What is ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system (ISMS). The current version, ISO/IEC 27001:2022, pairs management-system requirements (clauses 4–10) with 93 Annex A controls grouped into four themes.
Definition
ISO/IEC 27001 is the leading international standard for information security management. It specifies the requirements for establishing, operating, and continually improving an information security management system (ISMS): a risk-based way of managing the security of information.
Background
ISO 27001 is published jointly by ISO and the IEC. The current edition is ISO/IEC 27001:2022. Its management-system requirements live in clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation, and improvement). Annex A lists 93 controls organized into four themes: Organizational (37), People (8), Physical (14), and Technological (34). Unlike SOC 2, ISO 27001 is a certifiable standard: an accredited certification body audits your ISMS, and certificates run on a three-year cycle with annual surveillance audits.
Why it matters
ISO 27001 is the most widely recognized security standard internationally, so it carries weight with customers outside North America. Because it is risk-based, it also gives you a durable operating model for security rather than a checklist you satisfy once.
Step by step
- Define the ISMS scope and secure leadership commitment.
- Run a risk assessment and choose risk treatments.
- Produce a Statement of Applicability (SoA) that justifies which Annex A controls apply.
- Implement the selected controls and the mandatory management-system processes.
- Run internal audits and a management review.
- Engage an accredited certification body for the Stage 1 and Stage 2 audits.
Examples
- A European SaaS company pursues ISO 27001 because its enterprise prospects expect the certificate rather than a SOC 2 report.
- A company that already has SOC 2 crosswalks its existing controls to Annex A, so much of the evidence is reused.
Common mistakes
- Writing a Statement of Applicability that excludes controls without a documented, risk-based justification.
- Treating the risk assessment as a formality instead of the engine that drives control selection.
- Neglecting the mandatory internal audit and management review, which auditors always check.
FAQ
What is the current version of ISO 27001?
ISO/IEC 27001:2022. It reorganized Annex A into 93 controls across four themes (Organizational, People, Physical, Technological), down from 114 controls in the 2013 edition.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 is a certifiable international standard built around an ISMS; SOC 2 is a US attestation report against the Trust Services Criteria. They overlap heavily, so one control set can support both.
Do I need to implement all 93 Annex A controls?
Only the ones your risk assessment says are applicable. The Statement of Applicability documents which controls you include or exclude and why.
Related
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free