Skip to main content

Framework explainer

ISO 27001, and what it actually requires

ISO/IEC 27001 is the international standard for an Information Security Management System. This page sets out what the standard asks for: the clauses that carry the weight, how Annex A works, and what an auditor looks at in Stage 1 and Stage 2.

What ISO 27001 is

ISO/IEC 27001 is published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It does not prescribe a set of security products. It requires an organisation to decide the boundary of its management system, understand the risks to information inside that boundary, treat those risks deliberately, document the decisions, and then keep the whole thing running and improving under management oversight.

Certification is not self-declared. An accredited certification body audits the system in two stages and issues a certificate that states the scope. Buyers read that scope statement, which is why scope is the first decision rather than a formality.

The 2022 edition, and what changed from 2013

ISO/IEC 27001:2022 is the current edition. Organisations certified against the 2013 edition moved across during the published transition period, and anyone certifying now certifies against 2022.

  • Annex A was restructured from 114 controls in 14 domains into 93 controls across four themes.
  • Eleven controls are new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
  • Controls carry attributes, which makes mapping them to other frameworks and to regulatory obligations far easier.
  • The wording around planning, the Statement of Applicability and continual improvement was tightened, and the clause structure follows the ISO Harmonised Structure shared with ISO 42001 and other management system standards.

The clause structure, and where the weight sits

Clauses 4 to 10 are the requirements. Two of them account for most of the audit conversation: clause 6.1.3 d), which produces the Statement of Applicability, and clause 9.2, which requires an independent internal audit.

Clauses 4 and 5: context and leadership

The organisation works out who its interested parties are, what they expect, and where the boundary of the management system sits. Top management sets the policy, assigns roles and carries the accountability. Scope decided here shapes everything the auditor later looks at.

Clause 6: planning, and clause 6.1.3 d)

Risks and opportunities are identified, and a risk treatment plan sets out what is done about them. Clause 6.1.3 d) is the one that produces the Statement of Applicability: every Annex A control compared against the treatment plan, with a documented reason for including it or leaving it out.

Clauses 7 and 8: support and operation

Competence, awareness, communication and documented information, then the operational planning and control that puts the risk treatment plan into practice rather than leaving it on paper.

Clause 9, and clause 9.2 internal audit

Monitoring, measurement and management review. Clause 9.2 requires a planned internal audit programme carried out by auditors who are objective and impartial about the work being audited, which is why an implementer cannot audit their own implementation.

Clause 10: improvement

Nonconformities are recorded, their root cause established and corrective action taken and evidenced. Continual improvement is a requirement of the standard, not an aspiration.

Annex A: 93 controls, four themes

The 2022 edition groups 93 controls into organisational, people, physical and technological themes, each tagged with attributes such as control type and security domain. Annex A is a reference set, not a checklist to implement wholesale: the risk treatment plan decides which apply.

What Stage 1 and Stage 2 assess

Certification is a two-stage audit carried out by the certification body, not by the organisation that built the system.

Stage 1: is the system designed?

A documentation and readiness review. The auditor reads the scope statement, the policy, the risk methodology, the risk treatment plan, the Statement of Applicability and the internal audit and management review records. The output is usually a set of findings to close before Stage 2, and a date.

Stage 2: is the system operating?

A deeper audit of the system in use. The auditor samples evidence across the controls in the Statement of Applicability, interviews the people who own them and tests whether what is documented matches what happens. Findings are raised as major or minor nonconformities, with corrective action required before the certificate is issued.

After certification

A certificate runs for three years, with surveillance audits in years two and three and a full recertification audit at the end of the cycle. The management system has to keep running in between, because surveillance audits sample it.

QUESTIONS

Frequently asked

Where to go next

This page explains the standard. These pages set out the work.

ISO 27001 Sprint

Practitioner-led implementation to the point of audit readiness.

ISO 27001 Guided

For teams with an internal owner who want direction rather than delivery.

ISO 27001 internal audit

The clause 9.2 audit, carried out independently of the build.

Statement of Applicability

What clause 6.1.3 d) asks for, and how the document is put together.

What will ISO 27001 cost you? Four questions, no signup.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.