ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines requirements for establishing, implementing, maintaining, and continually improving a management system that protects the confidentiality, integrity, and availability of information through a risk-based process.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It specifies requirements an ISMS must meet to establish, implement, maintain, and continually improve a risk-based system that protects information. It is published jointly by ISO and the International Electrotechnical Commission (IEC), under the responsibility of ISO/IEC JTC 1/SC 27.
The standard applies to organizations of any size and from any sector. It does not tell you which safeguards to buy or install. Instead, it defines a management system that decides which information risks matter and how to treat them, then operates controls, reviews results, and improves. Conformity with ISO/IEC 27001 means an organization has put in place a system to manage risks related to the security of data it owns or handles, and that this system respects the principles and best practices the standard sets out.
The ISMS and its structure
An information security management system is the framework of policies, processes, procedures, roles, and controls an organization uses to manage information security. ISO/IEC 27001 organizes the requirements for that framework in ten clauses. Clauses 1 through 3 cover scope, normative references, and terms. Clauses 4 through 10 are the operational core:
- Context of the organization — determines the internal and external issues relevant to information security, the interested parties whose requirements matter, and the scope of the ISMS. Clause 4.4 requires establishing, implementing, maintaining, and continually improving the ISMS, including the processes needed and their interactions.
- Leadership — top management establishes the information security policy, assigns roles and responsibilities, and demonstrates commitment. Clause 5.1 includes a note that the term "business" can be interpreted broadly.
- Planning — the organization addresses risks and opportunities, sets information security objectives, and plans changes to the ISMS. Clause 6.3 requires that changes to the ISMS be carried out in a planned manner.
- Support — the organization provides the resources, competence, awareness, communication, and documented information the ISMS needs.
- Operation — the organization plans, implements, and controls the processes needed to meet information security requirements, including implementing the actions determined in Clause 6. Clause 8.1 requires establishing criteria for the processes and controlling them in accordance with those criteria.
- Performance evaluation — the organization monitors, measures, analyzes, and evaluates information security performance, conducts internal audits, and holds management reviews. Clause 9.2.2 requires an internal audit program; Clause 9.3 requires management review.
- Improvement — the organization continually improves the ISMS and handles nonconformities and corrective actions.
Risk-based management
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.iso.org/isoiec-27001-information-security.html
Supports
- ISMS definition, applicability to any size or sector, and risk-based management purpose
- Confidentiality, integrity, and availability principles
- Certification voluntary nature, accredited bodies, scope limits, and full reference convention
- ISO Survey 2022 adoption figures (over 70,000 certificates in 150 countries)
- Quiz answers and learner reference rationale
- https://www.iso.org/standard/82875.html
Supports
- Third edition publication date, edition number, and status
- Amendment 1 climate action changes and SME practical guide
- Timeline event for the 2022 third edition
- Learner reference rationale
- https://www.iso.org/standard/73906.html
Supports
- Family overview and vocabulary role of ISO/IEC 27000
- Ecosystem listing in intro
- Timeline event for the 2018 update
- Learner reference rationale
- https://www.iso.org/standard/75652.html
Supports
- Companion code of practice with implementation guidance for Annex A controls
- 93 controls in four themes and 2022 revision timeline event
- Learner reference rationale
- https://blog.ansi.org/anab/iso-iec-27001-2013-2022-comparison/
Supports
- Clause 6.1.3(d) Statement of Applicability contents
- 93 controls in four themes, 11 new controls, 56 consolidated into 24
- New requirements Clause 4.4 and Clause 6.3
- Annex A description as a list of possible controls that is not exhaustive
- Internal audit program (Clause 9.2) and management review (Clause 9.3)
- Risk treatment options and ISO 31000 alignment in Clause 6.1.3
- Quiz answers
- https://www.iso.org/standard/80585.html
Supports
- Risk management guidance standard in the family
- ISO 31000 alignment and 2022 revision timeline event
- Learner reference rationale
- https://www.iso.org/standard/82908.html
Supports
- Requirements for bodies that audit and certify ISMSs
- Ecosystem listing in intro
- Timeline event for the 2024 reissue
- Learner reference rationale
- https://www.iso.org/the-iso-survey.html
Supports
- Source of the reported certificate and country adoption figures cited by the ISO overview page
- https://shop.standards.ie/en-ie/standards/bs-7799-1-1995-208743_saig_bsi_bsi_494382/
Supports
- BS 7799-1:1995 publication by BSI and February 1995 date
- Timeline event for the British code of practice
- https://en.wikipedia.org/wiki/BS_7799
Supports
- BS 7799 origin, adoption as ISO/IEC 17799, and BS 7799-2 certification history
- Timeline events for the British code of practice
- https://www.iso.org/standard/33441.html
Supports
- ISO/IEC 17799:2000 first international edition and December 2000 date
- Timeline event for the first international code of practice
- https://www.iso.org/standard/39612.html
Supports
- ISO/IEC 17799:2005 revised edition and June 2005 date
- Timeline event for the 2005 revision
- https://www.iso.org/standard/42103.html
Supports
- ISO/IEC 27001:2005 first edition and October 2005 date
- Timeline event for the first requirements edition
- https://www.iso.org/standard/50297.html
Supports
- Renumbering of ISO/IEC 17799:2005 to ISO/IEC 27002:2005 in August 2007
- Timeline event for the renumbering
- https://www.iso.org/standard/54534.html
Supports
- ISO/IEC 27001:2013 second edition and October 2013 date
- Timeline event for the 2013 requirements edition
- https://www.iso.org/standard/54533.html
Supports
- ISO/IEC 27002:2013 second edition and October 2013 date
- 114-control reference count in the 2013 edition
- Timeline event for the 2013 controls edition
- https://www.iso.org/standard/88435.html
Supports
- Amendment 1 climate action changes, publication date, and application to ISO/IEC 27001:2022
- Timeline event for the 2024 amendment
- https://github.com/sindresorhus/awesome
Supports
- Required discovery route to security and compliance awesome lists
- https://github.com/theopenlane/awesome-compliance
Supports
- Discovery of InSpec, OpenSCAP, Lynis, Wazuh, Compliance Trestle, Compliance Masonry, and Auditree
- https://www.inspec.io/
Supports
- InSpec compliance-as-code testing framework and Awesome Links rationale
- https://www.open-scap.org/
Supports
- OpenSCAP ecosystem implementing SCAP and Awesome Links rationale
- https://cisofy.com/lynis/
Supports
- Lynis host security auditing tool and Awesome Links rationale
- https://wazuh.com/
Supports
- Wazuh log collection, intrusion detection, and compliance reporting and Awesome Links rationale
- https://oscal-compass.dev/compliance-trestle/latest/
Supports
- Compliance Trestle OSCAL content management and Awesome Links rationale
- https://github.com/opencontrol/compliance-masonry
Supports
- Compliance Masonry documentation assembly approach and Awesome Links rationale
- https://github.com/ComplianceAsCode/auditree-framework
Supports
- Auditree checks-as-code evidence collection framework and Awesome Links rationale
- https://www.vanta.com/
Supports
- Vanta evidence collection and ISO/IEC 27001 program tracking placement
- https://drata.com/
Supports
- Drata control monitoring and evidence collection mapped to Annex A placement
- https://secureframe.com/
Supports
- Secureframe SoA-to-test evidence and remediation workflow placement
- https://www.thoropass.com/
Supports
- Thoropass evidence collection and internal audit support placement
- https://sprinto.com/
Supports
- Sprinto control mapping and evidence gathering placement
- https://www.scrut.io/
Supports
- Scrut control tracking, vendor risk, and audit evidence placement
- https://trustero.com/
Supports
- Trustero AI evidence gathering and readiness assessment placement
- https://www.apptega.com/
Supports
- Apptega control documentation and audit workflow placement
- https://www.onetrust.com/products/tech-risk-and-compliance/
Supports
- OneTrust Tech Risk and Compliance multi-framework mapping placement
- https://www.archerirm.com/
Supports
- Archer configurable risk and control system of record placement
- https://www.servicenow.com/products/integrated-risk-management.html
Supports
- ServiceNow Integrated Risk Management risk, control, and audit records placement
- https://www.auditboard.com/
Supports
- AuditBoard control mappings and internal audit program placement
- https://www.logicgate.com/
Supports
- LogicGate Risk Cloud configurable risk and control workflow placement
- https://hyperproof.io/
Supports
- Hyperproof control, evidence, and review cadence tracking placement
- https://www.eramba.org/
Supports
- Eramba open-source GRC and ISMS management placement
- https://github.com/intuitem/ciso-assistant-community
Supports
- CISO Assistant open-source risk and control mapping placement
- https://github.com/trycompai/comp
Supports
- Comp AI open-source compliance platform placement
- https://www.a-lign.com/
Supports
- A-LIGN certification body audit and certification services placement
