Most people meet ISO 27001 through a customer contract clause rather than a security ambition. A buyer asks for proof, someone forwards the standard, and the first reaction is that it looks far heavier than expected. This ISO 27001 overview is meant to cut through that first impression and show what the standard actually contains and what it asks you to do.
ISO 27001 is the international standard for building and running an information security management system. It is published jointly by ISO and IEC, and the current version is ISO/IEC 27001:2022. It is a management system standard, not a technical rulebook. It does not tell you which firewall to buy or how long your passwords should be. It tells you how to decide those things, record the decision, and check later whether it worked.
An honest ISO 27001 overview also has to state what the standard is not. It is not a guarantee against breaches, and it is not a one-time project. Certification confirms that a system exists and is running, and surveillance audits keep confirming it every year.
What ISO 27001 Covers
The standard applies to information in any form. Servers and cloud accounts, yes, but also paper files, printed contracts, employee knowledge and supplier access. Anything that carries value and can be lost, exposed or altered falls inside its reach.
Three properties sit at the centre of the standard: confidentiality, integrity and availability. Every control you select exists to protect at least one of them. If you understand what an ISMS is at a basic level, ISO 27001 is simply the formal specification for building one that others can verify.
The 2022 Revision and What It Changed
The 2013 version listed 114 controls in 14 domains. The 2022 revision consolidated these into 93 controls grouped under four themes: organisational, people, physical and technological. Eleven controls were new, covering areas like threat intelligence, cloud service security, data leakage prevention and secure coding.
The main clauses changed very little. Organisations moving from the older version usually find that the work sits in remapping their control documentation, not in rebuilding the management system itself.
Structure of the Standard
ISO 27001 has two distinct halves, and confusing them is the most common early mistake.

Clauses 4 to 10: The Management System
These clauses are mandatory. You cannot skip one because it feels inconvenient.
Clause | What it asks for |
4. Context | Understand your organisation, interested parties and ISMS scope |
5. Leadership | Policy, top management commitment, assigned roles |
6. Planning | Risk assessment, risk treatment, objectives |
7. Support | Resources, competence, awareness, documented information |
8. Operation | Run the processes you planned, keep evidence |
9. Performance Evaluation | Monitoring, internal audit, management review |
10. Improvement | Nonconformities, corrective action, ongoing improvement |
This structure follows the Plan-Do-Check-Act cycle, and it is shared with ISO 9001, ISO 14001 and ISO 45001. That common backbone is why organisations already certified to another standard usually find ISO 27001 easier than expected.
Annex A: The Control Set
Annex A lists 93 reference controls. These are not all mandatory. You select controls based on your risk assessment, then justify each inclusion and exclusion in a document called the Statement of Applicability.
Auditors read the Statement of Applicability closely. Excluding a control is acceptable when your reasoning is sound and recorded. Excluding it silently is a finding.
Documents ISO 27001 Requires
The standard names a specific set of documented information. Everything else is optional, whatever a template pack might suggest.
- ISMS scope statement
- Information security policy
- Risk assessment and risk treatment methodology
- Statement of Applicability
- Risk treatment plan
- Security objectives
- Evidence of competence
- Monitoring and measurement results
- Internal audit programme and results
- Management review records
- Nonconformity and corrective action records
Many first-time implementations produce three times this volume, then struggle to keep it current. A smaller, maintained document set performs better in an audit than a large, stale one.
Want to see how these records look in a live system? Get a Free Personalized Demo and walk through a working Statement of Applicability with our team.
Risk Assessment Sits at the Centre
Nothing in ISO 27001 works without a credible risk assessment. Your control selection, your Statement of Applicability and your treatment plan all trace back to it.
The standard does not prescribe a method. Asset-based, scenario-based and process-based approaches are all acceptable, as long as your method is documented, repeatable and produces consistent results between assessors. Following the key steps in conducting a risk assessment for ISO 27001 gives you a defensible starting point.
One practical note from real implementations: assessments that are done once and filed away are the single most common source of major findings. Risks change when systems, vendors and people change. A review that happens only before an audit is describing last year's environment.
The Certification Path
Certification is optional. Plenty of organisations implement ISO 27001 without it. If you do pursue it, the route is predictable.

Before the Auditor Arrives
Start with a gap analysis against the clauses and Annex A, so you know your real starting position. Then define scope, build the risk assessment, select controls, write the required documents and run the system.
Controls need to have been operating long enough to produce evidence. Three to six months of records is a reasonable minimum. You also need at least one completed internal audit cycle and one management review before the certification audit.
Stage 1 and Stage 2
Stage 1 is a documentation review. The auditor checks whether your ISMS exists on paper and whether you are ready for a full assessment. Findings here are usually about missing or inconsistent documents.
Stage 2 tests whether the system runs in practice. The auditor samples records, interviews staff and looks for evidence that controls operate as described. Understanding how an ISO 27001 audit is conducted helps teams prepare the right evidence rather than over-preparing the wrong material.
The Three-Year Cycle
Certificates run for three years. Surveillance audits happen in years one and two, covering part of the system each time. A full recertification audit happens in year three.
Typical timelines from a low starting base run six to twelve months for a first certification. Organisations with existing security practices and another ISO certification often complete it in three to six months.
What Teams Commonly Get Wrong
Treating Annex A as a checklist. Working through 93 controls without a risk assessment produces controls nobody needs and gaps nobody spotted.
Setting scope too wide in year one. A narrow scope that genuinely works certifies faster than a broad one that half works.
Assuming certification equals security. It confirms a system is running. The benefits of ISMS come from operating it, not from the certificate on the wall.
Skipping the internal audit. An internal audit is mandatory, and auditors check that it was independent and covered the whole scope.
Managing the Standard Day to Day
The paperwork burden of ISO 27001 is manageable at the start and difficult to sustain across three years of surveillance audits. Review dates slip, versions diverge, and audit preparation becomes a document hunt.
ISMS software keeps the risk register, Statement of Applicability, policies, incident records, training logs and audit findings linked in one place with reminders and version history. Effivity supports ISO 27001 alongside ISO 9001, ISO 14001, ISO 45001 and ISO 22000, so organisations running several standards work from one evidence base rather than four.
Try Effivity for Free and map your first set of Annex A controls in an afternoon.
Frequently Asked Questions
It is the international standard for managing information security through a documented, risk-based system. It sets out how to decide, apply and review your security controls.
Annex A lists 93 controls across four themes. You apply only the ones your risk assessment justifies and record the rest as exclusions.
No. It is voluntary, though many enterprise contracts and public tenders require it as proof of security maturity.
Six to twelve months is typical from a low starting base. Organisations with an existing ISO certification often finish in three to six months.
No. It supports both by providing the control framework, but each has its own separate legal or reporting requirements.