Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Security Frameworks

ISO/IEC 27001

Also known as: ISO 27001, ISO/IEC 27001:2022
Simply put

ISO/IEC 27001 is an internationally recognized standard that sets out requirements for an information security management system (ISMS)—the policies, processes, and controls an organization uses to manage its information security risks. It is a voluntary standard rather than a law, though organizations may adopt it to demonstrate a structured approach to protecting information. Organizations can pursue independent certification against it, but doing so is optional unless required by contract or another obligation.

Formal definition

ISO/IEC 27001 is a jointly published international standard specifying requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of an organization. It defines a risk-based framework for bringing information security under explicit management control, encompassing management responsibilities, risk assessment and treatment, and the selection of applicable controls. It is a voluntary, certifiable standard—distinct from binding regulation—and conformity may be verified through third-party certification by an accredited body; certification attests to the ISMS meeting the standard's requirements at the time of audit and is not equivalent to legal compliance. The standard is periodically revised (the current revision commonly cited is the 2022 edition, superseding the 2013 edition), and readers should confirm the applicable version and requirements against the current official ISO text, as details of the standard and associated certification schemes change over time.

Why it matters

Information security risk is pervasive and difficult to manage consistently without a structured, repeatable approach. ISO/IEC 27001 matters because it provides an internationally recognized framework for bringing information security under explicit management control, rather than treating security as a collection of ad hoc technical measures. By defining requirements for an information security management system (ISMS), the standard gives organizations a common reference point for establishing, implementing, maintaining, and continually improving how they identify and treat information security risks.

As the world's best-known standard for information security management systems, ISO/IEC 27001 also carries significant weight in commercial and contractual settings. Organizations frequently ask vendors, service providers, and partners to demonstrate a mature security posture, and certification against the standard by an accredited third party offers a widely understood signal that an ISMS meets the standard's requirements at the time of audit. This can streamline procurement, due diligence, and supply-chain assurance where security expectations must be evidenced.

It is important to keep the standard's role in perspective. ISO/IEC 27001 is voluntary and certifiable—it is not a law, and certification is not equivalent to legal compliance. An organization may adopt it to demonstrate a disciplined approach to security, but obligations under specific regulations remain separate and must be assessed independently. Where certification is pursued, it attests to conformity at a point in time, not to permanent or absolute security.

Who it's relevant to

Information security professionals
Those responsible for designing and running security programs use ISO/IEC 27001 as a framework for structuring an ISMS, defining risk assessment and treatment processes, and selecting appropriate controls. The standard helps them move from ad hoc measures toward a governed, continually improving system, though its requirements must be tailored to the organization's own context and risk profile.
Compliance and risk officers
Compliance and risk functions may look to the standard to demonstrate a structured approach to managing information security risk. They should be careful to distinguish conformity with a voluntary standard from legal compliance, since certification attests to the ISMS meeting the standard's requirements at a point in time and is not equivalent to satisfying regulatory obligations, which must be assessed separately.
Auditors and certification bodies
Accredited third-party bodies assess an organization's ISMS against the standard's requirements and issue certification where conformity is established. Internal auditors also use the standard to evaluate the maturity and effectiveness of an ISMS. Both should confirm which edition applies, as the standard is periodically revised and certification schemes change over time.
Vendors and organizations in supply chains
Service providers and vendors frequently pursue certification because customers and partners request evidence of a mature security posture during procurement and due diligence. For these organizations, certification can serve as a widely recognized signal of a structured approach to information security, but it should be understood as one point-in-time attestation rather than a guarantee of ongoing security or legal compliance.

Inside ISO/IEC 27001

Information Security Management System (ISMS)
The central concept of the standard: a systematic, risk-based framework of policies, processes, and controls for managing information security. ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS rather than prescribing a fixed set of technical measures.
Management system clauses
The main body of the standard sets out requirements covering areas such as organizational context, leadership commitment, planning, support and resources, operation, performance evaluation, and continual improvement. These are the elements against which conformity is assessed.
Risk assessment and risk treatment
A core requirement is that the organization identify information security risks and determine how to treat them. Control selection is expected to be driven by this risk process, so the applicable controls vary according to each organization's context and risk profile.
Statement of Applicability (SoA)
A document in which the organization records which controls it has selected, justifies inclusions and exclusions, and links them to identified risks. It serves as a bridge between the risk treatment decisions and the reference set of controls.
Annex A controls
A reference set of information security controls that organizations consider during risk treatment. Organizations select controls relevant to their risks rather than being required to implement all of them; the specific controls listed depend on the version of the standard in force.
Certification versus the standard itself
ISO/IEC 27001 is a voluntary standard, not a law. Accredited third-party certification bodies may certify an organization's ISMS against it, but certification is a separate activity from the standard's requirements and is not mandated except where imposed by contract or a specific sector obligation.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27001.

Is ISO/IEC 27001 a law that organizations are legally required to comply with?
No. ISO/IEC 27001 is a voluntary international standard, not a law or regulation. It carries no legal force in itself and does not impose statutory obligations. It may become effectively mandatory only where a contract, customer, or sector-specific requirement stipulates it, or where a regulation or regulator references it as an accepted means of demonstrating certain controls. Even in those cases, the binding obligation flows from the contract or law, not from the standard itself. Application to your circumstances depends on your contractual and regulatory context and warrants professional judgment.
Does being certified to ISO/IEC 27001 mean an organization is compliant with data protection regulations such as the GDPR?
No. Certification to ISO/IEC 27001 and regulatory compliance are distinct. The standard addresses the establishment and operation of an information security management system, which concerns security broadly rather than the specific legal obligations of any data protection regime. Certification may support and provide evidence toward certain security-related requirements, but it does not by itself establish compliance with the GDPR or any other regulation, which impose obligations the standard does not fully address. Readers should verify how the standard maps to their applicable legal requirements against current authoritative sources.
What is the difference between certification and simply aligning with ISO/IEC 27001?
An organization can align its practices with ISO/IEC 27001 without pursuing formal certification. Certification is a separate step in which an accredited certification body conducts an audit and issues a certificate attesting conformity. Self-alignment or self-assessment against the standard does not carry the same third-party assurance. The choice generally depends on whether external parties require demonstrable, independently verified conformity or whether internal improvement is the primary goal. Certification scheme details and their versions change, so readers should confirm current requirements with accredited bodies.
How does an information security management system under ISO/IEC 27001 relate to the standard's controls?
The standard sets out requirements for a management system as its core, with a set of controls typically referenced in an annex and elaborated in a companion guidance standard. In most cases, organizations select and justify applicable controls based on a risk assessment rather than applying every control uniformly, documenting decisions in a statement of applicability. The management system requirements themselves are generally the auditable core, while control selection is risk-driven. Because the standard and its associated control set are periodically revised, verify which version and control catalogue currently apply.
What role does risk assessment play in implementing ISO/IEC 27001?
Risk assessment generally functions as a central input to the management system, informing which controls are selected, how they are prioritized, and how their effectiveness is monitored. The standard typically expects organizations to establish a repeatable method for identifying, analyzing, and treating information security risks. The scope, methodology, and depth appropriate to any given organization depend on its size, sector, and risk profile, so implementation details vary. This description is qualitative; consult the current authoritative text for the specific requirements.
Once certified, does an organization's certification remain valid indefinitely?
No. Certification is generally issued for a defined period and is typically subject to ongoing surveillance activities and periodic recertification by the certification body, rather than being permanent. Maintaining certification usually depends on continued operation and improvement of the management system. Certification schemes, their cycles, and the underlying standard's versions change over time, so organizations should confirm the current validity terms, surveillance requirements, and applicable version with their accredited certification body.

Common misconceptions

ISO/IEC 27001 is a legal requirement that organizations must comply with.
It is a voluntary, internationally recognized standard, not binding law. It generally acquires obligatory force only where a contract, customer requirement, or a specific regulatory or sectoral arrangement incorporates it. Organizations should verify whether any such obligation actually applies to them.
Being certified to ISO/IEC 27001 means an organization is fully secure or fully compliant with data protection laws.
Certification indicates that an ISMS was assessed as conforming to the standard's requirements at a point in time; it does not guarantee the absence of incidents, nor does it by itself demonstrate compliance with regulations such as data protection law. Security and legal compliance are distinct matters that a certificate does not automatically satisfy.
The standard tells you exactly which technical controls to deploy.
ISO/IEC 27001 is risk-based and specifies management system requirements rather than mandating a universal control set. Which controls an organization applies is expected to follow from its own risk assessment and be documented in the Statement of Applicability, so implementations legitimately differ across organizations.

Best practices

Anchor control selection in a documented risk assessment and treatment process, and keep the Statement of Applicability consistent with those decisions rather than adopting controls indiscriminately.
Treat the ISMS as an ongoing management system subject to continual improvement, not a one-time project, maintaining evidence of operation over time rather than only in preparation for an audit.
Distinguish clearly between conforming to the standard and holding accredited certification, and confirm whether certification is genuinely required by a contract or sector obligation before pursuing it.
Do not rely on ISO/IEC 27001 certification as evidence of compliance with data protection or other legal regimes; assess those obligations separately with appropriate professional input.
Verify which version of the standard and its reference controls currently applies, since the standard and its control set are periodically revised, and align implementation and audit scope accordingly.
Secure demonstrable leadership commitment and adequate resources, as these are explicit requirements of the management system clauses and are commonly scrutinized during assessment.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."