ISO 27001
Information Security Management Systems
ISO 27001:2022 at a glance
- Current edition
- ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- Published
- 2022
- Status
- Published
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Previous edition
- ISO/IEC 27001:2013
- Official ISO page
- View ISO 27001:2022 on iso.org
- Last verified
Overview
The certifiable requirements standard for an information security management system. Current edition is ISO/IEC 27001:2022 with Amendment 1:2024 (climate action); Annex A lists 93 controls organised into four themes.
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, is the best known information security standard and the one organizations certify against. It is the third edition and replaced ISO/IEC 27001:2013. It is developed by ISO/IEC JTC 1/SC 27 and applies to organizations of any type, size or sector.
The standard has two parts. Clauses 4 to 10 contain the management system requirements — context of the organization, leadership, planning, support, operation, performance evaluation and improvement — using the harmonized structure shared with ISO 9001, ISO 14001 and other management system standards. Annex A contains a reference set of information security controls that the organization compares against its own risk treatment plan.
The engine of the system is information security risk assessment and treatment. The organization defines and applies a risk assessment process with defined criteria, identifies risks to the confidentiality, integrity and availability of information within the ISMS scope, analyses and evaluates them, then selects treatment options and the controls necessary to implement them. It compares the controls it has determined against Annex A to verify that no necessary control has been omitted, and produces a Statement of Applicability recording the controls, their justification, whether they are implemented, and the reason for excluding any Annex A control. A risk treatment plan and risk owner approval complete the cycle.
The 2022 edition restructured Annex A into 93 controls under four themes: organizational, people, physical and technological controls, replacing the fourteen clauses of the 2013 edition. Eleven controls were new, addressing threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. The remainder were merged or updated. Implementation guidance for the controls is in the companion standard ISO/IEC 27002:2022.
Amendment 1:2024 added climate action wording to the context and interested-parties clauses, in line with the same change applied across ISO management system standards. It adds no new controls or clauses.
Certification is carried out by certification bodies accredited against ISO/IEC 27006-1. The route is a two-stage initial audit — Stage 1 assesses readiness, scope, the risk assessment method, the Statement of Applicability and the internal audit and management review evidence; Stage 2 assesses implementation and effectiveness of the ISMS and the selected controls — followed by surveillance audits during the certificate cycle and recertification at the end. Scope definition matters commercially, because the certificate states which parts of the organization, which services and which locations are covered.
ISO/IEC 27001 is widely used as the evidence base for customer security assurance, and it interlocks with related standards: ISO/IEC 27002 for control guidance, ISO/IEC 27005 for information security risk management guidance, ISO/IEC 27017 and 27018 for cloud, and ISO/IEC 27701 for privacy information management as an extension to the ISMS.
Purpose
To specify the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization, including requirements for the assessment and treatment of information security risks tailored to the organization's needs.
Key Benefits
- Provides a recognised, certifiable framework for managing information security risk
- Certification is widely accepted as customer and procurement assurance across sectors
- Forces a defined, repeatable risk assessment and treatment process with named risk owners
- Annex A gives a comprehensive control checklist that exposes gaps in existing security programmes
- The Statement of Applicability creates a clear, auditable record of control decisions
- Structurally aligned with ISO 9001, ISO 14001 and ISO 22301 for integrated management
- Extends to privacy management through ISO/IEC 27701 without a separate management system
- Supports evidence for contractual, regulatory and supply chain security obligations
- Improves incident management, business continuity readiness and supplier security control
Key Requirements
- Determine the context of the organization and the needs and expectations of interested parties (Clause 4)
- Define the scope and boundaries of the ISMS and establish, implement, maintain and improve it
- Demonstrate top management leadership, establish an information security policy and assign roles (Clause 5)
- Define and apply an information security risk assessment process with defined risk criteria (Clause 6)
- Define and apply an information security risk treatment process and select necessary controls
- Compare selected controls with Annex A and produce a Statement of Applicability
- Obtain risk owner approval of the risk treatment plan and acceptance of residual risks
- Set information security objectives and plan how to achieve them
- Provide resources, ensure competence and awareness, manage communication and documented information (Clause 7)
- Plan, implement and control the processes needed to meet requirements and carry out risk assessments at planned intervals (Clause 8)
- Monitor, measure, analyse and evaluate the ISMS and the effectiveness of controls (Clause 9)
- Conduct internal audits and management reviews at planned intervals
- React to nonconformities, take corrective action and continually improve the ISMS (Clause 10)
- Implement the applicable organizational, people, physical and technological controls from Annex A
- Address climate change as a context issue in accordance with Amendment 1:2024
Who Needs This Standard?
Any organization that holds or processes information whose confidentiality, integrity or availability matters — software and cloud providers, data centres, managed service providers, financial services, healthcare, telecoms, professional services, government suppliers and manufacturers with valuable intellectual property. It is commonly required by enterprise customers, public procurement and regulated sectors, and is used by information security managers, CISOs, IT and risk teams, internal auditors and compliance functions.
Where to get ISO 27001
The full text of ISO 27001 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27001 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 27001, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 27001 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 27001 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).