openskills.info
ISO/IEC 27001 logoCourse Preview

ISO/IEC 27001

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines requirements for establishing, implementing, maintaining, and continually improving a management system that protects the confidentiality, integrity, and availability of information through a risk-based process.

itCybersecurity fundamentals and governance

Don't Panic - ISO/IEC 27001

ISO/IEC 27001 is the international requirements standard for an information security management system, or ISMS. It is published jointly by ISO and IEC under JTC 1/SC 27. It does not prescribe which products to buy. It requires a management system that decides which information risks matter, treats them, operates controls, reviews results, and improves. Conformity means that system exists and respects the standard's principles, not that every asset is permanently safe.

Clauses 4 through 10 are the operational core: context and scope, leadership, planning, support, operation, performance evaluation, and improvement. Risk assessment and treatment feed the Statement of Applicability, which lists necessary controls, justifies inclusions and exclusions, and records whether each necessary control is implemented. Treatment options include applying controls, accepting residual risk within policy, avoiding the activity, or transferring risk. The SoA is the documented link from risk decisions to the control set.

Annex A of the 2022 edition lists 93 controls in organizational, people, physical, and technological themes. Every Annex A control must be addressed in the SoA, either applied with justification or excluded with justification. Controls need owners, implementations, and evidence such as policies, logs, restore tests, and review records. Certification is voluntary and scoped: a certificate asserts conformity of the ISMS within that scope, not the absence of incidents. A narrow scope can hide assets the business still depends on.

The recurring loop is assess, treat, operate, measure, audit, review, and correct. Management review is where leadership examines performance and decides what to change. Skip evidence or those decisions and the documents stop being an ISMS, regardless of how complete the policies look on paper.

Read the Intro for the clause map and SoA rules. Use the Cheatsheet when you need the risk-treatment options and Annex A themes. Landscape and Timeline place the standard among related frameworks; Updates tracks the standards-body page for edition status.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources