ISO 27001
ISO/IEC 27001 Information Security Management
ISO/IEC 27001 is the leading international standard for information security management systems (ISMS). It provides a risk-based framework of policies, procedures, and controls that organisations use to protect the confidentiality, integrity, and availability of information. Certification, issued after an independent audit, shows customers and regulators that security is managed systematically.
At its heart, ISO 27001 requires organisations to identify information risks and treat them using a set of controls, many of which are drawn from the standard's Annex A. Rather than prescribing specific technologies, it focuses on a repeatable management system — plan, implement, monitor, and improve.
Certification is achieved through a two-stage external audit and maintained with periodic surveillance audits and a full recertification every three years. It is widely requested in enterprise procurement and is often the foundation on which other compliance efforts, such as SOC 2, are built.
How ISO 27001 works in practice
ISO/IEC 27001 sets requirements for an information security management system, or ISMS. The organisation defines a scope, understands its context, assesses risk and selects treatment measures. Management needs to assign responsibilities and provide oversight. The system combines policies with operating processes and evidence: an approved access policy, for example, should be supported by records showing how access is granted, reviewed and removed.
Controls are selected in response to risk and applicable obligations. The Statement of Applicability records the necessary controls and explains inclusion or exclusion decisions. It should describe the organisation's actual choices, not merely reproduce a generic template. Internal audit and management review help evaluate the ISMS and identify improvements. Corrective actions address weaknesses discovered through reviews, incidents and other feedback.
Who needs it and what certification covers
Organisations may pursue certification because customers request it, procurement requires it or management wants a structured security programme. The standard can apply to different sizes and sectors. Certification concerns the defined ISMS scope, which may cover a particular service, entity or group of locations. Customers should read that scope rather than assume a certificate covers every activity performed under a company's name.
An independent certification body audits the ISMS. A readiness consultant can help assess gaps, implement processes and organise evidence, but does not issue the organisation's accredited certificate. Confirm the certification body's accreditation and scope before engagement. Also distinguish certification from an individual's training credential. Neither should be used as a substitute for reading the relevant service boundary, evidence and customer commitments.
Planning a sustainable programme
Begin by deciding which services, people, systems and third parties are in scope. Identify legal, contractual and business requirements with appropriate specialists. Allocate control ownership and plan remediation in a realistic sequence. Some improvements are technical; others involve human resources, supplier management or organisational approvals. A team cannot demonstrate that a process has operated if it has only just created the document describing it.
Preparation time and cost depend on scope, maturity, staffing and the independent audit. Avoid promising a fixed outcome before those are assessed. After certification, keep risk assessments, access reviews, internal audits and management reviews current. Changes to products, infrastructure or suppliers can affect the ISMS. Coordinate evidence with SOC 2 where useful, but recognise that SOC 2 is a separate CPA attestation with different reporting requirements.
ISO 27001 vs. SOC 2
| Aspect | ISO 27001 | SOC 2 |
|---|---|---|
| Focus | Requirements for an information security management system. | Independent assurance reporting on service-organisation controls. |
| Result | An organisation may seek certification from an independent certification body. | A licensed CPA firm issues a SOC 2 report, not an ISO certificate. |
Common misconceptions
- Certification is not a guarantee that no breach will occur. The ISMS manages risk and improvement rather than eliminating every possible threat.
- An ISO 27001 consultant and an independent certification body perform different roles. Readiness assistance alone cannot grant accredited organisational certification.
- A policy library is not an operating ISMS. Owners, implementation, reviews and records of actual activity are needed alongside written policies.
Frequently asked questions
Is ISO 27001 a technology checklist?
No. It sets requirements for establishing, maintaining and improving a risk-based information security management system; technology is only part of that work.
Does ISO 27001 certification replace a SOC 2 report?
No. They address different assurance requests. Confirm which evidence a customer or contract actually requires before starting either engagement.
Reference sources
Practical context
Using ISO 27001 in a real decision
Definitions are most useful when they help a team decide what to scope, who should own the work, and what evidence supports the next step. Use these questions to turn the term into a practical conversation.
- Which customers, data, services, or contracts make this requirement relevant?
- What controls and evidence would demonstrate that the requirement is operating in practice?
- Who is accountable for the scope, reviews, and any remediation work?
