What Is the ISO 27001 Standard? A Complete Overview

The ISO 27001 standard is the international standard for information security management, specifying the requirements for an Information Security Management System (ISMS) โ€” a risk-based framework organizations use to protect the confidentiality, integrity, and availability of their information. Published by ISO and IEC, it gives businesses of any size a structured, auditable way to identify security risks, apply the right controls, and prove to customers and regulators that information is being managed responsibly. This overview explains what the standard covers, how it is structured, what the Annex A controls are, who it applies to, and why it matters.

ISO 27001 Standard: An Overview

ISO/IEC 27001 is the only widely recognized international standard that sets out formal requirements for an ISMS. Rather than dictating a fixed checklist of technologies, it establishes a management-system approach: you understand your organizationโ€™s context, assess information security risks, decide how to treat those risks, and continually improve. Because it is risk-based, the standard adapts to a two-person startup or a global enterprise alike.

The current version is ISO/IEC 27001:2022, published in October 2022. It replaced the previous ISO 27001:2013 edition, and the transition period for older 2013 certificates ended on 31 October 2025. As a result, ISO/IEC 27001:2022 is now the only current and valid version of the standard โ€” any organization certifying today does so against the 2022 edition.

A key point that often causes confusion: ISO 27001 certifies organizations, not individuals. A company earns certification for its ISMS after an independent audit. Individuals build their competence through training and qualifications such as Lead Auditor or Internal Auditor courses, which are separate from an organizationโ€™s certificate.

What Is an Information Security Management System (ISMS)?

An Information Security Management System (ISMS) is the heart of the ISO 27001 standard. It is not a single piece of software or a firewall โ€” it is a coordinated set of policies, procedures, people, and technical measures that work together to manage information security in a systematic, repeatable way.

The ISMS is built around three core objectives, often called the CIA triad:

  • Confidentiality โ€” ensuring information is accessible only to those authorized to see it.
  • Integrity โ€” safeguarding the accuracy and completeness of information and processing methods.
  • Availability โ€” ensuring authorized users can access information and associated assets when needed.

Instead of reacting to incidents one at a time, an ISMS asks the organization to look at all its information assets, assess what could go wrong, and put proportionate controls in place. It then requires ongoing monitoring, internal audits, and management review so the system keeps pace with new threats โ€” a cycle of continual improvement.

How the ISO 27001 Standard Is Structured

The ISO 27001 standard has two main parts: the mandatory management-system clauses and Annex A.

Mandatory clauses (4โ€“10)

Clauses 4 through 10 contain the requirements every certified organization must meet. In plain terms, they cover:

  • Clause 4 โ€” Context of the organization: understanding internal and external issues, interested parties, and defining the ISMS scope.
  • Clause 5 โ€” Leadership: top management commitment, an information security policy, and clear roles and responsibilities.
  • Clause 6 โ€” Planning: risk assessment, risk treatment, and setting security objectives.
  • Clause 7 โ€” Support: resources, competence, awareness, communication, and documented information.
  • Clause 8 โ€” Operation: carrying out the risk assessment and implementing the risk treatment plan.
  • Clause 9 โ€” Performance evaluation: monitoring, measurement, internal audit, and management review.
  • Clause 10 โ€” Improvement: handling nonconformities, corrective action, and continual improvement.

These clauses are where the โ€œmanagement systemโ€ lives. For a clause-by-clause breakdown of exactly what each one demands, see our detailed guide to the ISO 27001 requirements.

Annex A controls

Alongside the clauses, Annex A provides a catalog of information security controls that organizations draw on to treat the risks they identify. Annex A is not a list you must implement in full โ€” you select the controls that apply to your risks and justify your choices.

The Annex A Control Themes (2022)

In the 2022 edition, Annex A was restructured. It now contains 93 controls grouped into four themes:

  • Organizational controls (37) โ€” policies, roles, supplier relationships, threat intelligence, and information security in project management.
  • People controls (8) โ€” screening, terms of employment, awareness and training, and remote-working responsibilities.
  • Physical controls (14) โ€” secure areas, equipment protection, clear desk and clear screen, and secure disposal.
  • Technological controls (34) โ€” access control, cryptography, secure development, logging, and protection against malware.

This four-theme structure replaced the 14-domain layout used in the 2013 edition, making the controls easier to navigate and map to modern security practices.

The Statement of Applicability (SoA)

Because organizations choose which Annex A controls apply, the standard requires a Statement of Applicability (SoA). The SoA lists all Annex A controls, states whether each is included or excluded, and explains why. It is one of the most scrutinized documents in a certification audit, because it ties your control selection directly back to your risk assessment.

Who Is the ISO 27001 Standard For?

The ISO 27001 standard is deliberately sector-agnostic. It applies to any organization that handles information worth protecting, including:

  • Technology and SaaS companies that store customer data and need to satisfy security questionnaires.
  • Financial and professional services handling sensitive client and transaction information.
  • Healthcare providers managing patient records and privacy obligations.
  • Government contractors and suppliers required to demonstrate strong information security.
  • Any business that wants to reduce cyber risk and build customer trust.

Whether you are a small managed-service provider or a multinational, the standard scales to your scope, your risks, and your resources.

Why the ISO 27001 Standard Matters

Adopting the ISO 27001 standard delivers benefits that go well beyond a certificate on the wall:

  • Reduced risk of breaches: a structured risk-treatment process helps you find and close gaps before they are exploited.
  • Customer and market trust: certification is increasingly a prerequisite in vendor onboarding and tenders, especially with enterprise buyers.
  • Regulatory alignment: the ISMS framework supports compliance with data protection and privacy obligations.
  • Operational resilience: clear roles, procedures, and incident handling reduce downtime and confusion when something goes wrong.
  • Continual improvement: built-in audits and reviews keep your security posture current instead of letting it drift out of date.

In a landscape where a single incident can damage reputation and revenue, a recognized, independently audited framework gives stakeholders confidence that information security is being taken seriously.

The ISO 27000 Family of Standards

ISO 27001 does not stand alone. It sits within the broader ISO/IEC 27000 family of information security standards that support and expand on it. For example, ISO/IEC 27002 provides implementation guidance for the Annex A controls, while other standards in the family address risk management, cloud services, and privacy. When people refer to โ€œthe ISO 27001 standard,โ€ they usually mean the certifiable requirements standard โ€” ISO 27001 itself โ€” supported by these companion documents.

How Organizations Get Certified

At a high level, an organization implements its ISMS, runs internal audits, and then engages an accredited certification body for an independent, two-stage audit. Passing leads to certification, followed by periodic surveillance audits to confirm the ISMS stays effective. If you want the full journey, our guides to the ISO 27001 certification process and the ISO 27001 audit walk through each stage.

To build the internal competence needed to run and audit an ISMS, teams often pursue ISO 27001 Lead Auditor training or ISO 27001 Internal Auditor training. When you are ready to pursue the certificate itself, IAS offers ISO 27001 certification for organizations across the USA. IAS delivers accredited certification and training through its global network, and works alongside partner bodies such as EAS to support clients worldwide. To discuss your scope and next steps, contact us and our team will guide you through the options.

Frequently Asked Questions

What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard that sets the requirements for an ISMS, including the mandatory clauses and Annex A. ISO 27002 is a supporting guidance document that explains how to implement the Annex A controls in more detail. You get certified against ISO 27001; you use ISO 27002 as a reference to apply the controls well.
Is ISO 27001:2022 different from ISO 27001:2013?
Yes. ISO/IEC 27001:2022 updated the standard and restructured Annex A from 114 controls across 14 domains into 93 controls across four themes (Organizational, People, Physical, Technological). The management-system clauses remain broadly similar. Since the transition period ended on 31 October 2025, ISO 27001:2022 is now the only valid version for certification.
How many controls are in ISO 27001?
Annex A of the 2022 version contains 93 controls grouped into four themes. Organizations do not implement all of them by default โ€” they select the controls relevant to their identified risks and record their decisions in a Statement of Applicability (SoA).
Is the ISO 27001 standard mandatory or enforceable by law?
ISO 27001 is a voluntary standard, not a law. However, customers, partners, and tenders frequently require it as a condition of doing business, and it helps organizations meet legal and regulatory obligations around data protection. In practice, many companies treat it as a de facto requirement in their market.
Can an individual be certified in ISO 27001?
No. ISO 27001 certification is awarded to organizations for their ISMS. Individuals cannot be โ€œISO 27001 certified,โ€ but they can gain recognized qualifications by completing Lead Auditor or Internal Auditor training, which demonstrates personal competence in auditing and managing an ISMS.
What is a Statement of Applicability (SoA)?
The Statement of Applicability is a required document that lists every Annex A control, states whether it is applicable, and explains the reasoning based on your risk assessment. Auditors rely on the SoA to confirm your control selection is justified, making it one of the most important documents in an ISO 27001 audit.