Enquire Us

What is ISO 27001?

ISO/IEC 27001 is the international standard for an information security management system, published jointly by ISO and IEC. This page explains what the standard requires, how Annex A works, and how certification against it is actually obtained.

Definition and publisher

ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, usually shortened to ISMS. It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) through their joint technical committee.

The current edition is ISO/IEC 27001:2022, the third edition, published in October 2022. It has since been amended by ISO/IEC 27001:2022/Amd 1:2024, Climate action changes, which requires an organisation to consider whether climate change is a relevant issue when it determines its context and the needs and expectations of interested parties.

ISO/IEC 27001 is a management system standard, which means it is about how security is governed and improved, not only about which technical controls are switched on. It is certifiable. Its companion document ISO/IEC 27002 gives implementation guidance for the controls and is not certifiable.

What the standard requires

Clauses 1 to 3 cover scope, normative references and terms. The auditable requirements sit in clauses 4 to 10, which follow the harmonised structure used across ISO management system standards.

  • Clause 4, Context of the organisation. Internal and external issues, interested parties and their requirements, the scope of the ISMS, and the ISMS itself.
  • Clause 5, Leadership. Top management commitment, the information security policy, and assignment of roles, responsibilities and authorities.
  • Clause 6, Planning. Actions to address risks and opportunities, the information security risk assessment and risk treatment processes, the Statement of Applicability, and information security objectives.
  • Clause 7, Support. Resources, competence, awareness, communication and control of documented information.
  • Clause 8, Operation. Operational planning and control, and carrying out the risk assessment and risk treatment in practice.
  • Clause 9, Performance evaluation. Monitoring, measurement, analysis and evaluation, the internal audit programme, and management review.
  • Clause 10, Improvement. Continual improvement, and handling of nonconformities and corrective action.

Annex A and the Statement of Applicability

Annex A of ISO/IEC 27001:2022 lists 93 controls grouped into four themes.

  • Organisational controls, 37 controls, covering policies, roles, supplier relationships, threat intelligence, cloud services, incident management and continuity.
  • People controls, 8 controls, covering screening, terms of employment, awareness and training, disciplinary process and remote working.
  • Physical controls, 14 controls, covering secure areas, equipment, clear desk and clear screen, and physical security monitoring.
  • Technological controls, 34 controls, covering access, cryptography, secure development, logging, monitoring, malware protection and data masking.

Annex A is a reference set. You do not adopt all 93 controls by default. The risk assessment drives the treatment decisions, and the Statement of Applicability records for each control whether it applies, why, and whether it is implemented. Exclusions are permitted provided they are justified and consistent with the risk treatment.

Documented information the standard requires

  • The scope of the information security management system.
  • The information security policy and the information security objectives.
  • The information security risk assessment process and its results.
  • The information security risk treatment process, the risk treatment plan, and the risk owner approval and acceptance of residual risk.
  • The Statement of Applicability.
  • Evidence of competence of the people doing work that affects information security.
  • Results of monitoring and measurement.
  • The internal audit programme and the audit results.
  • Evidence of the results of management reviews.
  • Evidence of nonconformities, the actions taken and the results of corrective action.

Beyond this list, the standard expects whatever documented information the organisation itself determines is necessary for the ISMS to be effective, which is where operational procedures and records sit.

How ISO 27001 certification is obtained

ISO does not certify organisations and does not issue certificates. Certification is carried out by an independent certification body. Where that body is accredited, it is assessed by a national accreditation body against ISO/IEC 17021-1 and the ISMS specific requirements in ISO/IEC 27006-1:2024. Accredited certificates can be verified through IAF CertSearch, the database of the International Accreditation Forum.

The audit itself is carried out in two stages.

  1. Stage 1. A readiness and documentation review. The auditor checks the scope, the risk assessment, the Statement of Applicability, the internal audit and management review records, and confirms whether the organisation is ready for Stage 2.
  2. Stage 2. An audit of implementation and effectiveness. The auditor samples evidence across the scope to test whether the ISMS and the applicable Annex A controls are actually operating.

Where nonconformities are raised, they must be addressed before a certificate is issued. The certificate is valid for three years, subject to surveillance audits during the cycle and a recertification audit before expiry.

Who needs ISO 27001

ISO/IEC 27001 is voluntary as a matter of law in most markets, but it is frequently made contractual. Organisations most often pursue it because a customer, a tender process or a group parent requires it. Common cases include software and cloud providers whose enterprise customers require evidence of security governance, business process outsourcing and IT services firms handling client data, financial services and fintech firms, healthcare and health technology providers, and suppliers bidding for public sector work where an accredited certificate is a qualification criterion.

It is also used as the structural backbone for meeting data protection obligations, because the risk assessment, access control, supplier management and incident response processes that the standard requires are the same processes most privacy laws expect an organisation to be able to demonstrate.

How Univate supports ISO 27001

Univate works through the full ISMS lifecycle: defining a scope that is defensible rather than convenient, running the risk assessment and risk treatment, building the Statement of Applicability against the 93 Annex A controls, writing the documented information the standard requires, implementing the control set with your technical teams, running internal audits and management review, and supporting you through Stage 1 and Stage 2 with the certification body you appoint.

We do not issue certificates. Certification bodies do that, and keeping consultancy separate from certification is a requirement of the accreditation rules those bodies work under. Where an organisation also needs a SOC 2 report, we map the Trust Services Criteria onto the same control environment so one set of evidence supports both.

ISO 27001 questions we are asked most often

Which edition of ISO 27001 is current?

The current edition is ISO/IEC 27001:2022, the third edition, published in October 2022. It was amended by ISO/IEC 27001:2022/Amd 1:2024, Climate action changes, which adds a requirement to consider whether climate change is a relevant issue when determining the context of the organisation and the needs of interested parties.

How many controls are in Annex A of ISO 27001:2022?

Annex A lists 93 controls arranged in four themes: organisational controls, people controls, physical controls and technological controls. Annex A is a reference set, not a checklist that must be adopted in full. The Statement of Applicability records which controls apply, the justification for including them, whether they are implemented, and the justification for excluding any that do not apply.

Does ISO issue ISO 27001 certificates?

No. ISO states that it does not perform certification and does not issue certificates. Certificates are issued by independent certification bodies. Where a certification body is accredited, it is assessed against ISO/IEC 17021-1 and the ISMS specific requirements in ISO/IEC 27006-1:2024 by a national accreditation body. An accredited certificate can be checked in the International Accreditation Forum database, IAF CertSearch.

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 contains the requirements you are audited against and is the certifiable standard. ISO/IEC 27002 is a guidance document that explains the Annex A controls in detail and suggests how to implement them. You cannot be certified to ISO/IEC 27002.

How long is an ISO 27001 certificate valid?

An accredited ISO 27001 certificate is valid for three years. The certification body carries out surveillance audits during that period, normally annually, and a recertification audit before the certificate expires. The certificate can be suspended or withdrawn if major nonconformities are not closed.

What is the Statement of Applicability?

The Statement of Applicability is the mandatory document that links your risk treatment decisions to the Annex A reference controls. For every control it records whether the control is applicable, the justification for that decision, and whether it is currently implemented. Auditors use it as the map between your risk assessment and the controls they will test, so it is one of the first documents reviewed at Stage 1.

Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.