The Cyber Academy take
ISO 27001 is the certifiable framework auditors use to grade your information security. The 2022 revision tightened Annex A down to 93 controls across four themes (organisational, people, physical, technological). Your ISMS lives or dies on the Statement of Applicability and the operating evidence. Everyone references it; few run it well.
What ISO/IEC 27001 actually certifies
ISO/IEC 27001 is the international standard that specifies the requirements for an information security management system, or ISMS. The certificate does not say your systems are unhackable. It says an accredited body examined how you identify information risks, decide what to do about them, and keep that decision running under management oversight. The standard is built on the Plan-Do-Check-Act cycle, so certification is never a one-off event: you commit to a recurring rhythm of risk assessment, treatment, internal audit, management review and corrective action.
A common confusion is treating the Annex A controls as the standard. They are not. The certifiable requirements live in the numbered management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement). Annex A is a reference set of controls you select from. You can pass an audit without implementing every control, provided your Statement of Applicability justifies what you excluded and your evidence backs up what you kept.
The 2022 revision and the control themes
The 2022 revision reorganised Annex A into four themes rather than the older fourteen domains. The themes group the controls by the kind of thing being protected or governed:
- Organisational controls cover policies, supplier relationships, threat intelligence and information security in project management.
- People controls cover screening, terms of employment, awareness and disciplinary process.
- Physical controls cover secure areas, equipment, clear-desk and the disposal of media.
- Technological controls cover access management, cryptography, logging, secure development and configuration management.
If you certified under the earlier version, transition work is mostly a remapping exercise: re-cut your Statement of Applicability against the new control set, confirm nothing fell through the gaps created by merged or newly introduced controls, and update the evidence references. The management-system clauses changed far less than the annex did.
How it sits next to its neighbours
ISO 27001 is the certifiable anchor of a family. ISO 27002 gives implementation guidance for the same Annex A controls but is not certifiable on its own; auditors reach for it when they want to challenge how well you operate a control, not merely whether it exists. ISO 27005 supplies a method for the information security risk assessment that clause 6 requires but deliberately leaves open. The ISMS is the running machine the standard certifies, and the SoA is its central controlled artefact.
On the people side, the work splits into two complementary disciplines. Implementers build and run the management system. Auditors plan and lead the audits that test it, working to the auditing guidance in ISO 19011. Most mature security functions need both mindsets, even when one person wears both hats early on.
What practitioners actually do
Running ISO 27001 well, rather than just passing the certificate, looks like this in practice:
- Define the scope honestly. An over-broad scope buries you in evidence; an over-narrow one fools nobody and undermines the certificate.
- Run a real risk assessment and treatment plan, and keep them current as the business and threat landscape change.
- Maintain the Statement of Applicability as a living document tied to actual evidence, not a spreadsheet completed once for the auditor.
- Operate internal audits and management reviews on schedule, and close corrective actions with proof rather than promises.
- Treat surveillance audits and the recertification cycle as continuity, not as separate fire drills.
Frequently asked questions
01Is ISO 27001 a legal requirement?
No. ISO 27001 is a voluntary standard, not a law. Organisations adopt it because customers, regulators or contracts ask for demonstrable security assurance, and a third-party certificate is the cleanest way to provide it.
02What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard with the management-system requirements and Annex A reference controls. ISO 27002 is implementation guidance for those controls and cannot be certified on its own. You certify against 27001 and lean on 27002 for the operational detail.
03Do I have to implement all the Annex A controls?
No. You select controls based on your risk assessment and document the rationale in the Statement of Applicability, including any you exclude. The auditor checks that your selection is justified and that the controls you kept are genuinely operating.
04How long does certification stay valid?
A certificate runs on a multi-year cycle with regular surveillance audits in between, followed by a full recertification audit. The exact timing is set by your certification body, but the principle is continuous: you maintain the ISMS throughout, not just at audit time.
05Does certification mean we cannot be breached?
No. Certification confirms you run a risk-based management system and operate the controls you selected. It reduces and manages risk; it does not eliminate it. Incident response and continual improvement are part of the standard precisely because breaches remain possible.