FixTheVuln

ISO/IEC 27001 Guide

By FixTheVuln Team Sources: ISO, IEC, Global Accreditation Cooperation

Test Your Knowledge

CISA Practice Quiz CISM Practice Quiz CISSP Practice Quiz
← Back to Home

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for an information security management system (ISMS). ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) publish it jointly. The current edition is ISO/IEC 27001:2022, published in October 2022, with one amendment (Amd 1:2024, climate action changes) published in February 2024.

An organization can be certified against it. An accredited certification body audits the ISMS, and a passing audit earns a certificate that customers can verify with the issuing body. That certification is the main difference from NIST CSF and CIS Controls, which have no certificate.

How the standard is built

The standard has two parts. Clauses 4 to 10 are the management system requirements. Every one of them is mandatory for certification. Annex A is a reference list of controls you compare your risk treatment against, so nothing necessary is missed. You can also use controls from other sources.

The Statement of Applicability (SoA) is a core document auditors review. It lists the necessary controls, why each is included, whether each is implemented, and why any Annex A control is excluded.

Annex A: 93 controls in 4 themes

The 2022 edition cut the 2013 edition's 114 controls in 14 domains down to 93 controls in 4 themes. It merged overlapping controls and added 11 new ones.

37

Organizational (A.5)

Policies, roles, asset management, access control, supplier relationships, incident management, compliance

8

People (A.6)

Screening, terms of employment, awareness training, disciplinary process, remote working

14

Physical (A.7)

Perimeters, entry controls, equipment protection, clear desk, secure disposal

34

Technological (A.8)

Endpoints, privileged access, malware, vulnerabilities, logging, cryptography, secure development

The 11 controls new in 2022

ControlName
A.5.7Threat intelligence
A.5.23Information security for use of cloud services
A.5.30ICT readiness for business continuity
A.7.4Physical security monitoring
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.16Monitoring activities
A.8.23Web filtering
A.8.28Secure coding

Annex A gives each control a one-line requirement. ISO/IEC 27002:2022 is the companion standard that explains each of the same 93 controls in detail. You certify against 27001, and you use 27002 to implement the controls.

The certification cycle

  1. Stage 1 audit: the certification body reviews your ISMS documentation, scope, risk assessment, and SoA to confirm you are ready.
  2. Stage 2 audit: the auditor tests whether the ISMS and the selected controls actually operate. Passing earns the certificate.
  3. Surveillance audits: shorter audits in years 1 and 2 keep the certificate valid.
  4. Recertification audit: a full audit in year 3 renews the certificate for another 3 years.

Choose a certification body accredited by a signatory of the Global Accreditation Cooperation recognition arrangement (formerly the IAF MLA; IAF and ILAC merged into Global Accreditation Cooperation on January 1, 2026), such as ANAB in the US or UKAS in the UK. A certificate from an unaccredited body carries far less weight with customers.

Version note: the 3-year transition from the 2013 edition ended on October 31, 2025. Certificates issued against ISO/IEC 27001:2013 are no longer valid, so any certificate you check should say 2022.

ISO 27001 vs SOC 2 vs NIST CSF

ISO/IEC 27001SOC 2NIST CSF 2.0
PublisherISO and IEC (international)AICPA (US)NIST (US government)
OutputCertificate, valid 3 yearsAttestation report from a CPA firmNo certificate. Voluntary, usually self-assessed
FocusThe management system that runs securityControls at a service organizationOutcomes across 6 functions
Typical useInternational procurement and vendor due diligenceUS enterprise customers vetting SaaS and service providersStructuring or measuring a security program

The three overlap heavily. An organization selling into both US and international markets can hold ISO 27001 and SOC 2 at the same time and reuse the same control evidence for both audits.

Related ISO standards

StandardCovers
ISO/IEC 27002:2022Implementation guidance for the 93 Annex A controls
ISO/IEC 27005:2022Information security risk management guidance
ISO/IEC 27017Security controls for cloud services
ISO/IEC 27701Privacy information management, often paired with GDPR work
ISO/IEC 42001:2023Management system for artificial intelligence
ISO 22301:2019Business continuity management

Primary sources

Related Resources

๐Ÿ“Š Risk Register Guide Feeds the clause 6 risk assessment โœ… SOC 2 Basics The US attestation counterpart ๐Ÿค Third-Party Risk Vendor assessment and supplier risk

FixTheVuln Store

Studying for ISACA CISA? Get the Study Planner

Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

ISACA CISA Planner

60+ certifications available, from $5.99