ISO/IEC 27001 is the internationally recognised standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published jointly by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC), the standard takes a risk-based approach to information security governance, requiring organisations to systematically identify information assets, assess threats and vulnerabilities, select appropriate controls from the accompanying Annex A catalogue, and demonstrate conformance through a formal audit and certification process. The 2022 edition restructured the Annex A catalogue to 93 controls across four themes — Organisational, People, Physical, and Technological — and introduced eleven new controls addressing cloud security, threat intelligence, and secure coding. Certification is granted by accredited third-party certification bodies and has become a de facto procurement prerequisite in technology supply chains, financial services, healthcare, and government contracting worldwide.
Overview
- ISO/IEC 27001 originated from British Standard BS 7799, first published by the British Standards Institution in 1995, driven by the inadequacy of ad hoc controls for protecting corporate information assets in an increasingly networked world.
- Part 2 of BS 7799 — the management system specification — became the first edition of ISO/IEC 27001 in 2005, establishing the certifiable framework still in use today.
- The standard follows the ISO High-Level Structure (HLS) common to all ISO management system standards (Clauses 4–10), enabling integration with ISO 9001 (quality), ISO 14001 (environment), and ISO 45001 (occupational health and safety) into a single integrated management system.
- The 2022 revision (ISO/IEC 27001:2022) restructured Annex A from 14 clauses and 114 controls to four themes and 93 controls, adding eleven new controls addressing cloud services, threat intelligence, data masking, physical security monitoring, ICT readiness for business continuity, and secure coding.
- Why it matters:
- Provides a common language for Information Security posture across trading partners, customers, and regulators.
- Enables structured, evidence-based Risk Assessment and documented Risk Treatment Plan decisions rather than ad hoc security investment.
- Certification issued by accredited Certification Body reduces the due-diligence burden in procurement and supply-chain assurance.
- Demonstrates commitment to continual improvement via mandatory Management Review and Internal Audit cycles.
Key Components
- Clauses 4–10 (Normative Requirements)
- Clause 4 – Context of the Organisation: define scope, understand internal/external issues, identify interested parties.
- Clause 5 – Leadership: executive commitment, information security policy, assignment of roles and responsibilities.
- Clause 6 – Planning: Risk Assessment methodology, risk acceptance criteria, treatment options, Statement of Applicability.
- Clause 7 – Support: resources, competence, awareness, communication, documented information management.
- Clause 8 – Operation: implement plans, conduct and record Risk Assessment, execute Risk Treatment Plan.
- Clause 9 – Performance Evaluation: monitoring, measurement, Internal Audit, Management Review.
- Clause 10 – Improvement: nonconformity management, corrective action, continual improvement.
- Annex A Control Themes (2022 Edition)
- Organisational Controls (37 controls): policies, roles, threat intelligence, Information Security in project management, asset management, supplier relationships.
- People Controls (8 controls): vetting, terms of employment, information security awareness, disciplinary process, remote working.
- Physical Controls (14 controls): physical security perimeters, equipment maintenance, secure disposal, clear-desk and clear-screen policies.
- Technological Controls (34 controls): Access Control, identity management, Cryptography, secure development, vulnerability management, Cloud Security, network security.
- Statement of Applicability (SoA)
- Mandatory document listing all 93 Annex A controls, noting which are included or excluded with justifications.
- Forms the primary audit artefact mapping organisational risk decisions to specific controls.
- Certification Process
- Stage 1 audit: documentation review — auditors check policy completeness, scope definition, SoA completeness.
- Stage 2 audit: on-site or remote examination of ISMS implementation and operational evidence.
- Surveillance audits: annual (or semi-annual) checks between the three-year recertification cycle.
- Certification granted by a Certification Body accredited by a national accreditation body (e.g., UKAS in the UK, DAkkS in Germany, ANAB in the US).
Applications and Use Cases
- Technology and SaaS Providers
- Cloud service providers use ISO 27001 ISMS as the control backbone for SOC 2 Type II and CSA STAR certifications; the control sets overlap substantially, reducing duplicated audit effort.
- SaaS vendors holding ISO 27001 certification satisfy enterprise procurement security questionnaires and reduce bespoke vendor-risk assessment cycles for customers.
- Financial Services
- Banks and payment processors align ISO 27001 ISMS with PCI DSS requirements; the risk-based documentation reduces scope of PCI QSA assessments.
- Regulatory frameworks in the UK (FCA), EU (DORA — Digital Operational Resilience Act), and Singapore (MAS TRM) reference ISO 27001 as an acceptable baseline control framework.
- Healthcare
- NHS Digital and healthcare regulators in multiple jurisdictions accept ISO 27001 certification as evidence of baseline Data Security for systems handling patient data.
- Aligns with HIPAA administrative safeguards when mapping Annex A controls to HIPAA Security Rule requirements.
- Government and Critical Infrastructure
- Defence supply chains in the UK (MOD Cyber Standards), EU (NIS2 Directive), and Australia (IRAP alignment) reference or require ISO 27001 as a minimum security posture.
- Critical infrastructure operators use ISO 27001 alongside sector-specific frameworks such as IEC 62443 for industrial control systems.
- AI and Emerging Technology Governance
- Organisations implementing ISO IEC 42001 AI management systems leverage existing ISO 27001 ISMS structure for risk treatment, audit, and continual improvement — the two standards are explicitly designed for integration.
- AI providers use ISO 27001 controls for training data integrity, model access control, and adversarial input monitoring — bridging AI Governance and operational Information Security.
- Third-Party and Supply Chain Assurance
- ISO 27001 certification is used as a gateway condition in supplier qualification programmes, reducing the need for individual security questionnaires at scale.
- Third-Party Risk Management programmes reference ISO 27001 as a baseline for vendor classification and ongoing monitoring.
Standards and Context
- ISO/IEC 27000 Series — ISO 27001 is the certifiable management system specification within a broader family:
- IEC 27002 — Code of practice providing implementation guidance for the 93 Annex A controls (companion to ISO 27001, not independently certifiable).
- IEC 27005 — Risk management guidance specifically for information security, aligning with ISO 31000 methodology.
- ISO/IEC 27017 — Controls for cloud service providers and customers.
- ISO/IEC 27018 — Privacy controls for personally identifiable information in public clouds.
- ISO/IEC 27701 — Extension for Privacy Information Management Systems (PIMS), enabling alignment with GDPR Compliance and other privacy regulations.
- ISO IEC 42001 — AI management system standard, explicitly designed for integration with ISO 27001.
- Related Frameworks
- NIST Cybersecurity Framework — US-originated voluntary framework with a similar risk-based posture; organisations frequently map ISO 27001 controls to NIST CSF categories.
- SOC 2 — US attestation standard (AICPA) for service organisations; significant control overlap with ISO 27001 Annex A but different assurance model (attestation vs. certification).
- PCI DSS — Payment card industry standard; organisations use ISO 27001 ISMS to provide contextual governance around PCI-scoped environments.
- Cyber Essentials — UK government-backed baseline scheme; ISO 27001 exceeds Cyber Essentials requirements but both can be held concurrently.
- NIS2 Directive — EU network and information security directive (2022) requires essential and important entities to implement security measures broadly aligned with ISO 27001 scope.
- DORA — EU Digital Operational Resilience Act for financial entities references ISO standards and risk management practices aligned with ISO 27001.
- Accreditation Infrastructure
- National accreditation bodies (UKAS, DAkkS, ANAB, JAB) accredit certification bodies that issue ISO 27001 certificates.
- The IAF (International Accreditation Forum) multilateral recognition arrangement ensures mutual acceptance of certificates across jurisdictions.
- ISO/IEC 17021-1 governs the requirements for conformity assessment bodies conducting management system audits.