top of page

ISO27k SME infosec guide

  • 13 hours ago
  • 2 min read

ISO/IEC JTC 1/SC 27/WG 1 is making progress on a proposed new ISO27k information security standard for Small to Mid-sized Enterprises with up to ~250 people. An initial rough draft will be fleshed-out over the coming years if the project is approved by the committee in its meeting at the end of this month. 



The draft's 39 SME information security controls are drawn from/basd loosely on ISO/IEC 27002 controls:

  • Half the controls are classified as "Initial baseline", suggested as likely priorities for all SMEs - a useful starting set, even for micro-organisations.

  • The remainder marked "Reinforced guidance" are offered as enhancements building on the starter set for [larger] SMEs who accept the need and value, and have the resources to adopt them.


If the project gets the committee's go-ahead, there will no doubt be plenty of debate and word-crafting on the controls, their purpose, classification and wording. Persuading the committee to use plain action-oriented language that SMEs will actually understand and use is a constant battle in the standards arena.  As Chris Hall put it: "Most SME owners don't want to learn ISO terminology—they want clear, practical guidance that tells them what to do, why it matters, and how much effort it will take. If the guide achieves that, it will reach a much wider audience."


Aside from the controls, the standard will essentially describe an ISMS-lite, providing guidance for SMEs on the governance and management aspects e.g. applying the conventional ISO27k risk-based approach, with direction, control and assurance for management and other stakeholders.  I hope we can build a convincing case for SMEs to adopt a sustainable approach to the management of information risk, security, privacy, safety, resilience, compliance and all that, without this being yet another minimalist checklist thing.


Meanwhile, the Adaptive SME Security paper remains freely available for those SMEs who can't afford to wait for the ISO version. Here's a visual overview of the 5-phase 'adaptive' approach:



If you'd like to see the initial draft and maybe get directly involved in the committee's work on this and other infosec standards, please contact your national standards body


 
 

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page