ISO/IEC 27001:2022
Overview
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It provides a framework for establishing, implementing, maintaining, and continually improving information security.
Key Concepts
Information Security Management System (ISMS)
An ISMS is a systematic approach to managing sensitive information through:
- People - Roles, responsibilities, and awareness
- Processes - Policies, procedures, and controls
- Technology - Tools and systems supporting security
Risk-Based Approach
ISO 27001 requires organizations to:
- Identify information assets
- Assess risks to those assets
- Implement appropriate controls
- Monitor and review effectiveness
Structure of ISO 27001:2022
| Clause | Topic |
|---|---|
| 4 | Context of the organization |
| 5 | Leadership |
| 6 | Planning |
| 7 | Support |
| 8 | Operation |
| 9 | Performance evaluation |
| 10 | Improvement |
Annex A Controls
ISO 27001:2022 includes 93 controls organized into 4 themes:
| Theme | Controls | Examples |
|---|---|---|
| Organizational | 37 | Policies, roles, supplier relationships |
| People | 8 | Screening, awareness, disciplinary process |
| Physical | 14 | Secure areas, equipment, clear desk |
| Technological | 34 | Access control, cryptography, logging |
Certification Process
Steps to Certification
- Gap Analysis - Assess current state vs requirements
- ISMS Implementation - Build the management system
- Internal Audit - Verify ISMS effectiveness
- Management Review - Leadership evaluation
- Stage 1 Audit - Documentation review
- Stage 2 Audit - Implementation verification
- Certification - 3-year certificate issued
Where audits actually fail
The single most common finding auditors raise isn't a missing control - it's an evidence gap. A policy exists and a control is genuinely followed, but nobody can produce the records proving it: no ticket showing the quarterly access review happened, no signed log of who approved a firewall change, no record that a terminated employee's access was revoked within the required timeframe. If you're implementing an ISMS, treat "can we prove this happened, six months from now, to someone who wasn't in the room" as the real bar - not just "do we do this."
Maintaining Certification
- Surveillance Audits - Annual audits (Years 1 & 2)
- Recertification Audit - Full audit at Year 3
- Continuous Improvement - Ongoing ISMS updates
Benefits of ISO 27001
- Demonstrates commitment to information security
- Reduces risk of security incidents
- Meets compliance requirements
- Competitive advantage in tenders
- Improves processes through systematic approach
Getting Started
- Obtain management commitment
- Define ISMS scope
- Conduct risk assessment
- Implement controls
- Train staff
- Monitor and measure
- Conduct internal audits
- Seek certification