Skip to content
atlas
← Back to the entry

What ISO 27001 is and who uses it

ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented, repeating way of deciding which security risks matter, dealing with them and checking that it works. The current edition is ISO/IEC 27001:2022 (with a small 2024 amendment adding climate change as something to consider in the organisation’s context). Certificates against the old 2013 edition had to be moved to the 2022 edition by 31 October 2025.

The standard is voluntary and fits any organisation of any size or sector. Companies adopt it for three reasons: customers demand a certificate (typical for IT and cloud suppliers), it gives a structure for meeting laws such as NIS2 and GDPR, or management simply wants security run as a routine rather than a series of projects. In Denmark, central government bodies have been required to work according to ISO 27001 since 2014, although they are not required to be certified.

ISO 27001 sits in a family: ISO 27002 gives guidance on each control, ISO 27005 covers information security risk management, and ISO 27701 adds privacy management on top.

The key requirements

Clauses 4-10: the management system

The mandatory part of the standard is clauses 4 to 10. They follow the same high-level structure as other ISO management standards (such as ISO 9001), and together they form a Plan-Do-Check-Act cycle.

Clause Topic What it asks for
4 Context of the organisation Internal and external issues, interested parties and their requirements, the scope of the ISMS
5 Leadership Top-management commitment, an information security policy, roles and responsibilities
6 Planning Risk assessment (6.1.2) and risk treatment (6.1.3), including the Statement of Applicability; security objectives; planned changes
7 Support Resources, competence, awareness, communication, documented information
8 Operation Carry out the risk assessments and treatment plans in practice
9 Performance evaluation Monitoring and measurement, internal audit (9.2), management review (9.3)
10 Improvement Continual improvement, nonconformities and corrective action

A certification auditor will look for evidence of each of these: the scope statement, the policy, the risk method and register, the risk treatment plan, audit reports, management review minutes and records of corrective actions.

Annex A: 93 controls in four themes

Annex A is a reference list of controls. The 2022 edition reorganised the old 114 controls in 14 domains into 93 controls in four themes:

Theme Number Examples
5 Organisational 37 Policies, asset inventory, access control, supplier relationships, incident management, cloud services, ICT readiness for business continuity, privacy of personal data
6 People 8 Screening, terms of employment, awareness and training, remote working, reporting security events
7 Physical 14 Secure areas, clear desk and screen, equipment protection, secure disposal
8 Technological 34 Endpoint devices, privileged access, malware protection, vulnerability management, backup, logging, monitoring, secure development

The 2022 edition also added eleven new controls, including threat intelligence, information security for cloud services, data leakage prevention, monitoring activities and secure coding.

The Statement of Applicability

The Statement of Applicability (SoA) is the bridge between risk assessment and Annex A. For every one of the 93 controls it states whether the control is included, why (the risk, a law, a contract), whether it is implemented, and - if it is excluded - why. The SoA is one of the first documents an auditor asks for, and it is a very useful overview for management.

Certification

Certification is done by an accredited certification body (in Denmark accredited by DANAK). The initial audit has two stages - a documentation review and an on-site audit of how the system works in practice. A certificate is valid for three years, with surveillance audits in the years between and a recertification audit at the end.

How ISO 27001 connects to the other frameworks

What a coordinator actually does with it

Common misunderstandings

Atlas is in beta.