Difference Between ISO 27001 and IASME Cyber Assurance

 TL;DR: ISO 27001 and IASME Cyber Assurance are both robust frameworks for protecting data, but they suit organisations differently. ISO 27001 is an internationally recognised standard with up to 93 controls and annual audits; IASME Cyber Assurance is a UK-focused, often lower-cost route with 65 requirements, tailored guidance for organisations under 50 people, and an external audit every three years. This article compares the two across recognition, controls, cost, audits and prerequisites to help you choose the right standard.

Introduction

With cyber security threats constantly evolving, having measures to protect data is essential. Organisations often choose to implement IASME Cyber Assurance for comprehensive cyber resilience. Organisations also choose ISO 27001 as an effective way to protect data and apply an Information Security Management System (ISMS). So what are the differences between ISO 27001 and IASME Cyber Assurance, and why does that matter? In this article, we explore these differences to help organisations gain more clarity and support decision-making. 

IASME Cyber Assurance Version 7 

The latest version of IASME Cyber Assurance is aimed at making organisations more cyber resilient and references 65 security-related requirements. These requirements can be applied to organisations of all sizes, with specific tailored guidance for organisations with less than 50 people. There are two levels for the IASME Cyber Assurance scheme, with Level One being a verified self-assessment and Level Two being an audit. Successful applicants are awarded a 12-month certificate, with the Level Two audit being required every three years. Cyber Essentials is a valid prerequisite for IASME Cyber Assurance.  

ISO 27001:2022 

ISO 27001 is an international standard for information security management. It provides a framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). The aim is to protect data and ensure confidentiality, integrity, and availability. The ISMS references the applicability of ISO 27002 in Annex A, which includes ninety-three controls, categorised into people, organisational, physical and technical controls. This standard can also be applied to organisations of all sizes. 

Specific Controls and Themes 

IASME Cyber Assurance has up to 14 themes and 65 security controls – it’s aimed at helping organisations be cyber resilient: 

     

      1. Planning  

      1. Organisation  

      1. Assets 

      1. Legal and Regulatory  

      1. Risk 

      1. Physical and Environmental  

      1. People  

      1. Policy  

      1. Managing Access 

      1. Technical Intrusion  

      1. Change Management 

      1. Secure Operations 

      1. Backup and Restore 

      1. Resilience: Business Continuity, Incident Management, and Disaster Recovery 

    ISO 27001 is a structured framework of policies, procedures, and controls to manage information security risk – it contains ten clauses, of which six are mandatory (clauses 4 through 10): 

       

        1. Scope  

        1. Normative References  

        1. Terms and Definitions  

        1. Context of the Organisation  

        1. Leadership  

        1. Planning  

        1. Support 

        1. Operation  

        1. Performance Evaluation  

        1. Improvement  

      ISO 27001 refers to Annex A, which contains 93 security controls grouped into 4 themes: 

         

          • Organisational (37 requirements) 

          • People (8 requirements)  

          • Physical (14 requirements) 

          • Technological (34 requirements) 

        The diagram shows IASME Cyber Assurance and ISO 27001:2022, with key references to the number of requirements / controls and reference to Information Security Management System (ISMS)

        The diagram shows IASME Cyber Assurance and ISO 27001:2022, with key references to the number of requirements/controls and reference to Information Security Management System (ISMS) 

        Key Differences 

           

            1. Recognition: ISO 27001 is an internationally recognised standard, whereas IASME Cyber Assurance is predominantly UK-based

            1. Controls (Measures): ISO 27001 has 10 clauses and up to 93 security controls, whereas IASME Cyber Assurance has 14 themes and up to 65 requirements

            1. Audits and Certification Cycle: ISO 27001 requires internal and external audits annually, whereas only IASME Cyber Assurance (Level Two) requires an external audit every three years 

            1. Cost: Based on audit requirements alone, the cost of IASME Cyber Assurance can be a lot less than ISO 27001

            1. Prerequisites: There are no prerequisites for ISO27001, whereas IASME Cyber Assurance has Cyber Essentials (Level One) as a prerequisite  

            1. Control Governance: ISO 27001 has a heavy focus on a risk-based approach for the implementation of security controls, whereas IASME Cyber Assurance can be considered as being more prescriptive (with mandatory requirements)

            1. Time to Achieve Certification: Typically, it can be quicker to achieve IASME Cyber Assurance than ISO 27001, based on the reduced requirement for testing and auditing alone

            1. Organisational size: IASME Cyber Assurance has specific (tailored) requirements for organisations of less than 50 people, whereas ISO 27001 does not

          Mapping Exercise between IASME Cyber Assurance and ISO 27001 

          IASME carried out a mapping exercise in 2022 to guide how IASME Cyber Assurance maps to ISO 27001 – the results of the mapping show: 

          “IASME Cyber Assurance covers all the ISO 27001 requirements at an achieved or partially achieved level. IASME Cyber Assurance covers almost all the ISO 27001 controls explicitly or implicitly. Only 7 controls are not covered by any significant relationship with the IASME Cyber Assurance requirements – these largely relate to software development activities.” 

          The source document with full details can be downloaded from here

          Where to Start 

             

              • ISO 27001 and IASME Cyber Assurance are both comprehensive  

              • Both can suit organisations in different ways 

              • Where to start can depend upon organisational size, security posture, IT setup and complexity 

            If you are also weighing up the certifications themselves, see our guide to the difference between Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance

            How RB Consultancy Ltd Help 

               

                • Holding CISSP and ISO 27001 lead implementer certification, we provide Consultancy for organisations to implement IASME Cyber Assurance and ISO 27001 (ISMS) 

                • As an IASME Assessor and Certification Body, we assess and certify organisations for Cyber Essentials, Cyber Essentials Plus, and IASME Cyber Assurance 

              Conclusion – key differences between ISO 27001 and Cyber Assurance  

              Both ISO 27001 and IASME Cyber Assurance offer robust frameworks for managing information security. While ISO 27001 is internationally recognised and comprehensive, IASME Cyber Assurance provides a more tailored approach for smaller organisations. Understanding the key differences, including cost, audit requirements, and control governance, can help organisations make informed decisions about which standard best suits their needs. Engaging with experts like RB Consultancy Ltd can further streamline the implementation and certification processes. 

              Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional and cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.

              Other articles you might find useful.

              Cyber Security Consultancy: Incident Response

              Cyber Security Consultancy: Incident Response

              Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

              Read More »
              Benefits of Cyber Essentials Plus

              Benefits of Cyber Essentials Plus

              Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

              Read More »
              Cyber Security Consultancy: Change Management

              Cyber Security Consultancy: Change Management

              Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

              Read More »
              Cyber Security Consultancy: Physical and Environmental Protection

              Cyber Security Consultancy: Physical and Environmental Protection

              Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

              Read More »
              Cyber Security Risk Management: Supply Chain Security & Building Resilience

              Cyber Security Risk Management: Supply Chain Security & Building Resilience

              Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

              Read More »
              Get started today

              Ready to get certified and
              reduce your cyber risk?

              Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

              About RB Consultancy Ltd

              Remo Belisari

              Founder & Managing Director, RB Consultancy Ltd

              Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

              Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

              Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

              Personal Qualifications

              Company Accreditations

              Remo Belisari, founder of RB Consultancy
              NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
              RB Consultancy shield logo blue

              RB Consultancy Ltd

              Pioneer House, Pioneer Business Park,
              North Road, Ellesmere Port, Cheshire,
              CH65 1AD

              NCSC Assured Service Provider
              IASME Certification Body
              Chartered (ChCSP) · CISSP · ISSAP