ISO 27001 is the international standard for building and certifying an Information Security Management System (ISMS) — a structured, ongoing program for managing information security risk, not a one-time technical checklist. It's jointly developed by ISO and IEC, and certification is issued by accredited third-party registrars.
What an ISMS actually is
An ISMS is the management system wrapped around security: risk assessment, policies, defined responsibilities, ongoing monitoring, and continual improvement. ISO 27001 certifies that this whole system exists and functions, not just that individual technical controls are in place. That's the key difference from a narrower technical audit.
Annex A controls
The current version of the standard organizes its reference controls — 93 in total — into four themes: organizational, people, physical, and technological. Examples range from access control and cryptography to supplier relationships and incident management. An organization doesn't have to implement every control; it runs a risk assessment and documents which controls actually apply in a Statement of Applicability, excluding the rest with justification.
The certification process
Certification happens in two stages: Stage 1 reviews whether the ISMS is designed correctly on paper (policies, scope, risk assessment); Stage 2 checks whether it's actually operating as designed, with real evidence. Once certified, the certificate is valid for three years, with annual surveillance audits in between to confirm the ISMS is still being maintained, not just built once and forgotten.
Where this shows up in GRC work
Most of the day-to-day work behind an ISO 27001 program is standard GRC work under a specific name: maintaining a risk register, running a policy gap analysis against Annex A, and collecting audit evidence ahead of the surveillance audits. See how ISO 27001 compares to SOC 2 if you're weighing which framework matters more for a given employer or industry.