GlossaryISO 27001

ISO 27001

Short answer

ISO 27001 is the international standard for an information security management system (ISMS). It sets out how an organisation identifies its security risks, chooses controls to manage them and keeps improving, and it can be certified by an accredited body after an external audit.

What the standard requires

ISO 27001 asks an organisation to define the scope of its ISMS, assess its information security risks, decide how to treat each one and run the controls that follow from that decision. The current version is ISO 27001:2022. Its Annex A lists 93 reference controls grouped in four themes: organisational, people, physical and technological. The organisation documents which controls apply in a Statement of Applicability.

How certification works

An accredited certification body audits the ISMS in two stages: a documentation review (Stage 1) and an audit of how the system works in practice (Stage 2). Certificates last three years, with surveillance audits in the years in between.

ISO 27001 vs SOC 2

ISO 27001 is an international certification of a management system. SOC 2 is an attestation report issued by a CPA firm, more common with customers in the United States. Many controls overlap, so one programme can support both.

Why companies get certified

Most companies pursue ISO 27001 because customers ask for it during procurement, and because it gives a structured way to manage security that also supports ENS, NIS2 and DORA requirements.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub