ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines requirements for establishing, implementing, maintaining, and continually improving a management system that protects the confidentiality, integrity, and availability of information through a risk-based process.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - ISO/IEC 27001
ISO/IEC 27001 is the international requirements standard for an information security management system, or ISMS. It is published jointly by ISO and IEC under JTC 1/SC 27. It does not prescribe which products to buy. It requires a management system that decides which information risks matter, treats them, operates controls, reviews results, and improves. Conformity means that system exists and respects the standard's principles, not that every asset is permanently safe.
Clauses 4 through 10 are the operational core: context and scope, leadership, planning, support, operation, performance evaluation, and improvement. Risk assessment and treatment feed the Statement of Applicability, which lists necessary controls, justifies inclusions and exclusions, and records whether each necessary control is implemented. Treatment options include applying controls, accepting residual risk within policy, avoiding the activity, or transferring risk. The SoA is the documented link from risk decisions to the control set.
Annex A of the 2022 edition lists 93 controls in organizational, people, physical, and technological themes. Every Annex A control must be addressed in the SoA, either applied with justification or excluded with justification. Controls need owners, implementations, and evidence such as policies, logs, restore tests, and review records. Certification is voluntary and scoped: a certificate asserts conformity of the ISMS within that scope, not the absence of incidents. A narrow scope can hide assets the business still depends on.
The recurring loop is assess, treat, operate, measure, audit, review, and correct. Management review is where leadership examines performance and decides what to change. Skip evidence or those decisions and the documents stop being an ISMS, regardless of how complete the policies look on paper.
Read the Intro for the clause map and SoA rules. Use the Cheatsheet when you need the risk-treatment options and Annex A themes. Landscape and Timeline place the standard among related frameworks; Updates tracks the standards-body page for edition status.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.iso.org/isoiec-27001-information-security.html
Supports
- ISMS definition, applicability to any size or sector, and risk-based management purpose
- Confidentiality, integrity, and availability principles
- Certification voluntary nature, accredited bodies, scope limits, and full reference convention
- ISO Survey 2022 adoption figures (over 70,000 certificates in 150 countries)
- Quiz answers and learner reference rationale
- https://www.iso.org/standard/82875.html
Supports
- Third edition publication date, edition number, and status
- Amendment 1 climate action changes and SME practical guide
- Timeline event for the 2022 third edition
- Learner reference rationale
- https://www.iso.org/standard/73906.html
Supports
- Family overview and vocabulary role of ISO/IEC 27000
- Ecosystem listing in intro
- Timeline event for the 2018 update
- Learner reference rationale
- https://www.iso.org/standard/75652.html
Supports
- Companion code of practice with implementation guidance for Annex A controls
- 93 controls in four themes and 2022 revision timeline event
- Learner reference rationale
- https://blog.ansi.org/anab/iso-iec-27001-2013-2022-comparison/
Supports
- Clause 6.1.3(d) Statement of Applicability contents
- 93 controls in four themes, 11 new controls, 56 consolidated into 24
- New requirements Clause 4.4 and Clause 6.3
- Annex A description as a list of possible controls that is not exhaustive
- Internal audit program (Clause 9.2) and management review (Clause 9.3)
- Risk treatment options and ISO 31000 alignment in Clause 6.1.3
- Quiz answers
- https://www.iso.org/standard/80585.html
Supports
- Risk management guidance standard in the family
- ISO 31000 alignment and 2022 revision timeline event
- Learner reference rationale
- https://www.iso.org/standard/82908.html
Supports
- Requirements for bodies that audit and certify ISMSs
- Ecosystem listing in intro
- Timeline event for the 2024 reissue
- Learner reference rationale
- https://www.iso.org/the-iso-survey.html
Supports
- Source of the reported certificate and country adoption figures cited by the ISO overview page
- https://shop.standards.ie/en-ie/standards/bs-7799-1-1995-208743_saig_bsi_bsi_494382/
Supports
- BS 7799-1:1995 publication by BSI and February 1995 date
- Timeline event for the British code of practice
- https://en.wikipedia.org/wiki/BS_7799
Supports
- BS 7799 origin, adoption as ISO/IEC 17799, and BS 7799-2 certification history
- Timeline events for the British code of practice
- https://www.iso.org/standard/33441.html
Supports
- ISO/IEC 17799:2000 first international edition and December 2000 date
- Timeline event for the first international code of practice
- https://www.iso.org/standard/39612.html
Supports
- ISO/IEC 17799:2005 revised edition and June 2005 date
- Timeline event for the 2005 revision
- https://www.iso.org/standard/42103.html
Supports
- ISO/IEC 27001:2005 first edition and October 2005 date
- Timeline event for the first requirements edition
- https://www.iso.org/standard/50297.html
Supports
- Renumbering of ISO/IEC 17799:2005 to ISO/IEC 27002:2005 in August 2007
- Timeline event for the renumbering
- https://www.iso.org/standard/54534.html
Supports
- ISO/IEC 27001:2013 second edition and October 2013 date
- Timeline event for the 2013 requirements edition
- https://www.iso.org/standard/54533.html
Supports
- ISO/IEC 27002:2013 second edition and October 2013 date
- 114-control reference count in the 2013 edition
- Timeline event for the 2013 controls edition
- https://www.iso.org/standard/88435.html
Supports
- Amendment 1 climate action changes, publication date, and application to ISO/IEC 27001:2022
- Timeline event for the 2024 amendment
- https://github.com/sindresorhus/awesome
Supports
- Required discovery route to security and compliance awesome lists
- https://github.com/theopenlane/awesome-compliance
Supports
- Discovery of InSpec, OpenSCAP, Lynis, Wazuh, Compliance Trestle, Compliance Masonry, and Auditree
- https://www.inspec.io/
Supports
- InSpec compliance-as-code testing framework and Awesome Links rationale
- https://www.open-scap.org/
Supports
- OpenSCAP ecosystem implementing SCAP and Awesome Links rationale
- https://cisofy.com/lynis/
Supports
- Lynis host security auditing tool and Awesome Links rationale
- https://wazuh.com/
Supports
- Wazuh log collection, intrusion detection, and compliance reporting and Awesome Links rationale
- https://oscal-compass.dev/compliance-trestle/latest/
Supports
- Compliance Trestle OSCAL content management and Awesome Links rationale
- https://github.com/opencontrol/compliance-masonry
Supports
- Compliance Masonry documentation assembly approach and Awesome Links rationale
- https://github.com/ComplianceAsCode/auditree-framework
Supports
- Auditree checks-as-code evidence collection framework and Awesome Links rationale
- https://www.vanta.com/
Supports
- Vanta evidence collection and ISO/IEC 27001 program tracking placement
- https://drata.com/
Supports
- Drata control monitoring and evidence collection mapped to Annex A placement
- https://secureframe.com/
Supports
- Secureframe SoA-to-test evidence and remediation workflow placement
- https://www.thoropass.com/
Supports
- Thoropass evidence collection and internal audit support placement
- https://sprinto.com/
Supports
- Sprinto control mapping and evidence gathering placement
- https://www.scrut.io/
Supports
- Scrut control tracking, vendor risk, and audit evidence placement
- https://trustero.com/
Supports
- Trustero AI evidence gathering and readiness assessment placement
- https://www.apptega.com/
Supports
- Apptega control documentation and audit workflow placement
- https://www.onetrust.com/products/tech-risk-and-compliance/
Supports
- OneTrust Tech Risk and Compliance multi-framework mapping placement
- https://www.archerirm.com/
Supports
- Archer configurable risk and control system of record placement
- https://www.servicenow.com/products/integrated-risk-management.html
Supports
- ServiceNow Integrated Risk Management risk, control, and audit records placement
- https://www.auditboard.com/
Supports
- AuditBoard control mappings and internal audit program placement
- https://www.logicgate.com/
Supports
- LogicGate Risk Cloud configurable risk and control workflow placement
- https://hyperproof.io/
Supports
- Hyperproof control, evidence, and review cadence tracking placement
- https://www.eramba.org/
Supports
- Eramba open-source GRC and ISMS management placement
- https://github.com/intuitem/ciso-assistant-community
Supports
- CISO Assistant open-source risk and control mapping placement
- https://github.com/trycompai/comp
Supports
- Comp AI open-source compliance platform placement
- https://www.a-lign.com/
Supports
- A-LIGN certification body audit and certification services placement
