3. Everyday controls
Backups, change management, and supplier security
Three more control areas shape your daily work, even when you barely notice them.
Backups
Backups protect availability. When ransomware, hardware failure, or simple human error destroys data, the backup is what turns a disaster into an inconvenience. The organisation runs backups of its approved systems and storage locations, and that sentence contains your responsibility: work in the approved locations. A file that lives only on your desktop, a personal drive, or an unapproved app is a file that is not backed up. If it matters, it belongs where the organisation can protect it. If you ever lose data, report it straight away, because restore options shrink as time passes.
Change management
Change management means significant changes to systems are planned, approved, tested, and reversible, rather than made on the fly. It exists because a large share of outages and security holes are self-inflicted: a well-intentioned tweak with an unforeseen consequence. For most staff the rule is simple. Do not make unapproved changes to systems, settings, or software. That includes installing unapproved applications, disabling security tools because they are slowing you down, and signing the team up to a handy new cloud service without going through the proper route. That last habit even has a name, shadow IT, and it is a recurring source of audit findings because it creates stores of company data that nobody is protecting, backing up, or even aware of. If a tool would genuinely help, ask for it. The answer is often yes, through a route that keeps the data safe.
Supplier security
Your organisation's information does not stay inside its walls. Cloud platforms, payroll providers, IT support firms, and contractors all handle it, and a breach at a supplier is a breach of your data. ISO 27001 therefore requires security to extend into the supply chain: assessing suppliers before they get access, putting security requirements into contracts, and reviewing them over time. Your part is to respect that process. Do not share company information with a new supplier or tool that has not been approved, and if a supplier asks you for access or data outside the agreed arrangement, check before you comply.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement