DefinitionISO/IEC 27001 is the international standard that sets out the requirements to establish, implement, maintain and continually improve an information security management system (ISMS). It is the main certifiable reference in information security; the current version is ISO/IEC 27001:2022.
How it works
The standard does not prescribe a fixed list of technologies. It requires a management system: the organization defines the scope, assesses its information security risks, decides how to treat them and keeps a cycle of monitoring, internal audit, management review and continual improvement. The mandatory requirements are in clauses 4 to 10.
Annex A provides a reference list of controls. In the 2022 version, there are 93 controls organized into four themes: organizational, people, physical and technological. The organization records in the Statement of Applicability (SoA) which controls it applies and why, always based on the risk assessment.
ISO 27001 vs ISO 27002
- ISO/IEC 27001: sets requirements and is the standard against which the organization is certified.
- ISO/IEC 27002: is a code of practice detailing how to implement each control. It is not certifiable.
Certification in practice
Certification is granted by an independent certification body after an audit, and it applies to the declared scope: a process, a business unit, a service or the whole company. That is why, when assessing a certified supplier, it is worth checking whether the certificate's scope covers the contracted service. Certification is maintained through periodic surveillance and recertification audits.
For the company, the standard frames security in the language of risk and produces verifiable evidence, which helps with customer, contractual and regulatory requirements. It works well alongside other frameworks such as the NIST CSF and supports security obligations under data protection laws such as Brazil's LGPD, without replacing them.
Network Secure operates a 24×7 SOC certified to ISO/IEC 27001:2022.
Frequently asked questions
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 defines the management system requirements and is certifiable. ISO 27002 is a guide detailing how to implement the controls, with no certification of its own.
Is ISO 27001 mandatory?
Generally not by law. But it is often required by customers, contracts and tenders as evidence of information security management.