← Glossary

Frameworks & Standards

ISO/IEC 27001

Also: ISO 27001 · ISO27001 · ISO/IEC 27001:2022 · ISMS · Annex A · Statement of Applicability

Last reviewed:

In one sentence

ISO/IEC 27001 is the international standard for running an information security management system (ISMS) — a certifiable, risk-driven way of deciding which security controls you need and proving you operate them.

Why it matters

ISO 27001 is the certificate customers ask for. A procurement questionnaire that says "ISO 27001 certified? Y/N" is deciding whether to trust your security programme on the strength of an independent audit, and for many B2B deals the answer gates the contract.

For the security team it is something more useful than a badge: a forcing function. The standard does not tell you which controls to run — it tells you to assess risk, choose controls that treat those risks, write down why you excluded the rest, and then produce evidence that the chosen controls actually operate. Regulations that do prescribe controls — DORA, NIS2 — are far easier to meet on top of an ISMS that already exists.

How it is structured

The standard has two halves. Clauses 4–10 are the management system: context and scope (4), leadership (5), planning and risk assessment (6), support (7), operation (8), performance evaluation (9) and improvement (10). These are mandatory and cannot be excluded — an auditor checks that the cycle runs, not just that documents exist.

Annex A is the control catalogue. The 2022 revision reorganised it into 93 controls in four themes: Organizational (37), People (8), Physical (14) and Technological (34) — down from 114 controls in 14 domains in the 2013 edition, with eleven genuinely new ones (threat intelligence, cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities, web filtering, secure coding, configuration management, information deletion, physical security monitoring). ISO/IEC 27002 is the companion document that explains how to implement each control.

The bridge between the two halves is the Statement of Applicability (SoA): one row per Annex A control stating whether it applies, why (a risk, a legal obligation, a contract) and whether it is implemented. Every control you exclude needs a justification. It is the first document an auditor reads and the one most organisations get wrong by treating it as a checklist instead of the output of the risk assessment.

Certification is a three-year cycle: a stage 1 (documentation) and stage 2 (operation) audit, then annual surveillance audits, then recertification. Organisations certified against 2013 had until 31 October 2025 to transition to 2022.

Try it yourself hands-on

You are a 40-person SaaS company preparing for a first certification and need a defensible SoA, not a copied template.

  1. Open the ISO 27001 SoA Builder. It lists all 93 Annex A:2022 controls by theme. For each, mark applicability, implementation status, a justification and an owner.
  2. Take control A.7.4 Physical security monitoring. You are fully remote with no office: mark it Not applicable with the justification "No premises operated; all infrastructure is cloud-hosted under A.5.23". That sentence is what the auditor wants to see — an exclusion tied to a fact and to the control that covers the residual risk.
  3. Take A.8.28 Secure coding. Applicable, Partially implemented: "Linting and dependency scanning in CI; no secure-coding training yet — planned Q1". A partial with a plan is honest and passes; a false "implemented" fails at stage 2 when the auditor asks for the training records.
  4. Tick "Keep my progress in this browser" so the work survives a reload, and export the SoA when you are done. The export is the table you hand to the auditor.
  5. Already mapped to another framework? The Control Mapper cross-references NIST CSF 2.0 functions to ISO 27001 controls and DORA articles, so a control you evidence once can be cited three times.

Common misreadings

  • "Certified" has a scope. A certificate may cover one data centre or one product line. Ask for the scope statement, not just the certificate number.
  • Annex A is not a to-do list. Applying all 93 controls without a risk assessment is a common stage-1 finding: the auditor cannot see why you chose them.
  • 27001 ≠ 27002. You certify against 27001; 27002 is guidance and is not certifiable.