Skip to content
atlas

ISO 27001

Also known as: ISO/IEC 27001, ISMS standard

The international standard for running an information security management system that can be certified.

Draft - this entry has not been reviewed yet.

Read the full article →

Formal

An international standard, current edition 2022, whose clauses 4-10 set the requirements for an information security management system - context, leadership, planning, support, operation, performance evaluation and improvement - with Annex A listing 93 controls to choose from.

In plain English

A set of house rules for running security as a daily routine rather than a one-off clean-up - written so that an outside inspector can check it is really followed.

In practice

Danish state bodies must follow ISO 27001, so the security lead at a ministry uses its clauses to set the scope, run the risk assessment, pick controls from Annex A and report maturity each year - without seeking a certificate.

Why it matters

Without a common measure every customer, auditor and authority would ask for security to be shown in a different way; ISO 27001 gives one structure that can be recognised, audited and mapped to laws such as NIS2.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Get top management to sponsor the ISMS, name an owner such as an information security coordinator, and set up a security committee that meets regularly.
  2. Map the context and interested parties (clauses 4.1-4.2) and write a scope statement naming the units, locations and systems the ISMS covers (4.3).
  3. Choose a documented risk assessment method, build an asset and risk register, and have risk owners approve the treatment plan and the residual risks (6.1.2-6.1.3).
  4. Select the controls the risks call for, compare them with the 93 controls in Annex A, and record every choice and justification in a Statement of Applicability approved by management.
  5. Write the information security policy (5.2) and the topic-specific policies and procedures, then implement the controls with owners, deadlines and staff training.
  6. Measure whether the controls work, run an internal audit by someone independent of the audited area (9.2), and hold a management review (9.3) with recorded decisions.
  7. Fix nonconformities with root-cause analysis and corrective actions; if you want a certificate, book a certification body accredited by DANAK or another IAF member for the stage 1 and stage 2 audits.
  8. Run the cycle every year - risk assessment, internal audit, management review and SoA update - since a certificate lasts three years with annual surveillance audits.

Common pitfalls

  • Writing a pack of documents before the risk assessment, so controls are copied from Annex A instead of chosen for real risks.
  • Drawing the scope so narrowly that the systems customers and authorities care about fall outside it.
  • Letting the people who run the controls audit themselves, which breaks the objectivity clause 9.2 requires.
  • Treating the certificate as the finish line and letting the ISMS go quiet between surveillance audits.

Good guides

Technical deep dive

The normative core is clauses 4-10, written in the harmonized structure used by all ISO management system standards; clauses 0-3 are introduction, scope, normative reference (ISO/IEC 27000) and terms. Annex A is also normative, but its 93 controls only become obligations through clause 6.1.3: the organisation determines the controls needed to treat its assessed risks, compares them with Annex A to verify that nothing necessary has been omitted, and records the result in the Statement of Applicability. Annex A is explicitly not exhaustive, so controls from other sources (CIS Controls, sector rules, customer contracts) can and often should be added.

The 2022 revision changed more than the annex. Clause 4.2 now asks which interested-party requirements will be addressed through the ISMS, 4.4 refers to the processes and their interactions, 6.3 requires changes to the ISMS to be planned, 8.1 requires criteria for processes, and management review (9.3.2) must consider changes in the needs and expectations of interested parties. Amendment 1:2024 added to clause 4.1 that the organisation must determine whether climate change is a relevant issue, and a note to 4.2 that interested parties can have climate-related requirements. Under IAF MD 26, certificates against the 2013 edition had to be transitioned by 31 October 2025.

The standard demands specific documented information rather than a fixed document set: the scope, the policy, the risk assessment and treatment processes, the SoA, objectives, evidence of competence, operational planning records, risk assessment and treatment results, monitoring results, the audit programme and audit results, management review results, and records of nonconformities and corrective actions. Certification is carried out by bodies accredited under ISO/IEC 17021-1 and ISO/IEC 27006 (in Denmark by DANAK); the initial audit runs in two stages, and nonconformities are graded major or minor, with a major one blocking certification until it is corrected.

Frequent failure modes are over-narrow scopes, a risk method whose results cannot be reproduced, SoA exclusions justified with "not relevant" but no risk rationale, and internal audits performed by the people who run the controls, which undermines the objectivity required by 9.2. Compared with NIS2 the standard is voluntary and silent on legal deadlines such as the 24-hour early warning; compared with the NIST CSF it prescribes a management system rather than a catalogue of outcomes; and compared with ISO/IEC 27002 it states what must be done, while 27002 explains how each control can be implemented.

Relationships

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022 · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.