What Is ISO 27001?

ISO 27001 is the international standard for building and certifying an Information Security Management System (ISMS) — a structured, ongoing program for managing information security risk, not a one-time technical checklist. It's jointly developed by ISO and IEC, and certification is issued by accredited third-party registrars.

What an ISMS actually is

An ISMS is the management system wrapped around security: risk assessment, policies, defined responsibilities, ongoing monitoring, and continual improvement. ISO 27001 certifies that this whole system exists and functions, not just that individual technical controls are in place. That's the key difference from a narrower technical audit.

Annex A controls

The current version of the standard organizes its reference controls — 93 in total — into four themes: organizational, people, physical, and technological. Examples range from access control and cryptography to supplier relationships and incident management. An organization doesn't have to implement every control; it runs a risk assessment and documents which controls actually apply in a Statement of Applicability, excluding the rest with justification.

The certification process

Certification happens in two stages: Stage 1 reviews whether the ISMS is designed correctly on paper (policies, scope, risk assessment); Stage 2 checks whether it's actually operating as designed, with real evidence. Once certified, the certificate is valid for three years, with annual surveillance audits in between to confirm the ISMS is still being maintained, not just built once and forgotten.

Where this shows up in GRC work

Most of the day-to-day work behind an ISO 27001 program is standard GRC work under a specific name: maintaining a risk register, running a policy gap analysis against Annex A, and collecting audit evidence ahead of the surveillance audits. See how ISO 27001 compares to SOC 2 if you're weighing which framework matters more for a given employer or industry.

Common Questions

Does every organization need to implement all 93 Annex A controls?

No. Organizations perform a risk assessment and a Statement of Applicability, selecting only the controls relevant to their actual risks. A control can be formally excluded if it genuinely doesn't apply, as long as that decision is documented and justified.

How long does ISO 27001 certification last?

Three years, with annual surveillance audits by the certification body to confirm the ISMS is still being maintained. A full recertification audit happens at the end of the three-year cycle.

Is ISO 27001 only for large companies?

No — the framework scales down to small organizations too, though the amount of documentation and control implementation is naturally lighter for a smaller, simpler environment. It's increasingly requested of vendors of all sizes as a baseline trust signal.

Want hands-on practice with these controls?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is GRC?

Governance, Risk, and Compliance, explained from the ground up.