Internal Policies, Industry Standards and Market Practices
In ISO/IEC 27001 Lead Auditor training, Internal Policies, Industry Standards and Market Practices are three sources of requirements and guidance that shape an Information Security Management System (ISMS). Together with legal and contractual obligations, they help an organization define what it mu… In ISO/IEC 27001 Lead Auditor training, Internal Policies, Industry Standards and Market Practices are three sources of requirements and guidance that shape an Information Security Management System (ISMS). Together with legal and contractual obligations, they help an organization define what it must protect and how. An auditor must understand each source in order to set audit criteria and judge conformity. Internal Policies are rules an organization sets for itself. They include the top-level information security policy required by clause 5.2 of ISO/IEC 27001, which must suit the organization's purpose, include information security objectives or a framework for setting them, and commit to meeting applicable requirements and to continual improvement. Topic-specific policies, such as access control, acceptable use, cryptography and supplier security, support it. Top management approves these policies, communicates them to staff and reviews them at planned intervals. Once adopted, they become binding audit criteria. Auditors check that they are documented, approved, communicated, implemented and effective. Industry Standards are consensus-based documents published by recognized bodies such as ISO, IEC, NIST or sector organizations. ISO/IEC 27001 contains certifiable requirements. ISO/IEC 27002 provides control guidance, ISO/IEC 27005 covers risk management, and ISO 19011 and ISO/IEC 17021-1 govern auditing and certification. Sector standards such as PCI DSS for payment card data may be mandatory through contracts. Standards give a common language, support interoperability and make independent certification possible. Market Practices, also called good or best practices, are widely accepted ways of working that are not formally required. Examples include frameworks such as COBIT, ITIL and the CIS Controls, threat intelligence sharing, and common approaches to secure development or cloud security. They reflect what peers and customers expect and help organizations benchmark their maturity. For a Lead Auditor, the distinction matters. Requirements from ISO/IEC 27001 and adopted internal policies justify nonconformities. Market practices usually support opportunities for improvement, unless the organization has formally adopted them.
Internal Policies, Industry Standards and Market Practices in ISO/IEC 27001 Lead Auditor: A Complete Guide
Introduction
In the ISO/IEC 27001 Lead Auditor syllabus, under the domain Fundamental principles and concepts of an Information Security Management System (ISMS), candidates must understand the sources of requirements and good practices that shape an ISMS. Three of these sources are internal policies, industry standards and market practices. They sit alongside legal, regulatory and contractual requirements. Together they form the reference framework an organization uses to design, operate and improve its ISMS, and an auditor uses to evaluate it.
Why It Is Important
1. Defining audit criteria: ISO 19011 defines audit criteria as the set of requirements used as a reference against which objective evidence is compared. Audit criteria can include policies, procedures, standards, legal requirements, management system requirements, contractual requirements and sector codes of conduct. An auditor who cannot tell these sources apart cannot set the scope and criteria of an audit correctly.
2. Understanding context: Clause 4 of ISO/IEC 27001 requires the organization to understand its context (4.1) and the needs and expectations of interested parties (4.2). Industry norms and market expectations are often part of those external issues and stakeholder requirements.
3. Distinguishing mandatory from voluntary: Laws and regulations are mandatory. Industry standards are generally voluntary unless they are made mandatory by law, contract or certification choice. Market practices are usually non-binding. Internal policies are binding within the organization. Knowing this hierarchy is key to raising valid nonconformities.
4. Credibility and competitiveness: Following recognized standards and market practices builds trust with customers, partners and regulators. It also shows due diligence.
5. Continual improvement: Benchmarking against industry standards and market practices helps organizations find gaps and mature their ISMS.
What It Is
1. Internal Policies
Internal policies are statements of intent and direction formally expressed by top management (ISO/IEC 27000 defines policy as the intentions and direction of an organization as formally expressed by its top management). In an ISMS they include:
- The information security policy required by Clause 5.2 of ISO/IEC 27001. It must be appropriate to the organization's purpose and include information security objectives or a framework for setting them. It must also contain a commitment to satisfy applicable requirements and a commitment to continual improvement. It must be documented, communicated and made available to interested parties as appropriate.
- Topic-specific policies, such as access control, acceptable use, cryptography, backup, supplier relationships and remote working. These are addressed in Annex A control 5.1 (ISO/IEC 27001:2022) and guided by ISO/IEC 27002:2022.
- Internal procedures, codes of conduct, work instructions and organizational rules.
Key characteristics:
- They are set by the organization itself.
- They are binding on personnel and relevant interested parties.
- They must be approved, communicated, acknowledged, reviewed at planned intervals and updated when significant changes occur.
- They form part of the audit criteria. Failure to follow one's own policy can be a nonconformity.
2. Industry Standards
Industry standards are documents established by consensus and approved by a recognized body. They provide rules, guidelines or characteristics for common and repeated use. Examples include:
- International standards: ISO/IEC 27001 (requirements), ISO/IEC 27002 (controls guidance), ISO/IEC 27005 (risk management), ISO/IEC 27017 (cloud security), ISO/IEC 27018 (PII in public clouds), ISO/IEC 27701 (privacy), ISO 22301 (business continuity) and ISO 31000 (risk management).
- Sector-specific standards: PCI DSS (payment card industry), ISO 27799 (health informatics), IEC 62443 (industrial automation), TISAX (automotive) and SWIFT CSP (banking).
- National and other frameworks: NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, COBIT and SOC 2 criteria.
Key characteristics:
- They are developed through consensus and are generally voluntary.
- They become mandatory when adopted through law, regulation, contract or the organization's own choice. For example, PCI DSS is contractually required by card brands, and ISO/IEC 27001 becomes binding once an organization seeks certification.
- They are distinguished as requirement standards (the word 'shall', which is auditable for certification, such as ISO/IEC 27001) and guidance standards (the word 'should', not certifiable, such as ISO/IEC 27002).
3. Market Practices
Market practices are the commonly accepted ways of doing things in a given sector or market. They are often called good practices, best practices or generally accepted practices. They may not be formally documented as standards. They emerge from experience, peer behaviour, customer expectations and industry associations. Examples include:
- Multi-factor authentication for remote access becoming an expectation.
- Regular penetration testing and vulnerability disclosure programs.
- Security questionnaires and third-party risk assessments in procurement.
- Zero trust architectures, encryption by default and secure software development lifecycles.
- Cyber insurance requirements influencing security controls.
Key characteristics:
- They are generally non-binding, but they reflect what stakeholders reasonably expect.
- They evolve quickly, often faster than formal standards.
- They can turn into contractual or regulatory requirements over time.
- They help define what is 'reasonable' or 'state of the art' (for example, GDPR Article 32 refers to the state of the art).
How It Works
Hierarchy and interaction
A useful mental model is a layered set of obligations:
1. Legal and regulatory requirements: mandatory, imposed by authorities.
2. Contractual requirements: mandatory, through agreements with clients, suppliers and partners.
3. Industry standards: voluntary unless adopted, but they provide structured requirements and guidance.
4. Market practices: voluntary, but they shape expectations and reasonableness.
5. Internal policies: the organization's own translation of all the above into binding internal rules.
Internal policies should reflect and integrate applicable legal, contractual, standard-based and market-driven expectations. They must never contradict legal obligations.
In the ISMS lifecycle (PDCA)
- Plan: The organization identifies its context, interested parties and requirements (Clauses 4.1–4.3). It selects relevant standards and practices, defines the information security policy (5.2), performs risk assessment (6.1.2) and compares the controls it has determined with Annex A (6.1.3). Other standards and practices (for example NIST or CIS) may also inform control selection. The Statement of Applicability (SoA) documents the decisions.
- Do: Policies and procedures are implemented, communicated (7.4) and supported by awareness (7.3).
- Check: Internal audits (9.2) and management reviews (9.3) verify conformity with the organization's own requirements and with ISO/IEC 27001. Monitoring checks alignment with evolving market practices.
- Act: Nonconformities lead to corrective actions (10.2). Benchmarking against standards and practices supports continual improvement (10.1).
Role for the auditor
- Establish audit criteria: ISO/IEC 27001 requirements, the organization's own policies and procedures, and applicable legal and contractual requirements. Industry standards like PCI DSS become criteria only if they are in scope or required.
- Verify policy adequacy: Check that the information security policy meets Clause 5.2 and that topic-specific policies exist where needed and are approved, communicated and reviewed.
- Verify implementation: Gather objective evidence (records, interviews, observation) that personnel follow internal policies.
- Avoid auditing against personal opinion: An auditor cannot raise a nonconformity simply because a market practice is not followed. A nonconformity requires non-fulfilment of a requirement. If a gap against good practice exists but no requirement is breached, the auditor may record an opportunity for improvement (where the audit programme allows it). Exception: if the organization's risk assessment shows a risk that is not treated, or if the organization itself adopted that practice in its policy or SoA, a nonconformity may be justified.
- Use ISO/IEC 27002 correctly: It is guidance. Certification is against ISO/IEC 27001, not ISO/IEC 27002.
Practical example
A fintech company's access control policy states that MFA is mandatory for all administrative accounts. During the audit, the auditor samples ten admin accounts and finds two without MFA. This is a nonconformity against the organization's own policy, and therefore against ISO/IEC 27001 Clause 8.1 (operational planning and control), which requires the organization to implement its planned processes and controls. Now consider a second company whose policy does not require MFA, and whose risk assessment justifies alternative controls. The absence of MFA, although contrary to market practice, is not automatically a nonconformity. The auditor may note an opportunity for improvement and check whether the risk assessment is sound.
Exam Tips: Answering Questions on Internal Policies, Industry Standards and Market Practices
1. Know the definitions precisely. Policy means intentions and direction formally expressed by top management. Standard means a consensus-based document approved by a recognized body. Market practice means a commonly accepted, often informal way of operating in a sector.
2. Remember who approves the information security policy. Top management establishes it (Clause 5.2). Answers that say the IT manager or CISO alone establishes it are usually wrong.
3. Distinguish mandatory from voluntary. If a question asks which source is legally binding, choose laws and regulations. Standards are voluntary unless adopted by contract, regulation or the organization's own decision.
4. 'Shall' versus 'should'. ISO/IEC 27001 uses 'shall' (requirements, certifiable). ISO/IEC 27002 uses 'should' (guidance, not certifiable). Questions often test whether an organization can be certified against ISO/IEC 27002. The answer is no.
5. Nonconformity requires a requirement. In scenario questions, a finding is a nonconformity only if objective evidence shows a requirement is not fulfilled. That requirement can come from ISO/IEC 27001, the organization's policies or procedures, or legal and contractual obligations. Not following a best practice the organization never adopted is not a nonconformity. At most it is an opportunity for improvement.
6. Internal policies are audit criteria. If an organization violates its own policy, that is a nonconformity even if the policy is stricter than market practice.
7. Policies must be communicated and reviewed. Look for keywords: documented, communicated within the organization, available to interested parties as appropriate, reviewed at planned intervals or when significant changes occur.
8. Link to context. When a question mentions customer expectations or sector norms, connect it to Clauses 4.1 and 4.2 (context and interested parties).
9. Annex A is not exhaustive. Organizations may use controls from other standards or market practices. They must still compare the controls they determine with Annex A and justify inclusions and exclusions in the SoA.
10. Beware of absolute words. Options with 'always', 'must adopt all best practices' or 'industry standards override internal policies' are usually wrong. Laws override policies. Policies should integrate standards, but standards do not automatically override them.
11. Auditor objectivity. The correct answer usually reflects evidence-based, impartial judgement against defined criteria, not the auditor's personal preference for a framework or practice.
12. For essay or scenario answers, use a structure: identify the criterion (which clause, policy or contract), state the evidence observed, decide whether there is conformity or nonconformity, grade it (major or minor) and justify it, then mention any opportunity for improvement.
13. Major versus minor. A systemic failure to implement a policy, or the absence of a required policy, can be a major nonconformity. An isolated lapse is usually minor.
14. Remember evolving practices. Questions may ask how organizations stay current. Good answers include monitoring industry developments, contact with special interest groups (Annex A 5.6), threat intelligence (Annex A 5.7) and periodic policy reviews.
Summary
Internal policies translate organizational intent into binding rules. Industry standards provide structured, consensus-based requirements and guidance. Market practices reflect evolving stakeholder expectations. An effective ISMS integrates all three with legal and contractual obligations. A competent Lead Auditor evaluates conformity against clearly defined criteria, separating true nonconformities from opportunities for improvement.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!