rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/iso-27001-implementation-guide-australia
Printed 28 August 2026
ISO 27001 implementation in Australia: scope, Statement of Applicability and the two-stage audit
A practical ISO 27001 implementation guide for Australian organisations: setting scope, risk treatment, the Statement of Applicability, Stage 1 and Stage 2 audits, and evidence.
ISO/IEC 27001:2022 specifies requirements for an information security management system (ISMS). This guide is about implementation mechanics for an Australian organisation — the sequence of work, the artefacts a certification body will demand, and the Australian legal overlays that change what "in scope" means. If you are still deciding whether to pursue certification at all, start with ISO 27001 vs the Essential Eight, which compares the two frameworks and their fit.
The catalogue entry for the current edition is the ISO/IEC 27001 standard page. Rules Mate tracks the credential itself as the obligation iso-27001-isms-certification.
What certification actually requires
Certification requires two things that organisations consistently underestimate: a risk-driven ISMS that has been operating long enough to produce records, and a defensible Statement of Applicability.
The 2022 edition restructured the Annex A control set into four themes — organisational, people, physical and technological — and introduced controls addressing threat intelligence, cloud services, data leakage prevention, secure coding and information deletion. The clause 4 to 10 management-system requirements are the certifiable core; Annex A is the reference control set your risk treatment draws from.
An important structural point: the standard does not tell you which controls to implement. You decide, through risk assessment, and then justify every inclusion and exclusion. That is the opposite of a prescriptive baseline like the Essential Eight, and it is why organisations often run both.
Step 1: fix the scope before anything else
Scope is the highest-leverage decision in the whole program, and the most expensive to change later.
The scope statement names what is protected: which legal entities, business units, locations, services, systems and information types. It appears on the certificate, and it is the first thing a customer's due-diligence team reads. A certificate scoped to "the development and hosting of the X platform" answers a procurement question; a certificate scoped to "the head office IT function" usually does not.
Practical rules for scoping:
- Scope to what customers are buying. If the certificate does not cover the service under contract, it will not satisfy the contract.
- Do not exclude a dependency you cannot control. Excluding a shared identity provider or a corporate network that the in-scope service depends on invites a scope-integrity finding.
- Document interfaces and dependencies to anything excluded, including outsourced functions. The standard requires this.
- Be honest about cloud. Shared-responsibility boundaries must be stated, not implied.
Run a structured gap analysis against the scope you have chosen before committing budget. The ISO 27001 gap assessment tool gives you a clause-level starting position.
Step 2: risk assessment and risk treatment
The risk assessment is the engine of the ISMS, and auditors test it harder than any other artefact.
You must define and apply a repeatable information security risk assessment process with documented risk criteria, including risk acceptance criteria. You must identify risks to confidentiality, integrity and availability of information in scope; assign risk owners; analyse and evaluate the risks against your criteria; and then produce a risk treatment plan. The methodology in ISO 31000 is a common foundation, though ISO 27001 does not require it.
The three failures that generate findings:
- Criteria that were never applied. A methodology document exists; the register scores risks by intuition.
- Missing risk owners. Risks owned by "IT" rather than a named accountable person.
- A treatment plan with no residual risk position. The standard requires risk owners to approve the plan and accept residual risk. Unsigned acceptance is a finding.
Step 3: the Statement of Applicability
The Statement of Applicability (SoA) is the document that distinguishes a real ISMS from a paper one, and it is mandatory.
For every Annex A control, the SoA must record whether it is applicable, the justification for inclusion or exclusion, and whether it is implemented. Auditors sample it aggressively, because it is where over-claiming shows up. Build it as a live register, not a one-off spreadsheet, with these columns at minimum:
| Column | Why the auditor cares |
|---|---|
| Control reference and title | Traceability to Annex A |
| Applicable (yes/no) | The inclusion decision |
| Justification | Must tie back to a risk, a legal or contractual requirement |
| Implementation status | Implemented, partial, planned with date |
| Evidence location | Where the auditor will look |
| Owner | Who answers questions on audit day |
Exclusions must be justified against your risk assessment and your legal and contractual requirements — not against convenience. "Not applicable, we are a small team" is not a justification.
Step 4: internal audit and management review
Both are mandatory, both must be complete before the Stage 2 audit, and both are routinely rushed.
The internal audit program must cover the whole ISMS across the cycle, be conducted objectively and impartially, and report results to management. Auditing your own work is a finding. Small organisations legitimately use an external contractor for internal audit — that is not the same as the certification body, which cannot audit a system it consulted on.
The management review must cover every required input: status of prior actions, changes in external and internal issues relevant to the ISMS, feedback on information security performance including nonconformities, monitoring results, audit results, fulfilment of objectives, interested-party feedback, risk assessment and treatment plan status, and improvement opportunities. Minutes that record attendance and a decision to continue are not a management review.
Step 5: the two-stage certification audit
Initial certification is conducted in two stages under ISO/IEC 17021-1, the standard governing certification bodies. See ISO/IEC 17021-1:2015.
Stage 1 is a readiness and documentation review. The auditor evaluates your scope, ISMS documentation, risk assessment, SoA, internal audit and management review, and confirms you are ready for Stage 2. Stage 1 findings are typically raised as areas of concern, not non-conformances — but an unfavourable Stage 1 means Stage 2 is deferred, and you pay for both.
Stage 2 tests implementation and effectiveness through sampling: interviews, records, technical configuration evidence and site observation. Non-conformances are raised as major or minor. A major non-conformance blocks the certification decision until corrective action is verified. The mechanics of grading, correcting and closing findings are covered in surveillance audits, non-conformances and maintaining certification.
Choose a certification body accredited for ISO/IEC 27001 specifically — accreditation is granted by scheme, not blanket. Verification method is in our guide to choosing a JAS-ANZ accredited certification body.
Australian overlays: Privacy Act, SOCI, CPS 234, IRAP
Certification supports Australian legal obligations but discharges none of them. Four overlays change implementation.
Privacy Act. APP 11 requires an APP entity to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. The OAIC's guidance on APP 11 security of personal information and its Guide to securing personal information describe technical and organisational measures that map closely to Annex A. A certified ISMS is strong evidence of reasonable steps; it is not a safe harbour. See APP 11 reasonable steps.
SOCI. Responsible entities for critical infrastructure assets have their own risk management program obligation. An ISMS can supply much of the material, but the critical infrastructure risk management program has statutory content requirements of its own — see the CIRMP guide.
CPS 234. APRA-regulated entities must maintain information security capability commensurate with threats and vulnerabilities, and notify APRA of material incidents within defined timeframes. ISO 27001 does not map one-for-one; test your position with the CPS 234 readiness scorer and read CPS 234 information security.
Government work. Commonwealth security requirements draw on the Information Security Manual and, for hosting and system assessments, IRAP. These are separate assessment regimes, not ISO substitutes. See our overview of the Information Security Manual.
What drives cost and timeline
Cost has three components, and the audit fee is usually the smallest.
- Certification body fees, driven by audit days. Audit duration is set from effective headcount in scope, number of sites, complexity of the ISMS, and whether the audit is integrated with another standard.
- Remediation, which dominates for organisations starting without formal access reviews, logging, supplier assurance or business continuity testing.
- Sustained operating cost — internal audit, management review, risk reassessment, awareness training, and the annual surveillance audit.
Two levers reduce total cost materially: tightening scope to what customers actually buy, and integrating with any other management system you hold so context, competence, internal audit and management review run once. Get quotes from at least three accredited bodies against an identical scope statement, and compare audit days rather than headline price.
Frequently asked
How long does ISO 27001 certification take?
The gating factor is operating evidence, not documentation. A certification body must see the ISMS producing records, and a completed internal audit cycle plus a management review are mandatory inputs before Stage 2. Organisations with mature security practices move faster because remediation, not paperwork, is the long pole.
What is a Statement of Applicability and is it mandatory?
Yes, it is mandatory. The Statement of Applicability records, for every Annex A control, whether it applies, the justification for including or excluding it, and its implementation status. It is the document auditors sample hardest, because it is where over-claiming becomes visible.
Can I exclude parts of my business from the ISO 27001 scope?
Yes, but exclusions must be justified and the interfaces and dependencies to anything excluded must be documented. Excluding a system the in-scope service genuinely depends on — a shared identity provider, for example — invites a scope-integrity finding and produces a certificate that will not satisfy customer due diligence.
Does ISO 27001 certification satisfy the Privacy Act?
No. APP 11 requires reasonable steps to protect personal information, and a certified ISMS is strong evidence that reasonable steps were taken. It is not a safe harbour, it does not displace the notifiable data breach obligations, and it does not address the collection, use, disclosure and access principles at all.
Do I need both ISO 27001 and the Essential Eight?
Many Australian organisations run both. The Essential Eight is a prescriptive technical baseline measured by maturity level; ISO 27001 is a risk-led governance system with a certificate. Essential Eight controls can be documented as evidence within ISO 27001 risk treatment so the work is not duplicated.
Can my consultant also be my certification body?
No. Impartiality requirements prevent a certification body from certifying a management system it consulted on. You can use an external contractor for internal audit, but that contractor cannot then perform the certification audit.
Related
Related reading
ISO 27001 vs the Essential Eight: which framework for Australian business
ISO 27001 vs Essential Eight for Australian business: how the two frameworks differ, who each suits, certification vs maturity levels, and when to do both.
APP 11 — reasonable steps to secure personal information
How the OAIC interprets the APP 11 obligation to take reasonable steps to protect personal information, and the indicative controls expected of regulated entities.
ISO 27701 privacy information management and the Australian Privacy Act
ISO/IEC 27701:2025 is now a standalone privacy management standard. How a PIMS maps to the Australian Privacy Principles, and what it does and does not satisfy.
Surveillance audits, non-conformances and keeping certification between recertification cycles
How the three-year certification cycle works: surveillance audit scope, major vs minor non-conformances, root cause and corrective action, and suspension or withdrawal.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/iso-27001-implementation-guide-australia