits and recertification on a three-year cycle. The audit tests whether the management system is being operated, which means evidence of reviews actually held, risks actually assessed and incidents actually processed — not a folder of policies written the month before.

    The commercial driver is usually procurement. Enterprise and government buyers, and increasingly large corporate clients, ask for certification as a precondition rather than a preference, and it shortens security questionnaires considerably. For organisations selling into those markets the certification pays for itself in sales cycle time.

    Mycelium 365 holds this certification itself: our information security management system is certified to ISO/IEC 27001:2022 by QAS International under certificate AIT1045, valid to 20 August 2027, covering our managed IT, cloud, cybersecurity and helpdesk services. Clients running supplier assurance on us can request the certificate and Statement of Applicability.

    Scope definition is the decision that determines cost. A scope covering one product line and the teams supporting it is achievable; a scope covering an entire diversified group is a much larger programme. Related standards worth knowing are ISO 27017 and 27018 for cloud, and ISO 42001 for AI management systems, which is becoming relevant as organisations deploy AI tooling into regulated processes.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.