What ISO 27001 is and who uses it
ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented, repeating way of deciding which security risks matter, dealing with them and checking that it works. The current edition is ISO/IEC 27001:2022 (with a small 2024 amendment adding climate change as something to consider in the organisation’s context). Certificates against the old 2013 edition had to be moved to the 2022 edition by 31 October 2025.
The standard is voluntary and fits any organisation of any size or sector. Companies adopt it for three reasons: customers demand a certificate (typical for IT and cloud suppliers), it gives a structure for meeting laws such as NIS2 and GDPR, or management simply wants security run as a routine rather than a series of projects. In Denmark, central government bodies have been required to work according to ISO 27001 since 2014, although they are not required to be certified.
ISO 27001 sits in a family: ISO 27002 gives guidance on each control, ISO 27005 covers information security risk management, and ISO 27701 adds privacy management on top.
The key requirements
Clauses 4-10: the management system
The mandatory part of the standard is clauses 4 to 10. They follow the same high-level structure as other ISO management standards (such as ISO 9001), and together they form a Plan-Do-Check-Act cycle.
| Clause | Topic | What it asks for |
|---|---|---|
| 4 | Context of the organisation | Internal and external issues, interested parties and their requirements, the scope of the ISMS |
| 5 | Leadership | Top-management commitment, an information security policy, roles and responsibilities |
| 6 | Planning | Risk assessment (6.1.2) and risk treatment (6.1.3), including the Statement of Applicability; security objectives; planned changes |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | Carry out the risk assessments and treatment plans in practice |
| 9 | Performance evaluation | Monitoring and measurement, internal audit (9.2), management review (9.3) |
| 10 | Improvement | Continual improvement, nonconformities and corrective action |
A certification auditor will look for evidence of each of these: the scope statement, the policy, the risk method and register, the risk treatment plan, audit reports, management review minutes and records of corrective actions.
Annex A: 93 controls in four themes
Annex A is a reference list of controls. The 2022 edition reorganised the old 114 controls in 14 domains into 93 controls in four themes:
| Theme | Number | Examples |
|---|---|---|
| 5 Organisational | 37 | Policies, asset inventory, access control, supplier relationships, incident management, cloud services, ICT readiness for business continuity, privacy of personal data |
| 6 People | 8 | Screening, terms of employment, awareness and training, remote working, reporting security events |
| 7 Physical | 14 | Secure areas, clear desk and screen, equipment protection, secure disposal |
| 8 Technological | 34 | Endpoint devices, privileged access, malware protection, vulnerability management, backup, logging, monitoring, secure development |
The 2022 edition also added eleven new controls, including threat intelligence, information security for cloud services, data leakage prevention, monitoring activities and secure coding.
The Statement of Applicability
The Statement of Applicability (SoA) is the bridge between risk assessment and Annex A. For every one of the 93 controls it states whether the control is included, why (the risk, a law, a contract), whether it is implemented, and - if it is excluded - why. The SoA is one of the first documents an auditor asks for, and it is a very useful overview for management.
Certification
Certification is done by an accredited certification body (in Denmark accredited by DANAK). The initial audit has two stages - a documentation review and an on-site audit of how the system works in practice. A certificate is valid for three years, with surveillance audits in the years between and a recertification audit at the end.
How ISO 27001 connects to the other frameworks
- NIS2 is law; ISO 27001 is a way to meet it. The risk-based approach, policies, supplier controls, incident management and management review map closely onto NIS2 Articles 20 and 21. What ISO does not give you is the NIS2 reporting deadlines, the national registration duty or a guarantee that your certificate’s scope covers the services the law cares about.
- GDPR Article 32 asks for “appropriate” security; an ISMS is a well-recognised way to show that. ISO 27701 extends it with privacy-specific requirements.
- CIS Controls are more concrete and prioritised. Many organisations use the ISMS as the governance frame and the CIS Controls as the technical to-do list behind the Annex A technological controls.
- D-mærket is lighter and aimed at Danish businesses; it can be a step on the way for a company that is not ready for full ISO 27001.
What a coordinator actually does with it
- Keeps the ISMS running: the risk register, the SoA, the policy set and the document control.
- Plans the annual cycle: risk review, internal audit, management review, awareness activities and supplier follow-up, each with a date and an owner.
- Collects evidence: training records, access reviews, backup tests, incident logs - the auditor wants to see that controls work, not only that they are described.
- Follows up on nonconformities from audits with root-cause analysis and corrective actions.
- Translates between management (risk, cost, customer demands) and IT operations (concrete controls).
Common misunderstandings
- “We must implement all 93 controls.” No. You select controls based on your risk assessment and justify inclusions and exclusions in the SoA. What you must meet are clauses 4-10.
- “Certification means we are secure.” It means the management system works within its scope. A narrow scope or a weak risk assessment can hide real gaps.
- “ISO 27001 is an IT standard.” Leadership, people, suppliers and physical security are as central as technology.
- “Once certified, we are done.” The standard is built around continual improvement; surveillance audits check exactly that.
- “ISO 27002 is the one you certify against.” You certify against 27001; 27002 is guidance on how to implement the controls.