Cybersecurity Glossary

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard containing requirements for an Information Security Management System (ISMS). Organizations define their scope, assess information-security risks, treat them systematically and demonstrate that the management system is monitored and continually improved. The current edition is ISO/IEC 27001:2022.

What does ISO/IEC 27001 cover?

The standard does not prescribe an identical security design for every organization. It defines a risk-based management framework. Size, industry, business objectives, processed information and legal obligations affect which risks are relevant and which measures are proportionate. ISO 27001 can therefore apply to a single cloud service or an entire organization, provided that its scope is described unambiguously.

Which requirements does the standard contain?

AreaExamples of requirements
ContextIdentify internal and external issues, interested parties and scope.
LeadershipEstablish policy, roles and management support for information security.
PlanningAssess risks and opportunities, plan treatment and set security objectives.
Support and operationManage resources, competence, communication, documentation and operational processes.
EvaluationUse metrics, internal audits and management review.
ImprovementCorrect nonconformities and continually develop the ISMS.

Risk management is the connecting thread. Organizations need traceable criteria, a risk assessment and a risk-treatment plan. The Statement of Applicability records the necessary Annex A controls, their implementation status and the reasons for including or excluding them.

What is the role of Annex A?

Annex A of the 2022 edition contains 93 reference controls in four themes: organizational, people, physical and technological controls. They address areas such as access control, supplier relationships, incident management, secure development and logging. Annex A is not a universal checklist that must be adopted wholesale without assessment. The organization selects controls appropriate to its risks and adds other measures where necessary.

How is the standard implemented?

  1. Establish ownership and scope: Define leadership, ISMS owners, boundaries and dependencies.
  2. Assess the current state: Record existing processes, controls, evidence and material gaps.
  3. Treat risks: Prioritize measures and assign owners and target dates.
  4. Operate the ISMS: Apply processes in daily work, enable staff and document results.
  5. Review internally: Conduct audits and management review, then address identified nonconformities.

Writing an individual policy is rarely the largest effort. Existing activities need to be joined, responsibilities clarified and missing evidence produced consistently. A rushed certification project otherwise tends to create documents with little connection to actual operations.

How does certification work?

Certification is performed by an independent certification body, not by ISO itself. A first-stage audit normally evaluates readiness and essential documentation. The second stage examines whether the ISMS is implemented and operating effectively within its scope. Successful certification is followed by periodic surveillance audits and later recertification. Nonconformities must be corrected before certification or within defined periods, depending on their significance.

What does an ISO 27001 certificate prove?

A certificate provides evidence that the management system in the stated scope was audited against the standard. It does not prove that every product is secure or that vulnerabilities and incidents are impossible. Customers should check the certification body, validity and especially the scope. A certificate for one site or process does not automatically cover every service offered by a provider.

What is the role of technical security testing?

ISO 27001 is a management-system standard, but technical effectiveness still needs evidence. Depending on risk, vulnerability scans, configuration reviews, recovery exercises and penetration tests may be appropriate. Scope and frequency should follow from risk, and findings must feed into improvement. A report without follow-up does not achieve that purpose.

ISO 27001 and technical security testing

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on ISO/IEC 27001? Tell us!