What is an ISMS, and who needs ISO 27001?
An information security management system is the set of policies, processes, roles, and controls an organization uses to manage information security risk. The word "management" matters: ISO 27001 certifies that the organization has a working system for deciding what to protect, how, and how it will know when something slips. It does not certify a product or guarantee that a breach cannot happen.
Organizations pursue ISO 27001 when customers, partners, or regulators ask for an internationally recognized proof of security. It is especially common for companies selling into Europe, Asia, and the Middle East, for technology and outsourcing providers, and for any business that wants one framework that can be mapped to others.
The current edition is ISO/IEC 27001:2022. Amendment 1, published in 2024, added a requirement to determine whether climate change is a relevant issue (clause 4.1) and a note that interested parties can have climate-related requirements (clause 4.2).
What are the ISO 27001 requirements?
Clauses 0 to 3 are introduction, scope, references, and definitions. The auditable requirements are clauses 4 through 10, which follow the same high-level structure used by other ISO management system standards such as ISO 9001.
| Clause | Title | What it requires |
|---|---|---|
| 4 | Context of the organization | Internal and external issues, interested parties, and the scope of the ISMS. |
| 5 | Leadership | Top management commitment, the information security policy, and assigned roles. |
| 6 | Planning | Risk assessment, risk treatment, the Statement of Applicability, and security objectives. |
| 7 | Support | Resources, competence, awareness, communication, and documented information. |
| 8 | Operation | Running the planned processes, including risk assessments and risk treatment. |
| 9 | Performance evaluation | Monitoring and measurement, internal audit, and management review. |
| 10 | Improvement | Continual improvement, nonconformities, and corrective action. |
What are the ISO 27001 Annex A controls?
Annex A is a reference list of 93 information security controls. The 2022 edition reorganized the older 14 domains into four themes and introduced new controls covering topics such as threat intelligence, cloud services, data masking, and secure coding.
| Theme | Controls | Examples |
|---|---|---|
| Organizational (5.1 to 5.37) | 37 | Policies, asset inventory, access control, supplier relationships, incident management, threat intelligence |
| People (6.1 to 6.8) | 8 | Screening, terms of employment, awareness training, remote working |
| Physical (7.1 to 7.14) | 14 | Perimeters, entry controls, equipment protection, secure disposal |
| Technological (8.1 to 8.34) | 34 | Endpoint devices, privileged access, logging, configuration management, secure coding |
Annex A is not a checklist to implement in full. After the risk assessment, the organization records which controls apply, why, and whether they are implemented in a Statement of Applicability (SoA). Auditors test the SoA against the risk treatment plan and the evidence. For more on how controls work in general, see what is a security control.
How does ISO 27001 certification work?
- Build the ISMS: Define scope, run a risk assessment, select controls, write the SoA, and operate the processes long enough to generate records.
- Internal audit and management review: Clause 9 requires both, and certification auditors expect completed records of each before issuing a certificate.
- Stage 1 audit: An accredited certification body reviews documentation and readiness.
- Stage 2 audit: The auditor tests whether the ISMS and selected controls operate as documented. Major nonconformities must be corrected before a certificate is issued.
- Surveillance and recertification: The certificate covers a three-year cycle, with surveillance audits in the intervening years and a recertification audit at the end.
How GRC engineers automate ISO 27001
The management system side of ISO 27001 (risk assessment, reviews, improvement) runs on records, and the technological controls run on configuration. Both can be generated by systems instead of assembled by hand:
- 8.9 Configuration management: Baselines defined in Terraform, with AWS Config or Azure Policy detecting drift and recording every change for the audit trail.
- 8.15 Logging and 8.16 Monitoring: A scheduled check confirms CloudTrail or equivalent audit logging is enabled in every account and that alerts route to an owned channel.
- 5.9 Asset inventory: Cloud asset APIs or tools like CloudQuery and Steampipe produce a current inventory instead of a stale spreadsheet.
- 8.28 Secure coding and 8.32 Change management: CI pipelines run static analysis and require reviewed pull requests, and the repository history becomes the evidence.
- SoA and risk register as data: Keeping the Statement of Applicability and risk register in version control, or as OSCAL, gives every change an author, a timestamp, and a review.
Go deeper with ISO 27001 automation, what is a risk register, and compliance as code.
Frequently Asked Questions
What is ISO 27001 in simple terms?
ISO/IEC 27001 is an international standard that defines the requirements for an information security management system (ISMS). It tells an organization how to identify its information security risks, choose controls to treat them, and keep improving. Organizations can be certified against it by an accredited certification body.
How many controls are in ISO 27001:2022?
Annex A of ISO/IEC 27001:2022 lists 93 controls grouped into four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Organizations are not required to implement all of them. They select controls based on their risk assessment and justify each inclusion or exclusion in a Statement of Applicability.
Is ISO 27001:2013 still valid?
No. The transition period for moving from the 2013 edition to the 2022 edition ended on October 31, 2025. Certificates issued against ISO/IEC 27001:2013 are no longer valid, and certification audits are performed against the 2022 edition.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international certification of a management system, issued by an accredited certification body against a fixed set of requirements. SOC 2 is a U.S. attestation report from a CPA firm that describes a specific system and tests its controls against the AICPA Trust Services Criteria. Many companies hold both and map one control set to each.
How long is an ISO 27001 certificate valid?
An ISO 27001 certificate runs on a three-year cycle. The certification body performs surveillance audits in the years between the initial certification and the recertification audit to confirm the ISMS is still operating.
What is ISO 27002?
ISO/IEC 27002 is a companion guidance document that explains each Annex A control in more detail, including purpose and implementation guidance. Organizations certify against ISO 27001, and use ISO 27002 to help implement the controls.