Blog
Recent blogs

ISO 27001 Clause 4.1 - Understanding the Organisation and its Context
Published on
21
September
2026
TRENDING
URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.
Read more
Data Protection
Published on
22/7/2022
Tips on Demonstrating UK GDPR ComplianceTRENDING
We provide some questions which should help you in determining your level of compliance with the GDPR
Data Protection
Published on
22/7/2022
Are you adequately covering GDPR within your ISMS?TRENDING
We have seen an increased focus on the General Data Protection Regulation (GDPR) by certification body (CB) assessors when conducting ISO 27001 audits.
Information Security
Published on
22/7/2022
What are the Most Common Insider Threats to Information Security?TRENDING
Broadly speaking, information security is held up by three pillars – People, Process and Technology. It is widely accepted that humans are the weakest link
Data Protection
Published on
21/7/2022
BS 10012:2017 – What are the Benefits and How Do I Achieve Certification TRENDING
BS 10012 is a standard which has been developed to enable organisations to implement a personal information management system (PIMS).
Data Protection
Published on
21/7/2022
Gaining Senior Management Buy-In to GDPR ComplianceTRENDING
Why can it still be challenging to gain traction on your GDPR compliance project?
Data Protection
Published on
21/7/2022
THE GDPR – 5 Myths DispelledTRENDING
The adoption of the General Data Protection Regulation (GDPR) in April 2016 had wide-ranging impacts. These affect all organisations.
Information Security
Published on
21/7/2022
ISO 27002:2022 UpdateTRENDING
The purpose of ISO 27002 is to provide organisations with guidance on selecting, implementing and managing information security controls.
Information Security
Published on
21/7/2022
What are the Primary Objectives of the Controls Detailed in Annex A of ISO 27001:2013? TRENDING
Annex A of ISO 27001 comprises 114 controls which are grouped into the following 14 control categories.
Information Security
Published on
21/7/2022
Everything You Need to Know About ISO 27001 CertificationTRENDING
As with all ISO standards, it has been developed by a panel of experts and provides a specification for the development of a ‘best practice" ISMS
Information Security
Published on
21/7/2022
How Do You Implement a Successful ISMS?TRENDING
Executing your decision to use an information security management system (ISMS) to manage the security of your information assets is a project. It is not.
Information Security
Published on
20/7/2022
10 Top Tips for Maintaining Information and Cyber Security When HomeworkingTRENDING
In this blog, we aim to provide 10 top tips to enable you to keep important information assets safe and secure whilst working remotely.
Information Security
Published on
20/7/2022
5 Common Fallacies Associated with ISO 27001 CertificationTRENDING
There are many good reasons to implement an information security management system (ISMS) and get it certified to ISO 27001.
Information Security
Published on
20/7/2022
Information Security Management Systems, ISO 27001 and the Benefits of ImplementationTRENDING
In this blog, we’re going back to basics and looking at some of the fundamentals of information security and ISO 27001.
Information Security
Published on
20/7/2022
How Do You Gain Top Management Commitment?TRENDING
In this blog, we’ll take a look at management commitment, one of the most significant.
Information Security
Published on
20/7/2022
How do You Develop and Implement an Incident Management Plan?TRENDING
Due to the increased use of technologies and the ‘human’ involvement, it is inevitable we are all going to face more and more information security incidents.
Information Security
Published on
20/7/2022
How do I Approach Asset Identification Within My Information Security Risk Assessment? TRENDING
Typically, this question is twofold; which assets to include and the depth or granularity. In this blog, we will look at granularity.
Information Security
Published on
20/7/2022
What Are the Critical Steps When Implementing an Effective Information Security Management System?TRENDING
URM assisted over 500 organisations achieve ISO 27001 certification, here are the critical steps when implementing an effective information security system.

Information Security
Published on
20/7/2022
Three Tips to Help you Simplify your Risk Management ProcessTRENDING
A key role of risk management is helping organisations decide how limited resources can be most effectively used to address the most pressing business issues.
Information Security
Published on
19/7/2022
How Do You Meet the Asset Management Requirements of IS0 27001?TRENDING
In order to meet the requirements of ‘Asset management’ A.8 from Annex A of ISO 27001, it is necessary to identify organisational assets and define protection
Information Security
Published on
19/7/2022
How do you Categorise Your Assets When Conducting an Information Security Risk Assessment? TRENDING
‘How do we approach asset identification within our information security risk assessment?’. This blog examines which assets or asset types to include.
Information Security
Published on
18/7/2022
What are the ‘Real World’ Benefits of Implementing ISO 27001?TRENDING
In this blog, we want to dig a bit deeper into the benefits that are gained from implementing the Standard and from achieving certification...
Information Security
Published on
18/7/2022
Key Things You Should Know About ISO 27001TRENDING
ISO 27001 is a standard for Information Security Management that provides any organisation with a framework to protect most valuable assets.

Information Security
Published on
21/6/2022
PCI SSC Remote Assessment Guidelines and ProceduresTRENDING
We address a number of key questions: What are the Main Contents? What Led to it Being Published? And others.

Data Protection
Published on
21/6/2022
When and How to Conduct a Data Protection Impact Assessment (DPIA)TRENDING
A DPIA delivers a pre-emptive approach to assessing these risks, and can prevent a data breach occurring. We present an outline of steps in conducting a DPIA

Information Security
Published on
13/6/2022
PCI DSS v4 – Changes at a GlanceTRENDING
After several years wait, and to surprisingly little fanfare, the PCI SSC released the new version of the PCI Data Security Standard (DSS).

Data Protection
Published on
13/6/2022
UK International Data Transfer AgreementTRENDING
DTA and the UK Addendum to the current European Commission’s SCCs re the next steps in providing a transfer tool for complying with the UK GDPR.

Data Protection
Published on
10/6/2022
How to Create a Record of Processing Activities (ROPA)TRENDING
In this blog, we will outline a step-by-step procedure on how you can create a ROPA.

Data Protection
Published on
8/6/2022
Who Needs a ROPA and Why?TRENDING
Under the UK GDPR, the majority of organisations processing personal data are required to create and maintain a ROPAs

Information Security
Published on
27/5/2022
What is ISO 27001? TRENDING
ISO 27001 is the International Standard for Information Security Management. It provides organisation with a framework and an approach to protecting assets

Information Security
Published on
25/5/2022
Benefits of Implementing ISO 27001TRENDING
What are the Benefits of Implementing ISO 27001? We dig a bit deeper on the benefits that are gained from implementing the standard.
We will ensure you never become a ‘slave to the Standard’ and your ISMS is something which can easily be maintained and improved.
Find out more
how URM CAN HELP?
URM CONSULTING services
Do you need any help with ISO 27001 certificate?
URM can help you achieve ISO 27001 certification
Read more
URM CONSULTING services
Do you need any help applying for Cyber Essentials Certification?
URM can offer a range of support services when applying for Cyber Essentials Certification. Check our offer!
Read more
URM CONSULTING services
ISO 27002:2022 Update
If you want to learn more about ISO 27002:2022 and how to implement the new controls and the new attributes, you can attend URM’s ISO 27001:2022 Control Migration Course.
Read more
"
Great presentation, thanks. I enjoyed the interaction between lead speaker and support person.
Webinar 'Planning Your ISO 27001 Audit Programme'
contact US
Let us help you
Let us help you in your compliance journey by completing the form and letting us know how we can best support you.
