ISO 27001

The anchor standard for information security: an auditable management system, not a checklist.

Universal core · ISO/IEC 27001:2022, Information security management systems

Issued by

ISO/IEC

Region

International

Effective

First published 2005; current edition 2022

Oversight

Certified by accredited bodies on a three-year cycle

Applies when

Any organisation running or certifying an information-security programme

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

ISO 27001 defines what a defensible information-security management system looks like: leadership that owns risk, a documented risk assessment and treatment plan, a Statement of Applicability over the Annex A controls, and a cycle of internal audit and improvement that proves the system is alive.

It is the standard most security programmes anchor on, and the one most other frameworks cross-map to. Done well, it becomes the backbone that SOC 2, NIST CSF and the local regimes all draw evidence from.

Where programmes are tested.

01

A management system, clauses 4 to 10

Scope, leadership, planning, support, operation, performance evaluation and improvement, the ISMS itself, not just controls.

02

Risk assessment and treatment

A documented method, a risk register with owners, and treatment decisions traceable to the controls that implement them.

03

The Annex A control set

93 controls across organisational, people, physical and technological themes, selected and justified through a Statement of Applicability.

04

Internal audit and improvement

Evidence that the system is exercised: audits, management review, nonconformities tracked to closure.

Curated once, evidenced continuously.

  • Annex A and clauses 4 to 10 are curated as requirements in the catalog, cross-mapped to the shared control library.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

ISO 27001, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Is ISO 27001 certification mandatory?

No law makes it mandatory in general, but the market often does: enterprise customers, partners and some regulators expect it, and security questionnaires assume it. For many organisations certification is the cheapest way to stop answering the same two hundred questions one buyer at a time.

What changed in ISO 27001:2022?

Annex A was restructured from 114 controls in 14 domains to 93 controls in four themes (organisational, people, physical, technological), with new controls for threat intelligence, cloud security and data leakage prevention. Certified organisations had to transition from the 2013 edition by late 2025.

How many controls does ISO 27001 have?

93 Annex A controls in the 2022 edition, selected and justified through a Statement of Applicability, plus the management-system requirements of clauses 4 to 10. You do not have to implement every control; you have to justify every exclusion.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is a certifiable management-system standard with an international accreditation scheme; SOC 2 is an attestation report written by a CPA firm against the AICPA Trust Services Criteria. Buyers in Europe and internationally tend to ask for ISO 27001, US enterprise buyers for SOC 2, and the underlying controls overlap heavily, which is why cross-mapping them pays.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.