Fundamentals

What Is ISO 27001?

Updated

ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). This guide explains the mandatory clauses, the 93 Annex A controls in the 2022 edition, how certification works, and how engineers keep an ISMS running with automation.

Key Takeaways

  • ISO/IEC 27001 specifies requirements for an information security management system (ISMS): a risk-driven way to manage information security that improves over time.
  • The certifiable requirements live in clauses 4 through 10. Annex A provides a reference set of 93 controls in four themes.
  • Controls are selected through risk assessment and documented in a Statement of Applicability, so no organization implements Annex A blindly.
  • The 2022 edition is the only valid edition for certification. The 2013 transition period ended October 31, 2025.
  • Certification is issued by an accredited certification body for a three-year cycle, with surveillance audits in between.

What is an ISMS, and who needs ISO 27001?

An information security management system is the set of policies, processes, roles, and controls an organization uses to manage information security risk. The word "management" matters: ISO 27001 certifies that the organization has a working system for deciding what to protect, how, and how it will know when something slips. It does not certify a product or guarantee that a breach cannot happen.

Organizations pursue ISO 27001 when customers, partners, or regulators ask for an internationally recognized proof of security. It is especially common for companies selling into Europe, Asia, and the Middle East, for technology and outsourcing providers, and for any business that wants one framework that can be mapped to others.

The current edition is ISO/IEC 27001:2022. Amendment 1, published in 2024, added a requirement to determine whether climate change is a relevant issue (clause 4.1) and a note that interested parties can have climate-related requirements (clause 4.2).

What are the ISO 27001 requirements?

Clauses 0 to 3 are introduction, scope, references, and definitions. The auditable requirements are clauses 4 through 10, which follow the same high-level structure used by other ISO management system standards such as ISO 9001.

ClauseTitleWhat it requires
4Context of the organizationInternal and external issues, interested parties, and the scope of the ISMS.
5LeadershipTop management commitment, the information security policy, and assigned roles.
6PlanningRisk assessment, risk treatment, the Statement of Applicability, and security objectives.
7SupportResources, competence, awareness, communication, and documented information.
8OperationRunning the planned processes, including risk assessments and risk treatment.
9Performance evaluationMonitoring and measurement, internal audit, and management review.
10ImprovementContinual improvement, nonconformities, and corrective action.

What are the ISO 27001 Annex A controls?

Annex A is a reference list of 93 information security controls. The 2022 edition reorganized the older 14 domains into four themes and introduced new controls covering topics such as threat intelligence, cloud services, data masking, and secure coding.

ThemeControlsExamples
Organizational (5.1 to 5.37)37Policies, asset inventory, access control, supplier relationships, incident management, threat intelligence
People (6.1 to 6.8)8Screening, terms of employment, awareness training, remote working
Physical (7.1 to 7.14)14Perimeters, entry controls, equipment protection, secure disposal
Technological (8.1 to 8.34)34Endpoint devices, privileged access, logging, configuration management, secure coding

Annex A is not a checklist to implement in full. After the risk assessment, the organization records which controls apply, why, and whether they are implemented in a Statement of Applicability (SoA). Auditors test the SoA against the risk treatment plan and the evidence. For more on how controls work in general, see what is a security control.

How does ISO 27001 certification work?

  • Build the ISMS: Define scope, run a risk assessment, select controls, write the SoA, and operate the processes long enough to generate records.
  • Internal audit and management review: Clause 9 requires both, and certification auditors expect completed records of each before issuing a certificate.
  • Stage 1 audit: An accredited certification body reviews documentation and readiness.
  • Stage 2 audit: The auditor tests whether the ISMS and selected controls operate as documented. Major nonconformities must be corrected before a certificate is issued.
  • Surveillance and recertification: The certificate covers a three-year cycle, with surveillance audits in the intervening years and a recertification audit at the end.

How GRC engineers automate ISO 27001

The management system side of ISO 27001 (risk assessment, reviews, improvement) runs on records, and the technological controls run on configuration. Both can be generated by systems instead of assembled by hand:

  • 8.9 Configuration management: Baselines defined in Terraform, with AWS Config or Azure Policy detecting drift and recording every change for the audit trail.
  • 8.15 Logging and 8.16 Monitoring: A scheduled check confirms CloudTrail or equivalent audit logging is enabled in every account and that alerts route to an owned channel.
  • 5.9 Asset inventory: Cloud asset APIs or tools like CloudQuery and Steampipe produce a current inventory instead of a stale spreadsheet.
  • 8.28 Secure coding and 8.32 Change management: CI pipelines run static analysis and require reviewed pull requests, and the repository history becomes the evidence.
  • SoA and risk register as data: Keeping the Statement of Applicability and risk register in version control, or as OSCAL, gives every change an author, a timestamp, and a review.

Go deeper with ISO 27001 automation, what is a risk register, and compliance as code.

Frequently Asked Questions

What is ISO 27001 in simple terms?

ISO/IEC 27001 is an international standard that defines the requirements for an information security management system (ISMS). It tells an organization how to identify its information security risks, choose controls to treat them, and keep improving. Organizations can be certified against it by an accredited certification body.

How many controls are in ISO 27001:2022?

Annex A of ISO/IEC 27001:2022 lists 93 controls grouped into four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Organizations are not required to implement all of them. They select controls based on their risk assessment and justify each inclusion or exclusion in a Statement of Applicability.

Is ISO 27001:2013 still valid?

No. The transition period for moving from the 2013 edition to the 2022 edition ended on October 31, 2025. Certificates issued against ISO/IEC 27001:2013 are no longer valid, and certification audits are performed against the 2022 edition.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international certification of a management system, issued by an accredited certification body against a fixed set of requirements. SOC 2 is a U.S. attestation report from a CPA firm that describes a specific system and tests its controls against the AICPA Trust Services Criteria. Many companies hold both and map one control set to each.

How long is an ISO 27001 certificate valid?

An ISO 27001 certificate runs on a three-year cycle. The certification body performs surveillance audits in the years between the initial certification and the recertification audit to confirm the ISMS is still operating.

What is ISO 27002?

ISO/IEC 27002 is a companion guidance document that explains each Annex A control in more detail, including purpose and implementation guidance. Organizations certify against ISO 27001, and use ISO 27002 to help implement the controls.

Run an ISMS with Code, Not Spreadsheets

The GRC Engineering Club teaches you to automate control evidence, drift detection, and risk tracking in hands-on cloud labs, with a community of practitioners doing the same work. Membership is $70 a year.