Introduction

You’re an organisation with more than 49 people and are looking for comprehensive cyber security protection, where do you go? Have you achieved Cyber Essentials and are looking for more? Are you considering ISO 27001 but think it’s too much for an organisation of your size? This is where IASME Cyber Assurance can be a great fit. In this article we dive into the new (version 7) release of IASME Cyber Assurance and see how it can be applied to an organisation of more than 49 people.

 

What Is IASME Cyber Assurance?

  • A flexible and affordable information security standard that builds on Cyber Essentials 
  • Covers 14 themes which are aimed at making organisations more resilient
  • Each theme has requirements based on organisational size and risk
  • Two levels the scheme: a verified self-assessment and an audit
  • Certification can be gained for both levels 
  • Ideal for organisations looking for alternative, or next step towards ISO 27001

 

FeatureIASME Cyber Assurance Level OneIASME Cyber Assurance Level Two
Assessment Verified self-assessmentAudit
TestingAssessor reviews self-assessmentAssessor carries out audit and IASME moderator reviews
Controls14 themesSame 14 themes
Certification12 month certificate3 year certificate, with annual (Level One) renewals

This table shows the key differences between IASME Cyber Assurance Level One and Two

 

Which themes and requirements apply to an organisation with more than 49 people?

  • IASME Cyber Assurance covers 14 themes 
  • Each theme has a number of requirements (security measures)
  • An organisation can choose to implement the requirements, based on size and risk 
  • For an organisation with more than 49 people, all 14 themes and all 65 requirements are mandatory 
ThemesFurther insight on aim of the theme Number of Mandatory requirements for more than 49 person organisation
PlanningConsider information security for day-to-day activity and projects1
OrganisationHave a clear structure and foundation for effective security4
AssetsUnderstand what you have and how to protect it6
Legal and Regulatory Consider contractual obligations, data protection requirements and more4
RiskIdentify threats, treat and manage them appropriately9
Physical and environmentalPrevent theft, loss or damage and ensure protection from temperatures or humidity7
PeopleConsider education, awareness, training and least privilege4
Policy For ‘right-sized’ security controls7
Managing AccessImplement appropriate access to resources and data4
Technical IntrusionLeverage tools to detect and prevent unauthorised access2
Change ManagementControl and manage key changes1
Secure OperationsTake action based on warning and alerts5
Backups and RestoresHave regular and segregated data backups – test to ensure recovery4
ResilienceBusiness continuity, incident management and disaster recovery7

The table shows the 14 themes, along with a brief outline of the aim of each theme, and shows the number mandatory requirements for each theme, based on an organisation with more than 49 people 

 

What are the mandatory requirements for an organisation of 10 to 49 people?

Number of employeesMandatory RequirementsNon-Mandatory Requirements (considered based on risk)
1 – 2 people2045
3 to 9 people 3233
10 – 49 people 4817
50 or more people650

This table shows how the total number of requirements can be applied, based on organisational size

 

Details can be found in the standard, which is located on the IASME website here – a summary relating to the 32 requirements for an organisation with more than 49 people is provided below (based on interpretation and paraphrasing):

  1. Make provisions for information security as part of business planning 
  2. Ensure commitment, funding, and accountability for information security from the top
  3. Appoint a suitably skilled leader to coordinate and act on information security activities
  4. Form a group to coordinate and implement information security activities 
  5. Define SLA’s or other contracts for partners and the supply chain
  6. Keep an up-to-date register of all information assets (including personal / BYOD)
  7. For each asset, include category, location, value, and owner
  8. Identify sensitive assets 
  9. Encrypt sensitive data, removable media, portable devices, and data stored on the cloud (including in transit to/from the cloud)
  10. Review data held at least annually to ensure relevance and accuracy  
  11. Ensure assets are disposed of securely and removed from the asset register
  12. Maintain a list of requirements by legal, statutory, regulatory, and contractual obligations 
  13. Have processes and support to fulfil legal obligations 
  14. Monitor compliance, counter deviations, or improve business processes 
  15. Ensure business records are protected from loss, destruction, or falsification 
  16. Have an up-to-date and well-maintained risk assessment
  17. Extend risk assessment to cover customers, partners, contractors, and suppliers 
  18. Be aware of business risks and integrate with the information risk assessment
  19. Keep up to date with emerging cyber threats
  20. Agree on organisational acceptance of risk 
  21. Assign an owner to each risk and its treatment
  22. Use risk assessment to set rules on how people use technology 
  23. Create action plans from the risk assessment
  24. Have risk assessment and treatment plans signed off by an authorised person 
  25. Ensure risk assessment covers physical harm to assets
  26. Include physical security that may be dictated by law and third parties 
  27. Consider physical access control to protect your office environment
  28. Restrict access to wired and wireless networks to authorised users only
  29. Keep confidential information away from those not authorised to see and store it securely 
  30. Ensure physical and environmental protection for assets taken away from the premises 
  31. Ensure your environment is suitable for your equipment needs
  32. Have named individuals, roles, and responsibilities relating to information governance 
  33. Have rules for the acceptable use of company assets
  34. Ensure appropriate access to data 
  35. Have a suitable joiners, leavers, movers, and termination procedure 
  36. Have a comprehensive, yet right-sized security policy
  37. Ensure policies include purpose, scope, requirements, review, monitoring, and breaches
  38. Ensure someone with competence and authority approves policies
  39. Ensure policies can cope with potentially conflicting rules
  40. Ensure policy understanding 
  41. Ensure policy review and updates
  42. Provide people access to resources and data necessary for their roles, but no more
  43. Consider network segregation for sensitive assets
  44. Consider setting restrictions on the locations that can / can’t access data
  45. Ensure accounts and devices do not remain signed in indefinitely 
  46. Detect unauthorised activity, deploying technical tools to support
  47. Review and act upon output from your tools, scans, and testing at least weekly
  48. Have documented change procedures
  49. Track and monitor systems, identifying unacceptable issues and improving security posture
  50. Prevent access to monitoring systems and preserve records
  51. Scan systems for vulnerabilities  
  52. Include penetration testing if deemed necessary by your risk assessment 
  53. Pay attention to warnings and reporting, taking appropriate action 
  54. Backup at least weekly and before a significant change 
  55. Have at least one backup that’s off-site / some distance from the working copy
  56. Ensure the logical segregation and secure storage of backups
  57. Test restores (of data backups) at least monthly  
  58. Ensure data breaches are detected, recorded, and dealt with 
  59. Have a Business Impact Assessment, Business Continuity, and Disaster Recovery Plan
  60. Exercise your plan at least annually and keep it up to date to account for change
  61. Analyse records for recurring incidents, effective incident management, and the effectiveness of risk assessment and business impact 
  62. Learn lessons from events

 

How RB Consultancy Ltd Help?

As an Assessor and Certification Body for IASME Cyber Assurance, we carry out assessments and issue certificates for both levels of the scheme. Holding a Certified Information Systems Security Professional (CISSP) certification, we can also help organisations implement the security measures and provide support through the process. We have templates and documentation to leverage that can also assist with each theme and can therefore provide completed packages to support.

 

Conclusion – how Cyber Assurance certification can help organisations with more than 49 people

IASME Cyber Assurance can be a great next step beyond Cyber Essentials. It provides additional confidence and assurance that a variety of security measures are in place to protect organisations. These security measures can be applied based on organisational size and risk. For an organisation of more than 49 people, there are 62 mandatory requirements for the scheme. With our credentials and experience, we help organisations through both levels of the scheme and issue the associated certificates. If you would like more information or any support with IASME Cyber Assurance, please contact us.

 

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional and cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only.

 

 

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
The Top 10 Benefits of Cyber Essentials

The Top 10 Benefits of Cyber Essentials

  Introduction Cyber Essentials is a UK government-backed annual certification scheme that helps organisations protect against common cyber threats. It provides a clear framework for securing devices, networks, and data. By implementing five key technical controls – relating to firewalls, secure configuration, security updates, access control, and malware protection – organisations can significantly reduce cyber […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP