- Okay, but what is ISO/IEC 27001?
- 93 Controls, because peace was never an option...
- Funmi and Michael went back to school...
- Security goes beyond the tech department...
- Nights started losing their meaning...
- The practice test asked uncomfortable questions...
- The main, the main...
- Security does not graduate...
PCI DSS nearly finished us. Apparently, one certification was not enough.
The PCI DSS ink was barely dry when we started this one.
We originally planned to work on both certifications at the same time. Because why do one difficult thing when you can do two difficult things and lose your mind twice as fast?
Then we researched what that would involve, looked at each other, and allowed good sense to prevail.
“Let’s drink water and drop the cup first.”
One certification at a time.
We completed PCI DSS, took one breath, and started working towards ISO/IEC 27001:2022.
If PCI DSS tested our patience, ISO arrived with the full syllabus.
Okay, but what is ISO/IEC 27001?
ISO/IEC 27001 is the best-known international standard for information security management systems, or ISMS for short.
It is not software you install or a checklist you complete once and forget inside a folder. It defines how a company must establish, operate, review, and continually improve the system it uses to protect information.
In plain English, a company must know what information it holds, what could go wrong, who owns each risk, and what controls are in place. Then it must prove that those controls work.
“Trust us” cannot carry the argument. An independent auditor has to check and agree, and those independent auditors do not normally smile while at it.
93 Controls, because peace was never an option…
ISO/IEC 27001 has seven core requirement clauses, from Clauses 4 to 10. Annex A also contains 93 reference controls across four areas: organisational, people, physical, and technological.
Not every control is blindly copied into every company. Each organisation must assess its risks, decide which controls it needs, and justify those decisions.
For us, that process produced more than 100 documents.
Policies, procedures, records, logs, screenshots, approvals, and sign-offs.
If a document said we followed a process, we had to show evidence that we actually followed it. Writing a beautiful policy that nobody practises is just very well-formatted fiction, and auditors are not moved by fiction.
Even a locked laptop is only one part of security. The person holding it must also know what to do, what not to do, and why any of it matters.
It was a lot.
It was supposed to be.
Funmi and Michael went back to school…
To lead the process, Funmi, our compliance lead and now officially our ISMS Manager, and Michael, our tech lead, had to become certified Lead Implementers.
Congratulations to Funmi on the new responsibility nobody warned her would come with homework.
Becoming Lead Implementers meant studying the standard and sitting exams.
Actual exams, with actual pass marks.
You can think of it as JAMB, but for information security.
Security goes beyond the tech department…
Information security reaches far beyond the Tech and Compliance teams.
It affects how People handles a new employee’s laptop. It shows up in how Finance stores an invoice, how Growth manages customer information, and how someone in Customer Experience handles a complaint containing personal details.
That meant every team lead at Breet had to become an ISO Champion.
Each Champion learned enough about the standard to manage risks within their department, make sure their team followed the agreed processes, and find gaps before an auditor did.
Funmi and Michael could understand ISO/IEC 27001 from cover to cover, but the system would still fail if everyone else treated security as their problem.
Three words came up so often that we could probably recite them in our sleep: confidentiality, integrity, and availability.
Translation: information stays private, data remains accurate, and authorised people can access it when they need it.
Every department had a part to play in keeping those three promises.
Nights started losing their meaning…
PCI DSS gave us late nights. ISO made it difficult to tell when one day ended and another started.
The work was not glamorous. It was document reviews, follow-ups, policies, procedures, process checks, and evidence requests.
Then more follow-ups.
We knew why we were doing it. People trust Breet with sensitive information every day. That trust deserves more than good intentions and confident statements about security.
It deserves a system that people outside the company can inspect.
Still, knowing the reason did not make the workload smaller.
The practice test asked uncomfortable questions…
Then came the internal audit, our first real look at how the external assessment might go.
Had we done enough?
Were we following everything we had written?
Would the evidence support what we claimed?
Was there a gap hiding somewhere inside one of those documents?
We almost fought the internal auditor, like “are you for us or against us?”, she was neither, the need was the need.
Nevertheless, we took every point from the internal audit report and went back to work. Outstanding requirements were reviewed. Gaps were addressed. Evidence was checked again.
Then the external auditor arrived.
The main, the main…
The external audit lasted four full days. One document, one question, one answer, multiple evidences. Then repeat.
More than 100 documents came up one after another.
Yes, we completed that.
Yes, we updated this.
Yes, we use that tool. Here is how it works and who manages it.
And, of course, here is the evidence: the screenshot, log, timestamp, or sign-off.
Four days of questions is a lot. But all the late nights and follow-ups meant we walked in with receipts. It showed.
The auditor told us that we had gone beyond the requirements in most areas.
Not a bad way to finish four days of opening documents while someone waits for you to prove every sentence inside them.
Phew.
Security does not graduate…
We are now certified to ISO/IEC 27001:2022.
Funmi and Michael also passed their exams and are officially certified Lead Implementers. Yes, both of them survived JAMB for information security.
The certification confirms that an independent auditor assessed our information security management system against an international standard.
It does not mean security work is finished. Threats change, systems change, and the standard requires continual improvement.
Security cannot depend on one person remembering the right thing at the right time. It needs clear ownership, working controls, evidence, regular reviews, and people across the company who understand their part.
First PCI DSS. Now ISO/IEC 27001:2022.
Funmi and Michael can put the textbooks down for a moment.
Drink water, drop cup.
On to the next standard.
We stay building. 🔐





