{"id":4433,"date":"2021-10-22T09:02:54","date_gmt":"2021-10-22T09:02:54","guid":{"rendered":"https:\/\/ias-certification.com\/ca\/?p=4433"},"modified":"2026-06-11T05:29:36","modified_gmt":"2026-06-11T05:29:36","slug":"iso-27001-requirements","status":"publish","type":"post","link":"https:\/\/ias-certification.com\/ca\/blog\/iso-27001-requirements\/","title":{"rendered":"ISO 27001 Requirements"},"content":{"rendered":"<div  style='padding-bottom:10px; color:#b02b2c;' class='av-special-heading av-special-heading-h1 custom-color-heading blockquote modern-quote  avia-builder-el-0  el_before_av_hr  avia-builder-el-first  '><h1 class='av-special-heading-tag '  >ISO 27001 Requirements<\/h1><div class='special-heading-border'><div class='special-heading-inner-border' style='border-color:#b02b2c'><\/div><\/div><\/div>\n<div  style='height:20px' class='hr hr-invisible   avia-builder-el-1  el_after_av_heading  el_before_av_textblock '><span class='hr-inner ' ><span class='hr-inner-style'><\/span><\/span><\/div>\n<section class=\"av_textblock_section \" ><div class='avia_textblock  '  style='font-size:14px; ' ><h2 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">About ISO 27001 requirements<\/span><\/strong><\/h2>\n<p style=\"text-align: justify;\">Looking to obtain ISO 27001 certification but unsure exactly what is required? This guide explains the key documents and processes you will need to prepare your organization for certification.<\/p>\n<h3 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">About ISO 27001<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\"><span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c; text-decoration: underline;\"><a style=\"color: #b02b2c; text-decoration: underline;\" href=\"https:\/\/ias-certification.com\/ca\/blog\/iso-27001-standard\/\">ISO\/IEC 27001<\/a> <\/span><\/strong><\/span>&#8211; currently the 2022 edition &#8211; is the international standard for an information security management system (ISMS) and its continual improvement. It sets out control mechanisms organizations can use to protect their customers&#8217; and clients&#8217; personal information from security risks and attacks. Implementing it builds customer confidence in your operations and security.<\/p>\n<h2><img decoding=\"async\" class=\"aligncenter wp-image-4434 lazyload\" title=\"ISO 27001 requirements\" data-src=\"https:\/\/ias-certification.com\/ca\/wp-content\/uploads\/2021\/10\/27001-requirements.png\" alt=\"ISO 27001 requirements\" width=\"223\" height=\"181\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 223px; --smush-placeholder-aspect-ratio: 223\/181;\" \/><\/h2>\n<h3 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">ISO 27001 documentation<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">ISO 27001 does not impose a single, one-size-fits-all security approach, because every organization faces unique information security concerns. Instead, the standard requires you to develop the processes and policies that suit your context &#8211; and by demonstrating these, you show successful implementation. The key documents include the following.<\/p>\n<h3 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">Scope of the ISMS<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">This document outlines the operations the <span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c;\"><a style=\"color: #b02b2c; text-decoration: underline;\" href=\"https:\/\/ias-certification.com\/ca\/iso-27001-training-in-canada\/\">Information Security Management System (ISMS)<\/a><\/span><\/strong><\/span> will cover and the boundaries that apply. It describes the products and services your company offers and where (regionally, across Canada, across North America, or worldwide), and specifies which parts of the organization &#8211; processes, locations, departments, and divisions &#8211; are within the ISMS.<\/p>\n<p style=\"text-align: justify;\"><strong>Information Security Policy and objectives: <\/strong>A statement that your organization&#8217;s objective is to handle data securely, in line with applicable laws and ethical obligations, and with a commitment to continual improvement.<\/p>\n<p style=\"text-align: justify;\"><strong>Risk assessment and treatment methodology: <\/strong>How you identify information security risks and how you plan to mitigate and resolve them when they arise.<\/p>\n<h3 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">Statement of Applicability (SoA)<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">The Statement of Applicability explains which of the 93 information security controls in Annex A of ISO\/IEC 27001:2022 you apply, and why. (The 2022 revision reorganized Annex A into 93 controls across four themes &#8211; Organizational, People, Physical, and Technological &#8211; replacing the 114 controls in 14 categories used by the 2013 version.) In the SoA you:<em>\u00a0<\/em><\/p>\n<ul style=\"text-align: justify;\">\n<li>Identify which controls apply to your organization<\/li>\n<li>State why they apply<\/li>\n<li>Describe how they have been implemented<\/li>\n<li>Justify why any controls were not selected (exclusions)<\/li>\n<\/ul>\n<h3 style=\"text-align: justify;\"><strong><span style=\"color: #b02b2c;\">Risk Treatment Plan<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">Once you have decided which controls to use, the Risk Treatment Plan sets out how you will put the relevant controls in place, who is responsible for implementation, what resources are needed, and how much time it will take.<\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>Roles and responsibilities: <\/strong>Defines the roles and responsibilities of each job involved in information security.<\/li>\n<li style=\"text-align: justify;\"><strong>Inventory of assets: <\/strong>Documents every asset used to store data &#8211; desktops, laptops, servers, phones, and tablets, as well as physical papers, financial data, email systems, and cloud services.<\/li>\n<li style=\"text-align: justify;\"><strong>Acceptable use of assets: <\/strong>Because these assets handle sensitive data, this defines how permanent and temporary staff and contractors may use them.<\/li>\n<li style=\"text-align: justify;\"><strong>Access control policy: <\/strong>Helps ensure sensitive information is only accessible to those who need it.<\/li>\n<li style=\"text-align: justify;\"><strong>IT management operating procedures: <\/strong>Documented procedures for areas where sensitive information is at risk from faulty IT use &#8211; identified by your risk assessments.<\/li>\n<li style=\"text-align: justify;\"><strong>Secure system engineering principles: <\/strong>How you apply security to new IT projects and existing infrastructure, including business continuity and disaster preparedness as well as firewalls and secure passwords.<\/li>\n<li style=\"text-align: justify;\"><strong>Supplier security policy: <\/strong>Sets security expectations for suppliers, so a supplier&#8217;s weaknesses do not expose your data to theft or loss.<\/li>\n<li style=\"text-align: justify;\"><strong>Incident management procedure: <\/strong>Documented protocols for how your organization responds to an information security breach.<\/li>\n<li style=\"text-align: justify;\"><strong>Business continuity procedures: <\/strong>Defined procedures so the organization can keep operating during a data security incident.<\/li>\n<li style=\"text-align: justify;\"><strong>Contractual, legal, and regulatory obligations: <\/strong>Documents the obligations that apply to how you manage information, and acts as a quick reference for staff.<\/li>\n<li style=\"text-align: justify;\"><strong>Training, skills, and qualification records: <\/strong>Shows that employees have the expertise to understand the requirements, and that your organization invests in ongoing training and development.<\/li>\n<li style=\"text-align: justify;\"><strong>Internal audit and outcomes: <\/strong>Internal audits assess the effectiveness of the ISMS and your information security performance, and help demonstrate compliance. Any non-conformities and the actions taken must be documented.<\/li>\n<\/ul>\n<h3 style=\"text-align: left;\"><strong><span style=\"color: #b02b2c;\">ISO 27001 and information security in Canada<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">In Canada, organizations have legal obligations to protect personal information &#8211; under the federal PIPEDA and provincial laws such as Quebec&#8217;s Law 25. ISO 27001 gives Canadian organizations a structured, internationally recognized way to demonstrate that they manage information security risk effectively, which supports these obligations and builds trust with customers and partners.<\/p>\n<h3 style=\"text-align: left;\"><strong><span style=\"color: #b02b2c;\">ISO 27001 certification<\/span><\/strong><\/h3>\n<p style=\"text-align: justify;\">You do not need every document above from day one &#8211; what matters most is the willingness to put these processes and policies in place to strengthen your information security. The path to <span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c;\"><a style=\"color: #b02b2c; text-decoration: underline;\" href=\"https:\/\/ias-certification.com\/ca\/iso-27001-certification-in-canada\/\">ISO 27001 certification<\/a><\/span><\/strong><\/span> begins with an external auditor from a certification body assessing your ISMS and identifying any gaps. You then make the necessary changes before the auditor returns for a second assessment to confirm they have been addressed. Once all requirements are met, your organization is awarded certification.<\/p>\n<p style=\"text-align: justify;\"><span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c;\"><a style=\"color: #b02b2c; text-decoration: underline;\" href=\"https:\/\/ias-certification.com\/ca\/contact-us\/\">Contact IAS<\/a><\/span><\/strong><\/span> today to learn more about ISO 27001, or visit our <a href=\"https:\/\/ias-certification.com\/ca\/frequently-asked-question-in-canada\/\"><span style=\"text-decoration: underline; color: #b02b2c;\"><strong>frequently asked questions<\/strong><\/span><\/a> page.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Explore Now<\/strong><\/h3>\n<ul>\n<li style=\"text-align: justify;\"><a href=\"https:\/\/ias-certification.com\/ca\/iso-27001-certification-in-canada\/\"><span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c; text-decoration: underline;\">ISO 27001 Certification in Canada<\/span><\/strong><\/span><\/a> &#8211; information security certification<\/li>\n<li style=\"text-align: justify;\"><a href=\"https:\/\/ias-certification.com\/ca\/iso-27001-training-in-canada\/\"><span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c; text-decoration: underline;\">ISO 27001 Training in Canada<\/span><\/strong><\/span><\/a> &#8211; lead auditor, internal auditor, and awareness courses<\/li>\n<li style=\"text-align: justify;\"><span style=\"text-decoration: underline;\"><strong><span style=\"color: #b02b2c;\"><a style=\"color: #b02b2c; text-decoration: underline;\" href=\"https:\/\/ias-certification.com\/ca\/vapt-certification-in-canada\/\">VAPT Certification in Canada<\/a><\/span><\/strong><\/span> &#8211; penetration testing that supports ISO 27001 controls<\/li>\n<\/ul>\n<\/div><\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":4434,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/posts\/4433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/comments?post=4433"}],"version-history":[{"count":10,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/posts\/4433\/revisions"}],"predecessor-version":[{"id":6017,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/posts\/4433\/revisions\/6017"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/media\/4434"}],"wp:attachment":[{"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/media?parent=4433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/categories?post=4433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ias-certification.com\/ca\/wp-json\/wp\/v2\/tags?post=4433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}