Skip to content
atlas

ISO 27001

Also known as: ISO/IEC 27001, ISMS standard

The international standard for running an information security management system that can be certified.

Draft - this entry has not been reviewed yet.

Read the full article →

Formal

An international standard, current edition 2022, whose clauses 4-10 set the requirements for an information security management system - context, leadership, planning, support, operation, performance evaluation and improvement - with Annex A listing 93 controls to choose from.

In plain English

A set of house rules for running security as a daily routine rather than a one-off clean-up - written so that an outside inspector can check it is really followed.

In practice

Danish state bodies must follow ISO 27001, so the security lead at a ministry uses its clauses to set the scope, run the risk assessment, pick controls from Annex A and report maturity each year - without seeking a certificate.

Why it matters

Without a common measure every customer, auditor and authority would ask for security to be shown in a different way; ISO 27001 gives one structure that can be recognised, audited and mapped to laws such as NIS2.

Technical deep dive

The normative core is clauses 4-10, written in the harmonized structure used by all ISO management system standards; clauses 0-3 are introduction, scope, normative reference (ISO/IEC 27000) and terms. Annex A is also normative, but its 93 controls only become obligations through clause 6.1.3: the organisation determines the controls needed to treat its assessed risks, compares them with Annex A to verify that nothing necessary has been omitted, and records the result in the Statement of Applicability. Annex A is explicitly not exhaustive, so controls from other sources (CIS Controls, sector rules, customer contracts) can and often should be added.

The 2022 revision changed more than the annex. Clause 4.2 now asks which interested-party requirements will be addressed through the ISMS, 4.4 refers to the processes and their interactions, 6.3 requires changes to the ISMS to be planned, 8.1 requires criteria for processes, and management review (9.3.2) must consider changes in the needs and expectations of interested parties. Amendment 1:2024 added to clause 4.1 that the organisation must determine whether climate change is a relevant issue, and a note to 4.2 that interested parties can have climate-related requirements. Under IAF MD 26, certificates against the 2013 edition had to be transitioned by 31 October 2025.

The standard demands specific documented information rather than a fixed document set: the scope, the policy, the risk assessment and treatment processes, the SoA, objectives, evidence of competence, operational planning records, risk assessment and treatment results, monitoring results, the audit programme and audit results, management review results, and records of nonconformities and corrective actions. Certification is carried out by bodies accredited under ISO/IEC 17021-1 and ISO/IEC 27006 (in Denmark by DANAK); the initial audit runs in two stages, and nonconformities are graded major or minor, with a major one blocking certification until it is corrected.

Frequent failure modes are over-narrow scopes, a risk method whose results cannot be reproduced, SoA exclusions justified with "not relevant" but no risk rationale, and internal audits performed by the people who run the controls, which undermines the objectivity required by 9.2. Compared with NIS2 the standard is voluntary and silent on legal deadlines such as the 24-hour early warning; compared with the NIST CSF it prescribes a management system rather than a catalogue of outcomes; and compared with ISO/IEC 27002 it states what must be done, while 27002 explains how each control can be implemented.

Relationships

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022 · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.