ISO 27001: Information Security Management
The international standard for managing information security. It provides a systematic approach to managing sensitive information through policies, procedures, and technical controls. Organizations get certified by demonstrating their ISMS meets the standard's requirements.
The Two Parts of ISO 27001
- Context of the organization
- Leadership commitment
- Planning and risk treatment
- Support and resources
- Operational planning and control
- Performance evaluation
- Continual improvement
- Organizational, people, and physical controls
- Technological controls
- Not all controls apply to every organization
- Select controls based on your risk assessment
- Document your decisions in the SoA
SoA = Statement of Applicability. This document lists which Annex A controls you are implementing and why.
The 14 Control Domains
Annex A organizes the 114 controls into 14 domains covering all aspects of information security.
Management direction and support for information security, documented and reviewed regularly.
Internal organization and responsibilities for information security.
Security responsibilities for employees, contractors, and third parties.
Identification, ownership, and acceptable use of information assets.
Limiting access to information and information systems to authorized users only.
Proper use of cryptographic controls to protect information confidentiality, authenticity, and integrity.
Preventing unauthorized physical access, damage, and interference to information and processing facilities.
Correct and secure operations of information processing facilities.
Security of information in networks and supporting infrastructure.
Security requirements for information systems throughout their lifecycle.
Protecting organizational assets that are accessible by suppliers.
Ensuring effective and appropriate response to information security incidents.
Protecting, maintaining, and recovering business-critical processes.
Avoiding breaches of legal, statutory, regulatory, or contractual obligations.
Path to Certification
ISO 27001 certification typically takes 6-12 months for smaller organizations and involves these steps. The timeline varies based on current maturity and available resources.
Gap Analysis
Compare current controls against ISO 27001 requirements to identify gaps.
Risk Assessment
Identify and evaluate information security risks according to the standard's methodology.
Implement Controls
Address identified gaps and implement controls from the Annex A list.
Document Everything
Create and maintain required documentation including policies, procedures, and records.
Internal Audit
Conduct an internal audit to verify the ISMS is functioning as designed.
Management Review
Have leadership review and approve the ISMS before external certification.
Certification Audit
Engage an accredited certification body to conduct the Stage 1 and Stage 2 audits.
Ready to begin your ISO 27001 journey?
ABC of Cyber helps you assess readiness, plan implementation, and track progress toward certification.