ISO 27001

ISO 27001

ISO/IEC 27001 is the leading international standard for information security management. A company earns the certification by building an Information Security Management System (ISMS) that identifies risks, applies controls, and improves continuously, then passing an independent audit against the standard's requirements.

Security questionnaires ask dozens of variations on the same question: does this vendor manage risk systematically, or reactively? ISO 27001 answers that question with a single, internationally recognized certificate.

What is ISO 27001?

ISO/IEC 27001 is a standard published by the International Organization for Standardization that specifies requirements for an Information Security Management System, or ISMS. Rather than mandating specific technologies, it requires a company to systematically identify information security risks, select controls to address them, and review the program on an ongoing basis.

The current version of the standard (ISO/IEC 27001:2022) organizes its reference controls, listed in Annex A, into 93 controls across four themes: organizational, people, physical, and technological. A certified company doesn't need to implement every control; it documents which ones apply to its risk profile and justifies any exclusions.

Why ISO 27001 Matters

ISO 27001 is often the baseline enterprise buyers expect before evaluating anything else, especially for vendors operating across multiple countries where a US-centric report alone isn't sufficient.

  • Global recognition: accepted as a security baseline across most regions and industries, unlike region-specific frameworks
  • Systematic, not one-off: certification requires an ongoing management system, not a single hardening project
  • Auditable governance: the ISMS produces a documented risk register and control set that customers can request to review during due diligence

How ISO 27001 Works

  1. The company scopes its ISMS: which systems, teams, and data it covers
  2. It runs a risk assessment and selects Annex A controls that address the identified risks
  3. An accredited certification body conducts a two-stage initial audit
  4. Once certified, the company undergoes annual surveillance audits, typically covering the framework plus a rotating subset of controls
  5. Full recertification happens on a three-year cycle

Because ISO 27001 is a certification rather than a raw attestation report, companies can usually share the certificate itself without an NDA, even when the underlying audit evidence stays private.

ISO 27001 vs ISO 27701

ISO 27001 covers information security broadly. ISO 27701 extends that same management-system approach specifically to personal data privacy, adding controls a company can't get from ISO 27001 alone. A company typically needs ISO 27001 in place before it can add ISO 27701 on top of it.

Frequently Asked Questions

Is ISO 27001 the same as SOC 2?

No. SOC 2 Type II is a US-originated attestation report on selected Trust Services Criteria; ISO 27001 is an international certification of a company's overall security management system. They test different things and many vendors hold both.

How often does ISO 27001 certification need to be renewed?

On a three-year cycle, with annual surveillance audits in between to confirm the management system is still operating as certified.

Related Terms

The #1 AI Agent for all your customer service