1. What ISO 27001 is
Confidentiality, integrity, availability, and risk
Information security in ISO 27001 is built on three properties, often called the CIA triad. Every control in the standard exists to protect one or more of them.
Confidentiality
Information is only accessible to the people who are authorised to see it. A leaked salary spreadsheet, a client file emailed to the wrong recipient, or a screen visible to a stranger on a train are all confidentiality failures.
Integrity
Information is accurate and complete, and it has not been tampered with or corrupted. If an invoice amount is silently changed, or a patient record is overwritten with the wrong data, integrity has failed even though nothing was "stolen."
Availability
Information is accessible to authorised people when they need it. A ransomware attack that encrypts your files, a deleted shared folder with no backup, or a critical system down during month-end are all availability failures.
It helps to notice that these can pull against each other. Locking data away so tightly that nobody can use it protects confidentiality but destroys availability. Good security is about balance, not maximum lockdown.
The risk-based approach
The second big idea in ISO 27001 is that security decisions should be driven by risk. The organisation identifies its information assets, works out what could go wrong (threats and vulnerabilities), estimates how likely and how damaging each scenario is, and then decides how to treat each risk: reduce it with controls, avoid it, transfer it (for example through insurance or a supplier), or accept it knowingly.
This is why security rules differ between organisations, and even between teams in the same organisation. A rule that feels strict in your role probably exists because a risk assessment found a real exposure behind it. It also means security is proportionate: the standard does not demand that every risk is eliminated, only that risks are understood, treated sensibly, and reviewed as things change. When your work changes, new systems, new suppliers, new ways of handling data, the risks change too, which is why security is never "done."
› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement