Why true ISO 27001 compliance goes far beyond technical controls.
If you asked ten people what ISO 27001 is, most would describe it as an information security standard.
They'd be right.
But ask what it takes to achieve and maintain ISO 27001 compliance, and the answers quickly become much narrower.
Cloud security.
Identity management.
Device monitoring.
Infrastructure visibility.
Those capabilities are all important.
But they're only part of the picture.
Under ISO 27001:2022, there are 93 controls. Of which, only 34 in fact are technical.
The remaining 63% sit elsewhere across organisational, people and physical controls.
That's the part of ISO 27001 that receives far less attention.
Yet it's the part that determines whether an Information Security Management System (ISMS) actually works.
The misconception at the heart of ISO 27001.
Over the last few years, a lot of compliance software has become increasingly focused on technical automation.
Connect your cloud environment.
Scan your infrastructure.
Monitor vulnerabilities.
Automatically collect technical evidence.
And those capabilities are valuable. But they're solving a different problem.
Monitoring infrastructure helps organisations understand the health of their technology.
Managing ISO 27001 controls is about demonstrating that the right governance, accountability and operational processes are embedded across the business.
Those are different things.
One helps you identify technical risks. The other demonstrates that your organisation has the structure and discipline to manage them consistently.
ISO 27001 is a business system, not an IT project.
One of the biggest misconceptions surrounding ISO 27001 certification is that it's owned by the IT team.
Technology undoubtedly plays a central role. But a successful ISMS extends far beyond IT.
It involves:
- HR onboarding and offboarding processes
- Supplier assurance
- Risk management
- Physical access controls
- Management reviews
- Internal audits
- Policy ownership
- Security awareness
These aren't simply technical activities – they're business operations.
Which means ISO 27001 shouldn't be treated as a technology project. It should become part of how the organisation governs risk, assigns accountability and demonstrates trust.
That's why we built Hicomply as a whole-business ISMS – to help businesses embed compliance into everyday operations, rather than treating it as a separate workstream.
The other 63% is where compliance becomes operational.
When people talk about "the other 63%", they're often surprised by what it actually includes.
It's not abstract governance. It's the everyday activities that determine whether security is embedded across the organisation.
This can include, for example:
- Employees reviewing and acknowledging information security policies
- Assigning ownership for controls and risks
- Managing supplier reviews
- Completing recurring governance activities
- Maintaining evidence that policies have been communicated and understood
These tasks not only likely take place every day, they’re also rarely complex.
But, as organisations grow, they become increasingly difficult to manage.
Operationally, this often involves multiplying spreadsheets, Outlook reminders and email chains.
That's where compliance starts to shift from enabling the business to consuming it.
A practical example: Policy acknowledgement.
Let’s take policy management as an example.
Writing an Information Security Policy is only part of the requirement. ISO 27001 also expects organisations to demonstrate that relevant employees are aware they exist and understand their responsibilities.
For a small business, sending policies by email and tracking acknowledgements manually may be perfectly manageable.
But as the organisation grows, so does the administrative burden.
At 50 employees, keeping track of who has read what becomes increasingly difficult.
At 500, it's almost impossible to manage consistently.
At enterprise scale, it's simply unsustainable.
Every policy update creates another round of emails. Another spreadsheet. Another reminder. Another exercise in proving who has (and hasn't) read the latest version.
The challenge isn't writing the policy.
It's operationalising it.
That's why Hicomply's Policy Reading & Acceptance Tracker exists.
Instead of managing policy distribution through Outlook, spreadsheets and manual follow-ups, we bring the entire process into a modern, trackable workspace.
Policies can be assigned to individuals or entire teams, with automatic reminders whenever a document needs reviewing or re-accepting.
Employees acknowledge policies directly within the platform, creating a complete audit trail without relying on manual administration or email chains.
Depending on the size of the organisation, that can save hundreds of hours of administrative effort every year. All while giving compliance teams the confidence that the right people have read the right policies at the right time.
It's a relatively simple capability. But it's a perfect example of what managing the "other 63%" actually looks like.
Not another dashboard.
Not another infrastructure scan.
Just operationalising one of the people controls thatsupports ISO 27001 compliance.
Why this matters beyond your next ISO 27001 audit.
One of the biggest mistakes organisations make is treating ISO 27001 as a certification project.
The objective becomes passing the audit. The ISMS becomes something that's revisited once a year.
The most resilient organisations take a different approach. They use ISO 27001 to strengthen how the business operates every day. The result?
- Ownership becomes clearer
- Governance becomes more consistent
- Employees understand their responsibilities
- Evidence is created as work happens
- Audits become validation rather than preparation
That's where the real value of an ISMS begins.
The future of ISO 27001 isn't more technology.
Technology will always play an essential role in information security.
But technology alone doesn't create compliance, nor does it create trust.
The organisations implementing the most resilient approaches are the ones recognising that compliance extends beyond infrastructure and into the way the entire business operates.
Because while only 34 of ISO 27001's 93 controls are technical, every one of the remaining controls contributes to something much bigger.
A stronger security posture.
Better governance.
Greater accountability.
And an organisation that's audit-ready – not just when certification comes around, but every day.


.avif)






















%20(1).png)

%20(1).png)
.png)
%20(1).png)
