ISO 27001 is an international standard for managing information security. Its full name is ISO/IEC 27001, and it gives organizations a structured way to identify security risks, apply appropriate controls, document responsibilities, and keep improving how sensitive information is protected.
Unlike a checklist focused on a single technology or department, ISO 27001 is built around an Information Security Management System, or ISMS. The ISMS connects risk management, policies, people, technology, physical security, internal audits, and management oversight into one ongoing program.
The current base standard is ISO/IEC 27001:2022, with a 2024 amendment addressing climate-related considerations in the organizational context.
In This Guide
- 01What Is ISO 27001 and How Does It Work?
- 02Why Is ISO 27001 Important?
- 03Who Can Use ISO 27001?
- 04What Are the Main ISO 27001 Requirements?
- 05What Are the ISO 27001 Annex A Controls?
- 06What Is the ISO 27001 Statement of Applicability?
- 07What Is the Current Version of ISO 27001?
- 08What Does ISO 27001 Certification Mean?
- 09How Do You Get ISO 27001 Certified?
- 10What Is the Difference Between Stage 1 and Stage 2 ISO 27001 Audits?
- 11How Long Does ISO 27001 Certification Last?
- 12What Is the Difference Between ISO 27001 and ISO 27002?
- 13How Does ISO 27001 Compare With SOC 2?
- 14How Nexeris Helps Organizations Prepare for ISO 27001 Certification
- 15FAQs
What Is ISO 27001 and How Does It Work?
ISO 27001 sets requirements for establishing, implementing, maintaining, and continually improving an ISMS.
The organization first defines what parts of the business fall within the ISMS scope. It then identifies information security risks, decides how those risks will be treated, implements suitable controls, measures performance, conducts internal reviews, and corrects weaknesses.
The standard is risk-based. It does not expect every organization to use the same tools or controls. Instead, companies are expected to understand their own risks and make informed decisions about how those risks should be managed.
What Is an Information Security Management System?
An Information Security Management System is the set of policies, processes, controls, responsibilities, and records an organization uses to manage information security.
An ISMS may cover areas such as:
- Risk management
- Access control
- Employee security responsibilities
- Vendor management
- Incident handling
- Business continuity
- Asset management
- Physical security
- Security monitoring
- Internal audits
The purpose is to make information security part of normal business management rather than treating it as a separate IT project.
What Are Confidentiality, Integrity, and Availability?
ISO 27001 is closely tied to three basic information security goals:
Confidentiality means information is only available to people or systems that are authorized to access it.
Integrity means information remains accurate, complete, and protected against improper changes.
Availability means authorized users can access information and systems when they need them.
Together, these three principles are often called the CIA triad.
Why Is ISO 27001 Important?
Organizations rely on information for almost every part of their operations. Customer records, employee information, intellectual property, financial data, credentials, and business systems can all create risk if they are lost, altered, exposed, or unavailable.
ISO 27001 gives organizations a consistent way to manage those risks.
How Does ISO 27001 Help Manage Information Security Risk?
The standard requires organizations to identify information security risks, evaluate their significance, and decide how those risks will be treated.
That means security decisions should be connected to actual business risks rather than made randomly.
The organization also needs to review whether controls are working and respond when risks, systems, business priorities, or threats change.
What Are the Business Benefits of ISO 27001 Certification?
Certification can help an organization show customers and business partners that its information security management system has been independently assessed.
Potential benefits include:
- Stronger risk management
- Better-defined security responsibilities
- More consistent policies and procedures
- Improved customer confidence
- Easier responses to security questionnaires
- Better control over vendor risks
- Stronger evidence during procurement reviews
ISO notes that certification can provide additional confidence to stakeholders by showing that an organization is able to manage information securely.
Who Can Use ISO 27001?
ISO 27001 is designed to be used by organizations of different sizes, industries, and locations.
Is ISO 27001 Only for Technology Companies?
No.
Technology companies commonly use ISO 27001 because they handle large amounts of data, but the standard is not limited to software or IT businesses.
It can also be used by organizations in healthcare, finance, manufacturing, professional services, education, government, logistics, and other industries.
ISO reports that ISO/IEC 27001 certification is used across many economic sectors around the world.
Is ISO 27001 Mandatory?
ISO 27001 is generally voluntary.
An organization can choose to implement the standard without becoming certified. However, customers, contracts, tenders, regulators, or supply-chain requirements may make certification commercially important in some situations.
What Are the Main ISO 27001 Requirements?
The main requirements appear in Clauses 4 through 10 of ISO/IEC 27001.
Clauses 4–5: Organizational Context and Leadership
Clause 4 requires an organization to understand its business context, interested parties, relevant requirements, and ISMS scope.
Clause 5 focuses on leadership.
Senior management is expected to support the ISMS, establish an information security policy, assign responsibilities, and make sure information security is connected to business priorities.
Clauses 6–8: Planning, Support, and Operation
These clauses cover much of the day-to-day work involved in running an ISMS.
Organizations need to assess risks, plan risk treatment, define security objectives, provide suitable resources, maintain competence and awareness, control documentation, and operate the processes needed to manage information security risks.
Clauses 9–10: Performance Evaluation and Improvement
ISO 27001 also requires organizations to check whether the ISMS is working.
This includes monitoring performance, conducting internal audits, carrying out management reviews, addressing nonconformities, and continually improving the system.
What Are the ISO 27001 Annex A Controls?
Annex A contains a reference set of information security controls that organizations consider during risk treatment.
ISO/IEC 27001:2022 contains 93 Annex A controls, organized into four themes.
Organizational Controls
Organizational controls cover areas such as security policies, roles, asset management, identity management, access control, access rights, supplier relationships, incident management, business continuity, compliance, and governance.
People Controls
People controls deal with security responsibilities connected to employees and other personnel.
They include areas such as screening, employment terms, awareness, training, disciplinary processes, remote working, and reporting security events.
Physical Controls
Physical controls protect facilities, equipment, workspaces, and physical information assets.
Examples include secure areas, entry controls, equipment protection, clear desk practices, storage media, and secure disposal.
Technological Controls
Technological controls address technical security measures.
These include privileged access rights, information access restriction, secure authentication, malware protection, backups, logging, network security, encryption, secure development, vulnerability management, and configuration management.
Are All 93 Annex A Controls Mandatory?
No.
Organizations are expected to consider all 93 controls, but that does not mean every control must be implemented.
Which controls apply depends on the organization’s risks, obligations, business environment, and chosen risk treatments.
Controls that are not applicable should have a clear reason for exclusion.
What Is the ISO 27001 Statement of Applicability?
The Statement of Applicability, often called the SoA, is one of the most important documents in an ISO 27001 ISMS.
It records which Annex A controls are applicable, whether they have been implemented, and why controls have been included or excluded.
How Does the Statement of Applicability Support Risk Treatment?
The Statement of Applicability connects the organization’s risk treatment decisions to the controls selected to address those risks.
It gives auditors a clear view of which controls the organization considers relevant and how those decisions were made.
How Does an Organization Decide Which Controls Apply?
Control selection should be based on factors such as:
- Risk assessment results
- Legal obligations
- Customer requirements
- Contracts
- Industry expectations
- Business needs
- Existing security measures
The decision should come from risk treatment, not from applying Annex A as a generic checklist.
What Is the Current Version of ISO 27001?
The current base edition is ISO/IEC 27001:2022, published in October 2022.
What Changed in ISO/IEC 27001:2022?
The 2022 edition aligned the standard with the updated ISO/IEC 27002 control structure.
One of the most visible changes was the restructuring of Annex A from the previous control arrangement into 93 controls across four themes: organizational, people, physical, and technological.
The update also modernized the standard to better reflect current cybersecurity and information security practices.
What Is ISO/IEC 27001:2022 Amendment 1:2024?
In February 2024, ISO published ISO/IEC 27001:2022/Amd 1:2024, titled Climate action changes.
The amendment requires organizations to determine whether climate change is a relevant issue in their organizational context and adds a note that interested parties can have climate-related requirements.
It does not replace ISO/IEC 27001:2022. It amends the existing standard.
What Does ISO 27001 Certification Mean?
Certification means an independent certification body has assessed the organization’s ISMS against ISO/IEC 27001 requirements and determined that it meets the certification criteria.
What Is the Difference Between ISO 27001 Compliance and Certification?
An organization can implement ISO 27001 requirements internally and consider itself aligned with or compliant with the standard without going through certification.
Certification adds independent third-party review.
That external assessment gives customers and other stakeholders more assurance than a self-declaration alone.
Who Can Issue an ISO 27001 Certificate?
ISO 27001 certificates are issued by independent certification bodies.
Using an accredited certification body can provide additional confidence because the certification body’s competence has itself been independently assessed.
Does ISO Issue Certificates Directly?
No.
ISO develops and publishes standards but does not perform certification or issue certificates. Certification is carried out by independent certification bodies.
How Do You Get ISO 27001 Certified?
Certification normally involves preparation, implementation, internal review, and an independent two-stage certification audit.
Step 1: Define the ISMS Scope and Conduct a Gap Analysis
Start by deciding which locations, systems, services, departments, and information assets are included in the ISMS.
Then compare current practices with ISO 27001 requirements to identify gaps.
Step 2: Perform a Risk Assessment and Create a Risk Treatment Plan
Identify information security threats, vulnerabilities, existing controls, likelihood, and business impact.
A formal risk assessment provides the foundation for deciding which risks need treatment.
The organization should then create a risk treatment plan showing how unacceptable risks will be addressed.
Step 3: Develop Policies and Implement Applicable Controls
Create the policies, procedures, and controls needed to support the ISMS.
Controls should reflect the organization’s actual risks and operating environment rather than being copied from a generic template.
Step 4: Conduct the Internal Audit and Management Review
Before certification, the organization should conduct an internal audit to evaluate whether the ISMS meets ISO 27001 requirements.
Leadership must also perform a management review to assess ISMS performance and decide whether improvements are needed.
Step 5: Complete the Stage 1 Certification Audit
The certification body first reviews whether the organization appears ready for the full assessment.
The auditor typically reviews areas such as ISMS scope, documented processes, risk assessment, Statement of Applicability, and internal audit activity.
Step 6: Complete the Stage 2 Certification Audit
Stage 2 is the main certification assessment.
The auditor looks more closely at how the ISMS operates and whether policies, controls, processes, and records meet ISO 27001 requirements.
Step 7: Address Nonconformities and Receive Certification
If the auditor identifies nonconformities, the organization may need to provide corrective actions and evidence before certification can be completed.
Organizations that need help preparing their ISMS can use professional ISO implementation support to organize the work before certification.
What Is the Difference Between Stage 1 and Stage 2 ISO 27001 Audits?
The two stages serve different purposes.
What Happens During the Stage 1 Audit?
Stage 1 focuses mainly on readiness.
The auditor reviews whether the ISMS has been established and whether the organization appears prepared for the more detailed Stage 2 assessment.
What Happens During the Stage 2 Audit?
Stage 2 tests the implementation and effectiveness of the ISMS in greater depth.
The auditor reviews evidence, interviews personnel, examines processes, and confirms whether the system operates as documented.
What Happens If an Auditor Finds a Nonconformity?
A nonconformity means part of the ISMS does not meet a requirement.
The organization normally needs to identify the cause, correct the issue, and provide evidence of corrective action.
Major nonconformities must be corrected, and the correction verified by the auditor, before certification is granted. Minor nonconformities usually need an accepted corrective action plan.
How Long Does ISO 27001 Certification Last?
ISO 27001 certification is generally managed through a three-year certification cycle, with surveillance activity between initial certification and recertification.
What Are Surveillance Audits?
Surveillance audits are periodic audits carried out during the certification cycle.
They do not usually repeat every part of the original certification audit. Instead, they review selected areas to confirm the ISMS continues to operate and improve.
What Happens During Recertification?
Near the end of the certification cycle, the certification body conducts a recertification audit.
The purpose is to confirm that the ISMS still meets the standard and remains effective before a new certification cycle begins.
How Do Organizations Maintain ISO 27001 Between Audits?
Organizations should continue:
- Reviewing risks
- Updating the Statement of Applicability
- Monitoring security performance
- Managing incidents
- Reviewing suppliers
- Conducting internal audits
- Completing management reviews
- Correcting nonconformities
- Updating policies and controls
Certification only remains meaningful when the ISMS continues to operate between audits.
What Is the Difference Between ISO 27001 and ISO 27002?
ISO 27001 and ISO 27002 work together, but they serve different purposes.
Which Standard Contains the Certification Requirements?
ISO/IEC 27001 contains the requirements used for ISMS certification.
An organization seeking formal certification is audited against ISO 27001.
How Does ISO 27002 Support ISO 27001?
ISO/IEC 27002 provides more detailed guidance on information security controls.
It helps organizations understand and implement controls, but it is not the certification standard itself. The current ISO catalogue lists ISO/IEC 27002:2022 as the information security controls standard alongside ISO/IEC 27001:2022.
How Does ISO 27001 Compare With SOC 2?
ISO 27001 and SOC 2 both help organizations demonstrate strong information security practices, but they use different approaches.
ISO 27001 Certification vs. SOC 2 Attestation
ISO 27001 involves certification of an ISMS against an international standard by an independent certification body.
SOC 2 is an attestation examination performed by an independent CPA firm against applicable AICPA Trust Services Criteria.
ISO 27001 produces a certificate. SOC 2 produces an attestation report.
Can an Organization Need Both ISO 27001 and SOC 2?
Yes.
Some organizations pursue both because different customers or markets ask for different assurance.
For example, a company may use ISO 27001 certification to support international customers while also maintaining SOC 2 compliance for customers that expect a detailed SOC 2 report.
There is overlap between the two, so many controls and evidence processes can support both programs.
How Nexeris Helps Organizations Prepare for ISO 27001 Certification
Preparing for ISO 27001 requires more than writing policies. The ISMS needs to reflect how the organization actually operates and manage real information security risks.
ISMS Scoping, Risk Assessment, and Gap Analysis
Nexeris helps organizations define a practical ISMS scope, identify security risks, review current practices, and find gaps against ISO 27001 requirements.
This gives teams a clearer view of what needs to be completed before certification.
Control, Policy, and Documentation Readiness
The certification audit requires evidence that policies and controls are working in practice.
Nexeris helps organizations develop the required documentation, select and implement appropriate controls, and organize evidence that supports the ISMS.
Internal Audit and Certification Preparation
Internal audits and management reviews are important parts of certification readiness.
Nexeris can help organizations prepare for these activities, address weaknesses before the certification audit, and organize the work required for Stage 1 and Stage 2.
Professional ISO 27001 consulting can also help teams build and maintain an ISMS without turning compliance into a disconnected documentation exercise.
FAQs
What Is ISO 27001 in Simple Terms?
ISO 27001 is an international standard that helps organizations manage information security risks through an Information Security Management System.
What Is an ISMS in ISO 27001?
An ISMS is the collection of policies, processes, controls, responsibilities, and records used to manage information security risks across an organization.
How Many Controls Are in ISO 27001:2022?
ISO/IEC 27001:2022 Annex A contains 93 information security controls divided into organizational, people, physical, and technological themes.
Are All 93 ISO 27001 Controls Required?
No. Organizations must consider the Annex A controls, but only those that are applicable to their risks and requirements need to be included in the ISMS. Exclusions should be justified in the Statement of Applicability.
Is ISO 27001 Certification Mandatory?
Generally, no. ISO 27001 certification is voluntary, although a customer, contract, tender, or industry requirement may make it necessary for a particular organization.
Who Can Issue an ISO 27001 Certificate?
Independent certification bodies issue ISO 27001 certificates. ISO itself does not certify organizations.
How Long Does ISO 27001 Certification Last?
ISO 27001 certification generally operates on a three-year certification cycle, with surveillance audits taking place during that period before recertification.
What Is the Difference Between ISO 27001 and ISO 27002?
ISO 27001 contains the requirements for establishing and certifying an ISMS. ISO 27002 provides guidance for selecting and implementing information security controls.
