Skip to content
FioSec Consulting

Frameworks · Foundational

ISO/IEC 27001 Information Security Management

The globally recognized way to prove, with an independent audit, that you manage information security properly.

Maintained by
International Organization for Standardization (ISO) and the IEC
Origin
International · current edition ISO/IEC 27001:2022
Certifiable?
Yes. A registered third party can audit and certify you.

What it is

ISO/IEC 27001 is the international standard for an Information Security Management System, or ISMS. An ISMS is not a single tool but a managed, repeatable system for identifying information risks and treating them: policies, processes, responsibilities, and controls, all kept under continual review.

What sets 27001 apart from NIST and CIS is that it is certifiable. An accredited, independent body can audit your ISMS and issue a certificate that customers, partners, and regulators worldwide recognize as objective proof that you take information security seriously.

The current edition, ISO/IEC 27001:2022, modernized the control set for cloud and contemporary operations. Its companion, ISO/IEC 27002, is the detailed implementation guidance for those controls.

How it's structured

The standard has two parts. The management-system clauses (Clauses 4 to 10) are the mandatory requirements you are audited against: understanding your context, leadership commitment, planning and risk assessment, support and resources, operation, performance evaluation, and continual improvement. This is the engine, the cycle of plan, do, check, and act that keeps security current.

Annex A is the catalogue of reference controls (93 in the 2022 edition) you select from based on your risk assessment, organized into four themes. You are not required to implement every control, but you must justify what you include and exclude in a document called the Statement of Applicability.

Clauses 4–10 · The management system

The mandatory ISMS engine: context, leadership, risk planning, support, operation, evaluation, and improvement. This is what the certificate attests to.

Risk assessment & treatment

The heart of the standard: identify information risks, decide how to treat each, and record your decisions and the controls chosen.

Annex A · Organizational controls

Policies, roles, supplier and threat-intelligence management, incident handling, and business-continuity expectations (37 controls).

Annex A · People controls

Screening, terms of employment, awareness, and disciplinary process (8 controls).

Annex A · Physical controls

Secure areas, equipment, media handling, and the physical protection of information (14 controls).

Annex A · Technological controls

Access control, cryptography, secure configuration, logging, backup, network security, and secure development (34 controls).

Who it's for

ISO 27001 is the right target when an independent, internationally recognized certificate carries real commercial weight: when enterprise customers, public-sector tenders, or partners in regulated industries require it as a condition of doing business.

It suits organizations ready to commit to an ongoing management system, not a one-time project. Certification involves an external audit and is maintained through annual surveillance audits and a full recertification roughly every three years, so it implies sustained leadership and resourcing.

It can be heavier than a smaller organization needs if no customer is actually asking for the certificate. In that case, running a NIST- or CIS-based program first, and pursuing certification only when the business case is clear, is often the more sensible path.

How it compares

ISO 27001 and NIST CSF describe much the same security outcomes. The difference is that ISO wraps them in a formal, auditable, certifiable management system. Organizations frequently use NIST to organize their thinking and ISO to certify it.

It is often confused with SOC 2. Both reassure customers, but ISO 27001 is an international certification of your management system against a fixed standard, while SOC 2 is a North-American auditor’s report describing how well your specific controls operate. Some customers ask for one, some the other, and large vendors often hold both.

How it maps to a Layered Defence

ISO/IEC 27001 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for ISO/IEC 27001?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Management system & leadership

Clauses 4–5: the foundation an auditor checks first.

Has leadership formally defined the scope of your ISMS and committed resources to it?
Do you have an approved information security policy endorsed by senior management?

Risk assessment & treatment

The core of the standard.

Do you run a documented information-security risk assessment on a regular cycle?
Do you have a risk treatment plan and a Statement of Applicability for the controls you’ve chosen?

The SoA is mandatory for certification.

People & access

Annex A people and access controls.

Are staff trained on their security responsibilities, with onboarding and offboarding controls in place?
Is access granted on least-privilege and reviewed periodically, with MFA where appropriate?

Technological controls

Annex A technological theme.

Are systems configured securely, patched, and protected against malware?
Are backups in place and tested, and is sensitive data encrypted?
Are events logged and monitored across your key systems?

Operate, evaluate, improve

Clauses 9–10: keeping the system alive.

Do you run internal audits and management reviews of the ISMS?
Do you track nonconformities and corrective actions to completion?

No email required; scored in your browser, never sent anywhere.

Authoritative source: ISO/IEC 27001 (iso.org)

Explore other frameworks

Need help putting ISO/IEC 27001 into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.