What ISO 27001 requires
ISO/IEC 27001 is the international standard for an Information Security Management System — an ISMS. The distinction that trips teams up is this: ISO 27001 is not primarily a checklist of security controls. It is a standard for the management system that decides which controls you need, implements them, measures whether they work, and improves them over time.
The main clauses (4 to 10) define that management system: understanding your context, leadership commitment, planning and risk treatment, support and resources, operation, performance evaluation, and continual improvement. Annex A then provides the catalogue of controls you select from, justified by your risk assessment.
Scope
Define the ISMS
Risk assess
Identify & evaluate
Treat
Select Annex A controls
Operate
Run & evidence
Internal audit
Plus management review
Certify
Stage 1 & Stage 2
What changed in ISO 27001:2022
The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, merging overlapping controls and introducing new ones that reflect how organisations actually operate today — including threat intelligence, cloud services, and data leakage prevention.
| Theme | Focus |
|---|---|
| Organizational | Policies, roles, supplier and cloud relationships, incident planning |
| People | Screening, awareness, responsibilities during and after employment |
| Physical | Secure areas, equipment, physical entry and environmental controls |
| Technological | Access, cryptography, secure development, logging, monitoring |
The Statement of Applicability
The Statement of Applicability (SoA) is the document auditors reach for first. It lists every Annex A control, states whether it applies to you, and justifies each inclusion or exclusion against your risk assessment. A vague or unjustified SoA is one of the most common sources of audit findings — it signals that risk treatment was not genuinely driven by risk.
How certification works
- 1Stage 1 audit: the certification body reviews your documentation and readiness, including scope, policies and the SoA.
- 2Stage 2 audit: a deeper examination of whether the ISMS is genuinely implemented and effective in practice.
- 3Certification: valid for three years, subject to ongoing surveillance.
- 4Surveillance audits: typically annual, checking the ISMS continues to operate and improve.
- 5Recertification: a full reassessment at the end of the three-year cycle.
Common pitfalls to avoid
- Treating Annex A as a checklist and skipping the risk assessment that is supposed to drive control selection.
- Writing policies nobody follows — auditors look for evidence of operation, not just documents.
- Scoping too broadly at first certification, which multiplies effort without commercial benefit.
- Neglecting internal audit and management review, which are explicit requirements and frequent finding sources.
- Rebuilding from scratch for SOC 2 instead of reusing the substantial overlap.