Skip to content

ISO/IEC 27001:2022

Overview

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It provides a framework for establishing, implementing, maintaining, and continually improving information security.

Key Concepts

Information Security Management System (ISMS)

An ISMS is a systematic approach to managing sensitive information through:

  • People - Roles, responsibilities, and awareness
  • Processes - Policies, procedures, and controls
  • Technology - Tools and systems supporting security

Risk-Based Approach

ISO 27001 requires organizations to:

  1. Identify information assets
  2. Assess risks to those assets
  3. Implement appropriate controls
  4. Monitor and review effectiveness

Structure of ISO 27001:2022

Clause Topic
4 Context of the organization
5 Leadership
6 Planning
7 Support
8 Operation
9 Performance evaluation
10 Improvement

Annex A Controls

ISO 27001:2022 includes 93 controls organized into 4 themes:

Theme Controls Examples
Organizational 37 Policies, roles, supplier relationships
People 8 Screening, awareness, disciplinary process
Physical 14 Secure areas, equipment, clear desk
Technological 34 Access control, cryptography, logging

Certification Process

Steps to Certification

  1. Gap Analysis - Assess current state vs requirements
  2. ISMS Implementation - Build the management system
  3. Internal Audit - Verify ISMS effectiveness
  4. Management Review - Leadership evaluation
  5. Stage 1 Audit - Documentation review
  6. Stage 2 Audit - Implementation verification
  7. Certification - 3-year certificate issued

Where audits actually fail

The single most common finding auditors raise isn't a missing control - it's an evidence gap. A policy exists and a control is genuinely followed, but nobody can produce the records proving it: no ticket showing the quarterly access review happened, no signed log of who approved a firewall change, no record that a terminated employee's access was revoked within the required timeframe. If you're implementing an ISMS, treat "can we prove this happened, six months from now, to someone who wasn't in the room" as the real bar - not just "do we do this."

Maintaining Certification

  • Surveillance Audits - Annual audits (Years 1 & 2)
  • Recertification Audit - Full audit at Year 3
  • Continuous Improvement - Ongoing ISMS updates

Benefits of ISO 27001

  • Demonstrates commitment to information security
  • Reduces risk of security incidents
  • Meets compliance requirements
  • Competitive advantage in tenders
  • Improves processes through systematic approach

Getting Started

  1. Obtain management commitment
  2. Define ISMS scope
  3. Conduct risk assessment
  4. Implement controls
  5. Train staff
  6. Monitor and measure
  7. Conduct internal audits
  8. Seek certification

Credits/References

  1. ISO/IEC 27001:2022 - Information Security Management Systems
  2. ISO/IEC 27002:2022 - Code of Practice for Information Security Controls
  3. ISO/IEC Annex SL - High Level Structure for Management Systems