Skip to content

ISO 27001

ISO 27001 overview

ISO/IEC 27001 is the international standard for an information security management system: how an organisation decides which risks to treat, puts controls in place and keeps them working. This guide covers what it asks for, how certification works and what technical evidence can and cannot show.

Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.

At a glance

ItemDetail
StandardISO/IEC 27001:2022, the requirements for an information security management system (ISMS). Third edition, published in October 2022.
AmendmentAmendment 1:2024, Climate action changes, published in February 2024. Read it together with the 2022 text.
RequirementsClauses 4 to 10. An organisation that claims conformity has to meet all of them.
Annex AA reference list of 93 information security controls in four themes. You choose controls by risk and justify each decision in a Statement of Applicability.
GuidanceISO/IEC 27002:2022 explains each Annex A control and ISO/IEC 27005:2022 explains information security risk management. Both are guidance; certification is to ISO/IEC 27001 only.
CertificationOptional. Carried out by certification bodies, which can be accredited; ISO itself does not certify. A certificate runs on a three-year cycle with yearly surveillance audits.
Previous editionISO/IEC 27001:2013, now withdrawn. Accredited certificates to it expired or were withdrawn when the transition period ended on 31 October 2025.

What an ISMS is

An information security management system is the way an organisation runs information security as a managed activity rather than a collection of tools. It sets a scope, a policy and objectives, gives people roles, assesses information security risks, chooses and operates controls to treat them, measures whether they work, audits itself, and has management review the results and correct what falls short.

The point, in ISO's own description of the standard, is to protect the confidentiality, integrity and availability of information through a risk management process, and to show customers and other interested parties that those risks are being managed.

The standard applies to organisations of any size and in any sector. It does not tell you which technologies to use or how much security is enough. It tells you how to decide, and how to show that you decided and followed through.

Certification is a choice. Some organisations use the standard as a framework without certifying; others certify because customers, tenders or partners ask for a certificate.

Clauses 4 to 10

After a short introduction, clauses 1 to 3 set out the standard's scope, refer to ISO/IEC 27000 for vocabulary and define terms. Clauses 4 to 10 hold the requirements. They follow the harmonised structure ISO uses for its management system standards, so anyone who knows ISO 9001 or ISO 14001 will recognise the headings.

ClauseTitleWhat it covers
4Context of the organisationInternal and external issues, interested parties and their requirements, and the boundaries of the ISMS: its scope.
5LeadershipTop management's commitment, the information security policy, and who is responsible for what.
6PlanningThe risk assessment and risk treatment processes, the Statement of Applicability, security objectives and planned changes to the ISMS.
7SupportResources, competence, awareness, communication and control of documented information.
8OperationRunning the planned processes, carrying out risk assessments and putting the risk treatment plan into effect.
9Performance evaluationMonitoring and measurement, internal audit and management review.
10ImprovementContinual improvement, and dealing with nonconformities through corrective action.

The requirements guide takes each clause in turn, with the documents and records an auditor will expect to see.

Annex A at a glance

Annex A is a reference list of information security controls: a number, a short title and a one-line statement for each. ISO/IEC 27002:2022 gives the purpose of each control and guidance on implementing it. The 2022 edition has 93 controls in four themes.

ThemeSectionControlsExamples
OrganisationalA.537Information security policies, threat intelligence, asset inventory, access control, supplier relationships, incident management
PeopleA.68Screening, terms and conditions of employment, awareness and training, remote working
PhysicalA.714Physical entry, clear desk and clear screen, equipment siting and protection, secure disposal or re-use of equipment
TechnologicalA.834User endpoint devices, technical vulnerabilities, configuration management, logging, network security, cryptography, secure development

Annex A is not a list to implement in full. Clause 6.1.3 has you decide which controls your risk treatment needs, from any source, and then compare them with Annex A so that nothing necessary is missed. The Statement of Applicability records every Annex A control, whether it applies, whether it is in place, and why. The Annex A controls guide goes through the four themes.

The 2022 edition and Amendment 1

ISO/IEC 27001:2022 was published on 25 October 2022 and replaced the 2013 edition. The clauses changed little; most edits brought the text into line with the harmonised structure. The main changes were these.

  • Annex A was replaced to match ISO/IEC 27002:2022: 93 controls in four themes, where the 2013 edition had 114 controls in 14 groups. Eleven controls are new, among them threat intelligence, information security for use of cloud services, configuration management, data leakage prevention, monitoring activities and secure coding.
  • A new clause, 6.3 Planning of changes, asks that changes to the ISMS are made in a planned way.
  • Clause 4.2 now also asks which of the interested parties' requirements the ISMS will address.
  • Clause 8.1 now covers externally provided processes, products and services, in place of the narrower term outsourced processes.
  • Clauses 9.2 and 9.3 were divided into named subclauses, for the internal audit programme and for management review inputs and results.

The International Accreditation Forum (IAF) set a three-year transition in its mandatory document IAF MD 26. From 30 April 2024 certification bodies could carry out initial certification and recertification to the 2022 edition only, and every certificate to the 2013 edition expired or was withdrawn when the transition ended on 31 October 2025. A valid accredited certificate today is to the 2022 edition.

Amendment 1:2024

Amendment 1:2024, Climate action changes, was published in February 2024 as part of a change ISO made to many management system standards at once. It adds two things to clause 4: the organisation decides whether climate change is a relevant issue for its ISMS, and a note that interested parties can have requirements related to climate change. ISO and the IAF said in a joint communiqué that the intent of clauses 4.1 and 4.2 is unchanged; the addition makes sure climate change is considered rather than overlooked.

In practice, make the decision deliberately and keep a note of it, with your reasoning, alongside your analysis of context and interested parties, so you can show an auditor how you reached it.

How certification works

ISO writes the standard; it does not certify anyone and issues no certificates. Certification is carried out by certification bodies. A certification body can in turn be accredited: a national accreditation body, which in the UK is UKAS, assesses it against ISO/IEC 17021-1, the requirements for bodies that audit and certify management systems, and ISO/IEC 27006-1:2024, which adds the requirements specific to information security management systems.

Accreditation is not compulsory, but ISO notes that a certificate from an accredited body carries extra confidence, because an independent body has confirmed the certification body's competence. You can find accredited certification bodies, and check a certificate, through UKAS or through IAF CertSearch. Since 1 January 2026 the IAF's role has been taken over by the Global Accreditation Cooperation Incorporated (Global ACI); CertSearch continues.

The initial audit

  1. Stage 1. The auditor reviews your ISMS documentation and scope, checks your understanding of the requirements, collects what is needed to plan stage 2, and judges whether you are ready for it, including whether internal audits and management reviews are being planned and carried out. Concerns left unresolved can become nonconformities at stage 2.
  2. Stage 2. The auditor evaluates whether the ISMS is implemented and effective, usually at your premises: records, interviews, samples of controls in operation, monitoring results, internal audit and management review.
  3. Nonconformities. Before the certification body decides, major nonconformities must be corrected and their corrective actions verified; for minor ones it reviews and accepts your plan for corrective action.
  4. Decision. The certification body makes the certification decision and issues a certificate that states the scope of the ISMS and the edition of the standard.

The three-year cycle

WhenAuditWhat it does
StartInitial audit, stage 1 and stage 2Leads to the certification decision, which starts the three-year cycle.
First yearSurveillance auditNo later than 12 months after the certification decision. Not a full audit: it samples the ISMS and always looks at internal audit, management review and action on earlier nonconformities.
Second yearSurveillance auditAt least once in each calendar year that is not a recertification year, on the same basis.
Third yearRecertification auditBefore the certificate expires. Reviews the whole ISMS and its performance over the cycle; a successful recertification starts a new cycle.

Between audits the certificate depends on the ISMS continuing to run: risk assessments repeated, internal audits and management reviews held, nonconformities closed. A certification body suspends a certificate when, for example, the organisation stops meeting the requirements or does not allow surveillance or recertification audits to take place, and withdraws it if the problem is not resolved.

Where technical evidence helps

Most of ISO 27001 is organisational: decisions, ownership, processes and records. A small part of Annex A concerns technology that can be observed from outside, and there an automated external check gives you dated, repeatable evidence. Whether each item supports a control depends on the controls in your Statement of Applicability.

ISO 27001 evidence

Ironfang can check

  • TLS versions, cipher suites and certificates on public services, for cryptography in transit (A.8.24 Use of cryptography).
  • HTTP security headers, cookie attributes, DNSSEC and CAA records, as evidence of secure public configuration (A.8.9 Configuration management).
  • Software versions visible from outside and known end-of-life releases, as input to technical vulnerability management (A.8.8).
  • For a verified domain, whether databases, remote access and other services on a fixed list of ports answer from the internet (A.8.20 Networks security).
  • SPF, DKIM and DMARC for your domains, where your controls for information transfer cover email (A.5.14).
  • Subdomains in certificate transparency logs and dangling DNS records, to test your asset inventory against what is public (A.5.9).
  • A dated history of results and rechecks, usable as monitoring records for these measures (clause 9.1).

The organisation must establish

  • The ISMS scope, context and interested parties.
  • The information security policy, objectives and roles.
  • Risk criteria, the risk assessment, the risk treatment plan and risk owners' approval.
  • The Statement of Applicability and the reasoning behind every decision in it.
  • Competence, awareness and training records.
  • Internal audits, management reviews, nonconformities and corrective actions.
  • Every control that cannot be seen from the internet: people, suppliers, physical security, endpoints, internal networks and cloud accounts.

A clean result does not prove conformity with any control. An auditor will want to see how you use the results: who reviews findings, how fixes are prioritised against your risk criteria, and how exceptions are accepted. The External Security Check verifies a domain, reports each finding with evidence, severity and a fix, keeps the history, and can recheck verified domains on a schedule.

Where to start

  1. Decide why you are doing it and what the ISMS will cover: its scope.
  2. Set risk criteria, list your assets and interested parties and carry out a risk assessment.
  3. Decide on risk treatment and controls, and write the Statement of Applicability.
  4. Put the controls into operation and keep the records.
  5. Measure, run an internal audit and hold a management review: performance evaluation.
  6. Carry out a gap analysis and work through the checklist.
  7. Choose an accredited certification body and agree dates for stage 1.

Stage 2 tests whether the ISMS is working, not only whether it is written down, so allow time for at least one full round of risk assessment, internal audit and management review before it.

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.