ISO 27001 Compliance
The international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Overview
ISO 27001 follows a Plan-Do-Check-Act cycle and is structured around a risk-based approach. Organisations must identify their information security risks, select appropriate controls to address them, and implement a management system to ensure those controls remain effective over time. The standard's clauses 4 through 10 define mandatory ISMS requirements.
The 2022 revision of the standard reorganised Annex A controls into four themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). Eleven new controls were introduced covering areas such as threat intelligence, information security for cloud services, ICT readiness for business continuity, and data masking.
Certification involves an independent audit by an accredited certification body conducted in two stages. Stage 1 reviews ISMS documentation and readiness. Stage 2 evaluates the implementation and operational effectiveness of the ISMS. Certification is valid for three years, with annual surveillance audits to confirm continued compliance.
ISO 27001 integrates with other management system standards through the Annex SL harmonised structure, enabling organisations to build integrated management systems that address quality (ISO 9001), business continuity (ISO 22301), AI governance (ISO 42001), and other domains alongside information security.
Key Areas
- Information Security Policy - establishing management direction and support for information security
- Organisation of Information Security - defining roles, responsibilities, and governance structures
- Human Resource Security - ensuring personnel are aware of their information security responsibilities
- Asset Management - identifying and classifying information assets and defining protection responsibilities
- Access Control - restricting access to information and information processing facilities
- Cryptography - ensuring proper and effective use of cryptographic controls
- Physical and Environmental Security - preventing unauthorised physical access, damage, and interference
- Operations Security - ensuring correct and secure operation of information processing facilities
- Communications Security - protecting information in networks and supporting information transfer
- Supplier Relationships - managing information security in supplier and third-party relationships
Who It's For
- Organisations of any size seeking internationally recognised certification of their security management practices
- Companies that need to demonstrate security maturity to customers, regulators, or partners across global markets
- Security leaders building an enterprise-wide information security program with executive governance
- Managed service providers and SaaS vendors needing to establish trust with enterprise clients
Core Requirements
- Policies and Governance
- An information security policy must be established, approved by top management, and communicated throughout the organisation. The ISMS scope must be defined, and a governance structure with clear roles and responsibilities must be in place. Management reviews must occur at planned intervals.
- Risk Management
- Organisations must implement a formal risk assessment methodology to identify information security risks, analyse their likelihood and impact, evaluate them against risk criteria, and select appropriate risk treatment options. A Statement of Applicability documents which Annex A controls are selected and justified.
- Security Controls
- Controls selected from Annex A (or equivalent) must address identified risks across organisational, people, physical, and technological domains. Controls must be implemented, documented, and their effectiveness measured. Additional controls beyond Annex A may be included where necessary.
- Incident Response
- An incident management process must be established to detect, report, assess, respond to, and learn from information security incidents. Roles and responsibilities for incident handling must be defined, and procedures for evidence collection and preservation must be in place.
- Evidence and Reporting
- The ISMS must be documented including scope, policies, risk assessments, Statement of Applicability, and operating procedures. Internal audits must be conducted at planned intervals, and management reviews must evaluate ISMS performance. Records must demonstrate compliance and support continual improvement.
Implementation Steps
- Scope and objectives - Define the boundaries and applicability of the ISMS, including the organisational units, locations, assets, and technologies in scope. Establish information security objectives aligned with business strategy and obtain top management commitment and resources.
- Gap assessment - Conduct an initial assessment of the current security posture against ISO 27001 requirements and Annex A controls. Identify gaps in governance, risk management, policies, technical controls, and documentation. Develop a remediation roadmap with clear milestones.
- Control implementation - Perform a formal risk assessment, develop the Statement of Applicability, and implement selected controls. Draft and approve policies, deploy technical controls, conduct awareness training, and establish operational procedures for all in-scope areas.
- Evidence and documentation - Build the documented information required by the standard including the ISMS scope, policies, risk assessment results, Statement of Applicability, and procedures. Establish evidence collection processes for ongoing control operation and conduct internal audits.
- Review and continuous improvement - Conduct management reviews to evaluate ISMS effectiveness. Address nonconformities and audit findings through corrective actions. Monitor the threat landscape, update risk assessments, and refine controls. Prepare for Stage 1 and Stage 2 certification audits.
Frequently Asked Questions
- How long does it take to achieve ISO 27001 certification?
- Typical implementation takes six to twelve months depending on organisational complexity, existing maturity, and available resources. The certification audit itself involves a Stage 1 documentation review and a Stage 2 implementation audit, usually conducted weeks apart.
- What is the Statement of Applicability?
- The Statement of Applicability (SoA) is a mandatory document that lists all Annex A controls, states whether each is applicable or not, provides justification for inclusions and exclusions, and confirms whether each applicable control is implemented.
- How much does ISO 27001 certification cost?
- Costs vary significantly based on organisation size, scope, and complexity. Expenses include implementation effort, potential consulting support, internal audit costs, and certification body fees. Annual surveillance audits and triennial recertification audits are ongoing costs.
- What changed in the 2022 revision?
- The 2022 revision reorganised Annex A controls from 14 domains into four themes (Organisational, People, Physical, Technological), reduced the control count from 114 to 93, and introduced 11 new controls addressing areas such as threat intelligence, cloud security, and data masking.
- Is ISO 27001 legally required?
- ISO 27001 is not legally mandated in most jurisdictions. However, it is increasingly referenced in contracts, regulations, and tender requirements. Some industries and regions effectively require it as a condition of doing business.
- Can small organisations achieve certification?
- Yes. ISO 27001 is scalable to any organisation size. Small organisations can define a focused scope and implement controls proportionate to their risk profile. The management system requirements apply equally, but the documentation and complexity are naturally smaller.
- How does ISO 27001 relate to ISO 27002?
- ISO 27001 specifies requirements for the ISMS and references Annex A controls. ISO 27002 provides detailed implementation guidance for those same controls. Organisations use ISO 27002 as a companion guide when implementing ISO 27001 Annex A controls.
Why It Matters
- Information security incidents continue to increase in frequency and impact. ISO 27001 provides a proven framework for systematically identifying and managing information security risks before they result in breaches. The risk-based approach ensures that security investments are directed where they will have the greatest effect.
- Customers, partners, and regulators increasingly expect evidence of formal security management. ISO 27001 certification provides an independently verified demonstration of security maturity that is understood and trusted globally. This can accelerate sales cycles, satisfy regulatory requirements, and reduce the burden of security questionnaires.
- Beyond certification, ISO 27001 drives a culture of continuous improvement. The management system approach ensures that security is not a one-time project but an ongoing program with executive oversight, regular reviews, and systematic adaptation to evolving threats and business requirements.
Common Challenges
- Securing sustained top management commitment and resources throughout the multi-month implementation process
- Defining an appropriate ISMS scope that is neither too narrow to be meaningful nor too broad to be manageable
- Developing a risk assessment methodology that is rigorous enough for auditors yet practical enough for ongoing use
- Maintaining documentation and evidence to satisfy both the standard's requirements and external auditors' expectations
- Building internal audit capability and ensuring auditors have sufficient independence and competence
- Sustaining the management system after certification, avoiding the common pattern of effort declining between surveillance audits
- Integrating ISO 27001 with existing business processes rather than creating a parallel system that operates in isolation