ISO 27001: Your Complete Guide
Everything you need to understand ISO 27001 - from the basics of the standard to a detailed clause-by-clause walkthrough.
Understanding the Standard
What is ISO 27001?
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive company information so that it remains secure.
Who needs it?
Any organization that handles sensitive data - from SaaS startups to enterprise companies. Increasingly required by customers, partners, and regulators, especially in B2B and regulated industries.
The certification process
Gap analysis, ISMS design, implementation, internal audit, management review, and finally the certification audit by an accredited body. Typically 3-12 months depending on your starting point.
Clause-by-Clause Guide
ISO 27001 is structured around clauses 4 through 10. Each clause addresses a different aspect of your information security management system.
Clause 4: Context of the Organisation
Clause 5: Leadership
Clause 6: Planning
Clause 7: Support
Clause 8: Operation
Clause 9: Performance Evaluation
Clause 10: Improvement
- 10.1 Continual Improvement →
- 10.2 Nonconformity and Corrective Action (coming soon)
Annex A Controls
ISO 27001:2022 Annex A groups 93 controls into four themes. We are working through them control by control, the same way we did the clauses.
A.5 Organizational controls (37)
- A.5.1 Policies for information security (coming soon)
- A.5.2 Information security roles and responsibilities (coming soon)
- A.5.3 Segregation of duties (coming soon)
- A.5.4 Management responsibilities (coming soon)
- A.5.5 Contact with authorities (coming soon)
- A.5.6 Contact with special interest groups (coming soon)
- A.5.7 Threat intelligence (coming soon)
- A.5.8 Information security in project management (coming soon)
- A.5.9 Inventory of information and other associated assets (coming soon)
- A.5.10 Acceptable use of information and other associated assets (coming soon)
- A.5.11 Return of assets (coming soon)
- A.5.12 Classification of information (coming soon)
- A.5.13 Labelling of information (coming soon)
- A.5.14 Information transfer (coming soon)
- A.5.15 Access control (coming soon)
- A.5.16 Identity management (coming soon)
- A.5.17 Authentication information (coming soon)
- A.5.18 Access rights (coming soon)
- A.5.19 Information security in supplier relationships (coming soon)
- A.5.20 Addressing information security within supplier agreements (coming soon)
- A.5.21 Managing information security in the ICT supply chain (coming soon)
- A.5.22 Monitoring, review and change management of supplier services (coming soon)
- A.5.23 Information security for use of cloud services (coming soon)
- A.5.24 Information security incident management planning and preparation (coming soon)
- A.5.25 Assessment and decision on information security events (coming soon)
- A.5.26 Response to information security incidents (coming soon)
- A.5.27 Learning from information security incidents (coming soon)
- A.5.28 Collection of evidence (coming soon)
- A.5.29 Information security during disruption (coming soon)
- A.5.30 ICT readiness for business continuity (coming soon)
- A.5.31 Legal, statutory, regulatory and contractual requirements (coming soon)
- A.5.32 Intellectual property rights (coming soon)
- A.5.33 Protection of records (coming soon)
- A.5.34 Privacy and protection of personal identifiable information (PII) (coming soon)
- A.5.35 Independent review of information security (coming soon)
- A.5.36 Compliance with policies, rules and standards for information security (coming soon)
- A.5.37 Documented operating procedures (coming soon)
A.6 People controls (8)
- A.6.1 Screening (coming soon)
- A.6.2 Terms and conditions of employment (coming soon)
- A.6.3 Information security awareness, education and training (coming soon)
- A.6.4 Disciplinary process (coming soon)
- A.6.5 Responsibilities after termination or change of employment (coming soon)
- A.6.6 Confidentiality or non-disclosure agreements (coming soon)
- A.6.7 Remote working (coming soon)
- A.6.8 Information security event reporting (coming soon)
A.7 Physical controls (14)
- A.7.1 Physical security perimeters (coming soon)
- A.7.2 Physical entry (coming soon)
- A.7.3 Securing offices, rooms and facilities (coming soon)
- A.7.4 Physical security monitoring (coming soon)
- A.7.5 Protecting against physical and environmental threats (coming soon)
- A.7.6 Working in secure areas (coming soon)
- A.7.7 Clear desk and clear screen (coming soon)
- A.7.8 Equipment siting and protection (coming soon)
- A.7.9 Security of assets off-premises (coming soon)
- A.7.10 Storage media (coming soon)
- A.7.11 Supporting utilities (coming soon)
- A.7.12 Cabling security (coming soon)
- A.7.13 Equipment maintenance (coming soon)
- A.7.14 Secure disposal or re-use of equipment (coming soon)
A.8 Technological controls (34)
- A.8.1 User endpoint devices (coming soon)
- A.8.2 Privileged access rights (coming soon)
- A.8.3 Information access restriction (coming soon)
- A.8.4 Access to source code (coming soon)
- A.8.5 Secure authentication (coming soon)
- A.8.6 Capacity management (coming soon)
- A.8.7 Protection against malware (coming soon)
- A.8.8 Management of technical vulnerabilities (coming soon)
- A.8.9 Configuration management (coming soon)
- A.8.10 Information deletion (coming soon)
- A.8.11 Data masking (coming soon)
- A.8.12 Data leakage prevention (coming soon)
- A.8.13 Information backup (coming soon)
- A.8.14 Redundancy of information processing facilities (coming soon)
- A.8.15 Logging (coming soon)
- A.8.16 Monitoring activities (coming soon)
- A.8.17 Clock synchronization (coming soon)
- A.8.18 Use of privileged utility programs (coming soon)
- A.8.19 Installation of software on operational systems (coming soon)
- A.8.20 Networks security (coming soon)
- A.8.21 Security of network services (coming soon)
- A.8.22 Segregation of networks (coming soon)
- A.8.23 Web filtering (coming soon)
- A.8.24 Use of cryptography (coming soon)
- A.8.25 Secure development life cycle (coming soon)
- A.8.26 Application security requirements (coming soon)
- A.8.27 Secure system architecture and engineering principles (coming soon)
- A.8.28 Secure coding (coming soon)
- A.8.29 Security testing in development and acceptance (coming soon)
- A.8.30 Outsourced development (coming soon)
- A.8.31 Separation of development, test and production environments (coming soon)
- A.8.32 Change management (coming soon)
- A.8.33 Test information (coming soon)
- A.8.34 Protection of information systems during audit testing (coming soon)
Related Resources
Statement of Applicability (SoA)
How to build your SoA and map controls to your organization.
The CIA Triad in ISO 27001
Confidentiality, integrity, and availability - the foundation of information security.
PDCA Cycle for ISO 27001
Plan-Do-Check-Act - the continuous improvement engine behind your ISMS.
Creating an Information Security Policy
A practical guide to writing a policy people will actually read and follow.
Frequently Asked Questions
What is ISO 27001?
ISO/IEC 27001:2022 is an international standard that provides a framework for managing information security. It is the most widely recognized information security standard in the world.
What are the benefits of ISO 27001 certification?
ISO 27001 certification helps organizations improve their security posture, reduce the risk of data breaches, comply with regulatory requirements, gain a competitive advantage, and build trust with customers and partners.
What are the steps to ISO 27001 certification?
The main steps are: conduct a risk assessment to identify information security risks, develop and implement an ISMS to address them, have the ISMS audited by an accredited certification body, implement any corrective actions, and receive certification.
What is an ISMS?
An Information Security Management System (ISMS) is a framework for managing information security risks. It includes policies, procedures, and controls to protect an organization's information assets.
What are the key requirements of ISO 27001?
The key requirements include establishing an information security policy, conducting a risk assessment, identifying and implementing appropriate controls, monitoring and reviewing the ISMS, and continuously improving it.
How long does it take to get ISO 27001 certified?
The timeline varies depending on the size and complexity of the organization and the maturity of its security program. Typically, it takes between 3 and 12 months to achieve certification.
How much does ISO 27001 certification cost?
The cost varies depending on the size and complexity of the organization. Factors include consulting fees, certification body audit fees, any tooling or infrastructure changes needed, and ongoing maintenance costs.
Who should get ISO 27001 certified?
Any organization that stores or processes sensitive information should consider ISO 27001 certification. This includes organizations across all industries - technology, healthcare, financial services, government, and education.
What are the benefits of maintaining ISO 27001 certification?
Maintaining certification helps organizations continuously improve their security posture, demonstrate their commitment to information security to customers and partners, and stay ahead of evolving threats and regulations.
Ready to get certified?
Whether you're just starting to explore ISO 27001 or ready to begin the certification process, we're here to help. No jargon, no pressure - just an honest conversation about where you stand.