Back to Frameworks
ISO 27001
International Standard for Information Security

ISO 27001: Information Security Management

The international standard for managing information security. It provides a systematic approach to managing sensitive information through policies, procedures, and technical controls. Organizations get certified by demonstrating their ISMS meets the standard's requirements.

The Two Parts of ISO 27001

Part 1: Clauses 4-10
Mandatory requirements for certification
  • Context of the organization
  • Leadership commitment
  • Planning and risk treatment
  • Support and resources
  • Operational planning and control
  • Performance evaluation
  • Continual improvement
Part 2: Annex A Controls
114 possible controls to implement
  • Organizational, people, and physical controls
  • Technological controls
  • Not all controls apply to every organization
  • Select controls based on your risk assessment
  • Document your decisions in the SoA

SoA = Statement of Applicability. This document lists which Annex A controls you are implementing and why.

The 14 Control Domains

Annex A organizes the 114 controls into 14 domains covering all aspects of information security.

A5
Information Security Policies
2 controls

Management direction and support for information security, documented and reviewed regularly.

A6
Organization of Information Security
7 controls

Internal organization and responsibilities for information security.

A7
Human Resource Security
3 controls

Security responsibilities for employees, contractors, and third parties.

A8
Asset Management
10 controls

Identification, ownership, and acceptable use of information assets.

A9
Access Control
14 controls

Limiting access to information and information systems to authorized users only.

A10
Cryptography
2 controls

Proper use of cryptographic controls to protect information confidentiality, authenticity, and integrity.

A11
Physical and Environmental Security
15 controls

Preventing unauthorized physical access, damage, and interference to information and processing facilities.

A12
Operations Security
14 controls

Correct and secure operations of information processing facilities.

A13
Communications Security
7 controls

Security of information in networks and supporting infrastructure.

A14
System Acquisition, Development, and Maintenance
13 controls

Security requirements for information systems throughout their lifecycle.

A15
Supplier Relationships
5 controls

Protecting organizational assets that are accessible by suppliers.

A16
Information Security Incident Management
7 controls

Ensuring effective and appropriate response to information security incidents.

A17
Business Continuity Management
4 controls

Protecting, maintaining, and recovering business-critical processes.

A18
Compliance
8 controls

Avoiding breaches of legal, statutory, regulatory, or contractual obligations.

Path to Certification

ISO 27001 certification typically takes 6-12 months for smaller organizations and involves these steps. The timeline varies based on current maturity and available resources.

1

Gap Analysis

Compare current controls against ISO 27001 requirements to identify gaps.

2

Risk Assessment

Identify and evaluate information security risks according to the standard's methodology.

3

Implement Controls

Address identified gaps and implement controls from the Annex A list.

4

Document Everything

Create and maintain required documentation including policies, procedures, and records.

5

Internal Audit

Conduct an internal audit to verify the ISMS is functioning as designed.

6

Management Review

Have leadership review and approve the ISMS before external certification.

7

Certification Audit

Engage an accredited certification body to conduct the Stage 1 and Stage 2 audits.

Ready to begin your ISO 27001 journey?

ABC of Cyber helps you assess readiness, plan implementation, and track progress toward certification.