Test Your Knowledge
What is ISO/IEC 27001?
ISO/IEC 27001 is the international standard for an information security management system (ISMS). ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) publish it jointly. The current edition is ISO/IEC 27001:2022, published in October 2022, with one amendment (Amd 1:2024, climate action changes) published in February 2024.
An organization can be certified against it. An accredited certification body audits the ISMS, and a passing audit earns a certificate that customers can verify with the issuing body. That certification is the main difference from NIST CSF and CIS Controls, which have no certificate.
How the standard is built
The standard has two parts. Clauses 4 to 10 are the management system requirements. Every one of them is mandatory for certification. Annex A is a reference list of controls you compare your risk treatment against, so nothing necessary is missed. You can also use controls from other sources.
- Clause 4, Context: internal and external issues, interested parties, and the ISMS scope
- Clause 5, Leadership: top management commitment, the information security policy, roles and responsibilities
- Clause 6, Planning: risk assessment (6.1.2), risk treatment and the Statement of Applicability (6.1.3), security objectives
- Clause 7, Support: resources, competence, awareness, communication, documented information
- Clause 8, Operation: running the risk assessments and carrying out the treatment plan
- Clause 9, Performance evaluation: monitoring and measurement, internal audit, management review
- Clause 10, Improvement: nonconformities, corrective action, continual improvement
The Statement of Applicability (SoA) is a core document auditors review. It lists the necessary controls, why each is included, whether each is implemented, and why any Annex A control is excluded.
Annex A: 93 controls in 4 themes
The 2022 edition cut the 2013 edition's 114 controls in 14 domains down to 93 controls in 4 themes. It merged overlapping controls and added 11 new ones.
Organizational (A.5)
Policies, roles, asset management, access control, supplier relationships, incident management, compliance
People (A.6)
Screening, terms of employment, awareness training, disciplinary process, remote working
Physical (A.7)
Perimeters, entry controls, equipment protection, clear desk, secure disposal
Technological (A.8)
Endpoints, privileged access, malware, vulnerabilities, logging, cryptography, secure development
The 11 controls new in 2022
| Control | Name |
|---|---|
| A.5.7 | Threat intelligence |
| A.5.23 | Information security for use of cloud services |
| A.5.30 | ICT readiness for business continuity |
| A.7.4 | Physical security monitoring |
| A.8.9 | Configuration management |
| A.8.10 | Information deletion |
| A.8.11 | Data masking |
| A.8.12 | Data leakage prevention |
| A.8.16 | Monitoring activities |
| A.8.23 | Web filtering |
| A.8.28 | Secure coding |
Annex A gives each control a one-line requirement. ISO/IEC 27002:2022 is the companion standard that explains each of the same 93 controls in detail. You certify against 27001, and you use 27002 to implement the controls.
The certification cycle
- Stage 1 audit: the certification body reviews your ISMS documentation, scope, risk assessment, and SoA to confirm you are ready.
- Stage 2 audit: the auditor tests whether the ISMS and the selected controls actually operate. Passing earns the certificate.
- Surveillance audits: shorter audits in years 1 and 2 keep the certificate valid.
- Recertification audit: a full audit in year 3 renews the certificate for another 3 years.
Choose a certification body accredited by a signatory of the Global Accreditation Cooperation recognition arrangement (formerly the IAF MLA; IAF and ILAC merged into Global Accreditation Cooperation on January 1, 2026), such as ANAB in the US or UKAS in the UK. A certificate from an unaccredited body carries far less weight with customers.
Version note: the 3-year transition from the 2013 edition ended on October 31, 2025. Certificates issued against ISO/IEC 27001:2013 are no longer valid, so any certificate you check should say 2022.
ISO 27001 vs SOC 2 vs NIST CSF
| ISO/IEC 27001 | SOC 2 | NIST CSF 2.0 | |
|---|---|---|---|
| Publisher | ISO and IEC (international) | AICPA (US) | NIST (US government) |
| Output | Certificate, valid 3 years | Attestation report from a CPA firm | No certificate. Voluntary, usually self-assessed |
| Focus | The management system that runs security | Controls at a service organization | Outcomes across 6 functions |
| Typical use | International procurement and vendor due diligence | US enterprise customers vetting SaaS and service providers | Structuring or measuring a security program |
The three overlap heavily. An organization selling into both US and international markets can hold ISO 27001 and SOC 2 at the same time and reuse the same control evidence for both audits.
Related ISO standards
| Standard | Covers |
|---|---|
| ISO/IEC 27002:2022 | Implementation guidance for the 93 Annex A controls |
| ISO/IEC 27005:2022 | Information security risk management guidance |
| ISO/IEC 27017 | Security controls for cloud services |
| ISO/IEC 27701 | Privacy information management, often paired with GDPR work |
| ISO/IEC 42001:2023 | Management system for artificial intelligence |
| ISO 22301:2019 | Business continuity management |
Primary sources
Related Resources
FixTheVuln Store
Studying for ISACA CISA? Get the Study Planner
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
ISACA CISA Planner60+ certifications available, from $5.99