,

What is ISO 27001? A practical guide to information security management 

Abstract  ISO 27001 gives organizations a structured way to manage information security risk. But for many teams, the real challenge is not understanding the standard. It is maintaining the evidence, ownership and control visibility needed to prove the system works.  This guide should explain what ISO 27001 is, why it matters, how certification works, what Annex A controls cover, and why…

Esme Dyos Avatar
ISO 27001 logo against black, green and blue gradient

Abstract 

ISO 27001 gives organizations a structured way to manage information security risk. But for many teams, the real challenge is not understanding the standard. It is maintaining the evidence, ownership and control visibility needed to prove the system works. 

This guide should explain what ISO 27001 is, why it matters, how certification works, what Annex A controls cover, and why ISO 27001 should be treated as an ongoing governance process, not a once-a-year audit project. 

Key takeaways 

  • ISO 27001 is the international standard for an information security management system, or ISMS. 
  • It helps organizations manage the confidentiality, integrity and availability of information. 
  • Certification can support trust with customers, partners, regulators and procurement teams. 
  • ISO 27001:2022 modernized the Annex A control structure into 93 controls across 4 themes. 
  • The biggest operational challenge is maintaining evidence, ownership and control performance over time. 
  • CoreStream GRC can help teams connect ISO 27001 risks, controls, policies, evidence, actions and reporting in one place. 

Intro: Why does ISO 27001 matter now? 

Information security is no longer just a technical concern. It is a board-level governance issue, tied directly to operational resilience, customer trust, regulatory scrutiny and business continuity. As organizations hold more sensitive data, rely on more third parties and operate across more connected systems, the question is no longer whether information security matters. It is whether the organization can prove that information security risk is being managed in a structured, repeatable and defensible way. 

The risk context is clear. The UK Government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses and 28% of charities reported a cyber breach or attack in the last 12 months. That figure rose to 65% for medium businesses and 69% for large businesses. The financial impact is just as serious. IBM’s Cost of a Data Breach Report 2025 puts the global average cost of a data breach at USD 4.44 million. 

That is why ISO 27001 matters. It gives organizations a structured way to identify information security risks, apply appropriate controls, assign ownership, monitor performance and improve over time. In other words, it helps turn information security from a set of disconnected activities into a risk-based, auditable and repeatable management system. 

What is ISO 27001? 

ISO/IEC 27001 is the international standard for information security management systems. ISO describes it as the world’s best-known standard for ISMS, setting out the requirements organizations need to create, implement, maintain and continually improve information security management. 

The standard is not just for technology companies. It can apply to any organization that needs to protect sensitive information, from customer data and employee records to financial information, intellectual property and supplier data. ISO 27001 covers people, processes and technology, giving organizations a framework for deciding what information needs protection, what could go wrong, what controls are needed and how those controls should be monitored. 

What is an information security management system? 

An information security management system, or ISMS, is the governance structure behind information security. It brings together policies, risk assessments, controls, roles, responsibilities, monitoring, internal audit, management review and continual improvement. 

ISO says ISO 27001 helps organizations establish, implement, maintain and continually improve an ISMS. That matters because an ISMS should not be a static document library. It should show how information security risk is managed in practice. 

For risk, compliance and security teams, this means knowing who owns each control, when it was last reviewed, what evidence supports it and what actions remain open. Without that workflow and accountability, ISO 27001 can quickly become an audit file rather than a live management system.

What are the core principles behind ISO 27001? 

ISO 27001 is built around 3 core information security principles: confidentiality, integrity and availability. ISO explains that the standard helps organizations protect all 3. 

  • Confidentiality means only the right people can access the right information.  
  • Integrity means information stays accurate, complete and protected from improper change.  
  • Availability means information and systems are accessible when the business needs them. 

Together, these principles connect information security to operational resilience. For risk and compliance teams, the challenge is having visibility across all 3 areas, especially where controls depend on third parties, internal approvals, policies, evidence collection or manual follow-up. 

Why do organizations get ISO 27001 certified? 

Organizations pursue ISO 27001 certification for commercial, operational and governance reasons. Certification can show customers, regulators, partners and procurement teams that the organization has a structured approach to managing information security. 

ISO states that certification can demonstrate to stakeholders and customers that an organization is committed and able to manage information securely. ISO research also notes that certification can support credibility, reduce the risk of fraud, information loss and data breaches, and improve access to security-conscious customers and partners.  

There is also a clear procurement angle. ISO 27001 often appears in tenders, supplier questionnaires and customer due diligence. For organizations selling into enterprise markets, certification can help remove friction from security reviews and strengthen trust before deeper commercial conversations begin. 

“For CoreStream GRC, ISO 27001 certification is about more than meeting a standard. It gives our clients confidence that we apply the same discipline to our own information security that we help them bring to their governance, risk and compliance processes.” 

Steve Biggs, Head of Infrastructure and Security, CoreStream GRC 

How widely used is ISO 27001? 

ISO 27001 is widely adopted across global markets. ISO research reported that valid ISO/IEC 27001 certifications grew from 4,073 in 2006 to 83,016 in 2023. The same report states that ISO/IEC 27001 certification was counted across 165 countries from 2006 to 2023.  

That global adoption matters for multinational organizations. When information security controls, evidence and assurance activity span multiple regions, business units and suppliers, teams need a consistent way to manage ISO 27001 requirements without losing visibility or control. 

What does ISO 27001 require? 

 ISO 27001 requires organizations to build and maintain a structured information security management system. NSAI explains that certification involves defining the ISMS scope, identifying risks and opportunities, implementing controls through risk treatment, assigning roles and governance arrangements, and establishing monitoring, internal audit and continual improvement. 

In practice, this means an organization needs to know what information it is protecting, what risks could affect it, which controls are in place, who owns them and how performance is reviewed. Each requirement creates an evidence trail. The challenge is keeping that trail clean, current and easy to defend when auditors, customers or internal stakeholders ask for proof.

What are ISO 27001 Annex A controls? 

Annex A is the reference control set used to help organizations treat information security risks. Under ISO 27001:2022, Annex A contains 93 information security controls across 4 themes:  

  • Organizational controls cover areas such as policies, responsibilities, supplier relationships, compliance, access management and governance.  
  • People controls focus on screening, training, awareness and responsibilities across the employee lifecycle.  
  • Physical controls deal with secure areas, physical access and equipment protection.  
  • Technological controls cover areas such as authentication, logging, monitoring, encryption, malware protection, configuration and secure development. 

Organizations do not apply every control in the same way. Controls should be selected based on risk, relevance and business context. But selection is only the first step. Teams also need to record why a control applies, who owns it, how it is tested and what evidence proves it is working.  

What is a Statement of Applicability? 

The Statement of Applicability is one of the most important ISO 27001 documents. It records which Annex A controls apply to the organization, which do not, and why. 

It should connect directly to the risk assessment and risk treatment plan. This is where control decisions become auditable. A weak Statement of Applicability can turn ISO 27001 into a paperwork exercise. A strong one shows how risk, control decisions and business context connect. 

For teams managing ISO 27001, the practical challenge is keeping that record current. Controls need to be mapped to risks, assigned to owners, linked to evidence and tracked through action plans where gaps exist. 

IT Risk Management solution download

What changed in ISO 27001:2022? 

ISO/IEC 27001:2022 replaced ISO/IEC 27001:2013. 

The transition period has now passed. INAB transition requirements stated that certification bodies had to complete client transitions to ISO/IEC 27001:2022 by 31 October 2025. 

The main practical change was the updated Annex A control structure. Controls were reorganized under 4 themes: organizational, people, physical and technological. Organizations should now check that their ISMS, control register, risk assessment, policies and Statement of Applicability align with the 2022 version. Framework changes are much easier to manage when controls, risks and evidence are mapped in one place. 

How does ISO 27001 support cyber risk management? 

ISO 27001 is risk-based, not checklist-based. NSAI explains that the standard requires organizations to identify, assess and treat information security risks in line with business objectives and stakeholder expectations. 

That matters because cyber risk changes quickly. The 2026 Verizon Data Breach Investigations Report reports that 31% of breaches now start with software vulnerabilities and 48% involve ransomware. 

ISO 27001 helps organizations bring structure to areas such as asset visibility, access control, vulnerability management, logging and monitoring, incident response, supplier security, business continuity and secure development. For risk and compliance teams, the value is visibility: who owns the risk, what controls are in place, where gaps remain and what evidence supports assurance. 

ISO 27001 is not the same as legal compliance. Certification does not automatically prove compliance with GDPR, NIS2 or DORA. But it can give organizations a stronger evidence base for security governance because it creates a structured way to assess risks, apply controls, monitor performance and show improvement over time. 

That matters because many regulatory expectations point in the same direction. UK GDPR Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The European Commission says NIS2 creates a unified cybersecurity framework across 18 critical sectors in the EU. EIOPA explains that DORA, which applies from 17 January 2025, strengthens digital resilience across financial entities, including ICT risk management, incident reporting, resilience testing and ICT third-party risk management. 

ISO 27001 can help organizations manage some of the underlying work behind these obligations, including: 

  • risk assessment and treatment 
  • access control 
  • supplier and third-party security 
  • incident management 
  • monitoring and audit evidence 
  • management review 
  • corrective actions and continual improvement 

The important point is that legal obligations still need to be mapped separately. ISO 27001 can support the control environment, but GDPR, NIS2 and DORA each have their own scope, language, deadlines and reporting expectations. 

This is where control mapping becomes valuable. One control may support ISO 27001, GDPR, NIS2, DORA, customer assurance, supplier due diligence and internal audit at the same time. The Secure Controls Framework, or SCF, is useful because it helps consolidate overlapping requirements into a common control structure, reducing duplicate work and making it easier to test once and evidence across multiple obligations. 

What is the ISO 27001 certification process? 

ISO 27001 certification is not just a one-off audit. It is a process for proving that the organization has designed, implemented and maintained an effective information security management system. 

NSAI outlines a certification process that includes application and quotation, a Stage 1 audit, a Stage 2 audit, ongoing surveillance audits and recertification at defined intervals. 

In practice, the journey usually includes: 

  • getting leadership buy-in 
  • defining the ISMS scope 
  • running a gap assessment 
  • completing risk assessment and risk treatment 
  • building or updating policies and controls 
  • creating the Statement of Applicability 
  • assigning control owners 
  • training employees 
  • collecting evidence 
  • conducting internal audit 
  • holding management review 
  • completing Stage 1 and Stage 2 audits 
  • maintaining the ISMS through surveillance audits 

The last point is often where teams struggle. Certification is not the finish line. The ISMS has to keep working after the certificate is issued. Risks change, suppliers change, systems change and evidence needs to stay current. 

What evidence do ISO 27001 auditors expect? 

ISO 27001 auditors will not only check whether documents exist. They will look for evidence that the ISMS is operating in practice. ISO explains that conformity means the organization has put in place a system to manage risks related to the security of data it owns or handles. 

That evidence may include: 

  • ISMS scope. 
  • Information security policy. 
  • Risk assessment records. 
  • Risk treatment plan. 
  • Statement of Applicability. 
  • Access review records. 
  • Supplier assessment records. 
  • Incident response logs. 
  • Training completion records. 
  • Internal audit reports. 
  • Management review minutes. 
  • Corrective action records. 
  • Control testing evidence. 
  • Monitoring and reporting outputs. 

The challenge is not simply collecting this evidence. It is keeping it traceable. Teams need to show who approved a control, when it was reviewed, what changed, what issue was raised and whether the action was closed. Without that audit trail, evidence can quickly become fragmented across inboxes, spreadsheets and shared drives.

How can GRC software support ISO 27001? 

ISO 27001 creates repeatable work: risk assessments, control reviews, evidence collection, issue tracking, policy approvals, supplier reviews, internal audits and management reporting. Managing that manually may work at a small scale, but it becomes harder as the ISMS grows across teams, systems and regions. 

GRC software can help by giving teams one place to manage: 

  • centralized control libraries 
  • risk and control mapping 
  • Statement of Applicability tracking 
  • evidence collection workflows 
  • automated reminders for control owners 
  • policy approvals and attestations 
  • supplier risk management 
  • internal audit planning 
  • corrective action tracking 
  • dashboards for management review 
  • audit trails and approval history 

CoreStream GRC also uses its own platform to support its ISO 27001 certification process. This gives the team first-hand experience of the same challenge many organizations face: keeping risks, controls, owners, evidence and actions connected, current and audit-ready. 

How can AI and integrations help with ISO 27001 evidence? 

ISO 27001 does not sit in isolation. Most organizations are also managing requirements across GDPR, NIS2, DORA, SOC 2, supplier assurance, internal audit and customer security reviews. That creates a familiar problem: the same control may be tested, mapped and evidenced several times across different frameworks. 

AI and integrations can help reduce that duplication, but only if they are used carefully. Evidence should still be source-backed, outputs should be explainable and human review should remain part of the process. The goal is not to replace judgment. It is to make it easier for teams to understand where evidence exists, where gaps remain and what needs remediation. 

The CoreStream GRC and SANNOS partnership supports this “show your work” challenge. SANNOS can help assess evidence against frameworks including ISO 27001, SOC 2, NIS2, DORA and GDPR, while CoreStream GRC helps teams turn that assessment into workflow, ownership, action tracking and audit-ready reporting. 

The Secure Controls Framework, or SCF, strengthens this further by providing a consolidated control structure across multiple standards and regulations. Instead of managing ISO 27001, GDPR, NIS2 and DORA as separate compliance projects, teams can map overlapping requirements into a single control view. That makes evidence easier to reuse, gaps easier to identify and reporting easier to defend. 

In practice, AI and integrations are most useful when they help teams: 

  • map requirements across overlapping frameworks 
  • identify evidence gaps 
  • reduce duplicate evidence requests 
  • connect controls to risks, owners and actions 
  • support faster audit preparation 
  • keep outputs explainable and reviewable 

For ISO 27001 teams, that matters because evidence is often the hardest part to sustain. The framework tells you what good information security management should look like. The harder question is whether you can prove it, quickly and clearly, when someone asks.

ISO 27001 readiness checklist 

Before pursuing ISO 27001 certification, or reviewing an existing ISMS, organizations should test whether the basics are genuinely in place. The checklist below is a practical starting point: 

  • Have we defined the scope of our ISMS? 
  • Have we identified key information assets? 
  • Have we assessed information security risks? 
  • Have we created a risk treatment plan? 
  • Have we selected and justified Annex A controls? 
  • Have we created a Statement of Applicability? 
  • Have we assigned control owners? 
  • Are policies approved, current and communicated? 
  • Do we have evidence that controls operate in practice? 
  • Do we review supplier and third-party risks? 
  • Do we track incidents and corrective actions? 
  • Have we conducted internal audit? 
  • Has leadership reviewed ISMS performance? 
  • Are actions tracked to closure? 

If the answer is “yes, but it lives across 12 spreadsheets,” that is still a problem. ISO 27001 depends on evidence, ownership and continual improvement. When those activities are scattered across different files, inboxes and shared drives, the ISMS becomes harder to manage and harder to defend.

Conclusion: ISO 27001 is a governance system, not a badge 

ISO 27001 certification matters. It can strengthen customer trust, support procurement conversations and show that an organization takes information security seriously. But the bigger value comes from running information security in a structured, risk-based and evidence-backed way. 

The standard helps organizations define risks, select controls, assign ownership, review performance and improve over time. The hard part is sustaining that discipline after certification. Risks change. Suppliers change. Systems change. Evidence requests do not stop once the certificate is issued. 

That is why ISO 27001 should be treated as a live governance system, not a static audit file. It becomes stronger when risks, controls, evidence, policies, suppliers, actions and audits are connected. 

The goal is not just to pass the audit. It is to build an information security management system that works when risks change, evidence is requested and the business needs clear answers. Done well, ISO 27001 can help create a stronger risk-aware culture, where information security is owned, evidenced and improved across the organization. 

Frequently asked questions for ISO 27001

What is ISO 27001 in simple terms? 

ISO 27001 is the international standard for an information security management system, or ISMS. It helps organizations manage information security risks by setting requirements for risk assessment, controls, ownership, monitoring and continual improvement.

What is ISO 27001 certification?

ISO 27001 certification is an independent confirmation that an organization has implemented an information security management system that meets the requirements of the standard. It shows customers, partners and other stakeholders that information security is being managed through a structured and auditable process. 

Is ISO 27001 mandatory?

ISO 27001 is not generally mandatory. However, it may be required through customer contracts, supplier assurance processes, tenders or procurement requirements. For some organizations, certification can also support wider regulatory and compliance expectations around information security governance.

What is an ISMS? 

An ISMS, or information security management system, is the framework an organization uses to manage information security. It brings together policies, risk assessments, controls, roles, responsibilities, evidence, monitoring, internal audit and management review. 

What are ISO 27001 Annex A controls?

ISO 27001 Annex A controls are the reference controls organizations use to help treat information security risks. Under ISO 27001:2022, Annex A includes 93 controls across 4 themes: organizational, people, physical and technological controls. 

What is the Statement of Applicability in ISO 27001? 

The Statement of Applicability is a key ISO 27001 document that records which Annex A controls apply to the organization, which do not, and why. It links control decisions back to the organization’s risk assessment and risk treatment plan. 

How long does ISO 27001 certification take? 

The time needed for ISO 27001 certification depends on the size of the organization, the scope of the ISMS, existing control maturity and evidence readiness. Organizations with clear ownership, current policies, mapped controls and organized evidence will usually be better placed to move through the certification process efficiently. 

Does ISO 27001 mean an organization is GDPR compliant? 

No. ISO 27001 does not automatically prove GDPR compliance. However, it can support GDPR security expectations by helping organizations manage information security risks, technical and organizational controls, evidence and continual improvement. GDPR obligations still need to be mapped and assessed separately. 

How does ISO 27001 support NIS2 and DORA? 

ISO 27001 can support NIS2 and DORA by giving organizations a structured way to manage information security risks, controls, suppliers, incident response, monitoring and audit evidence. It does not replace legal compliance, but it can strengthen the control environment behind those obligations. 

What is the difference between ISO 27001 and SOC 2? 

ISO 27001 is an international standard for information security management systems. SOC 2 is an assurance report focused on controls relevant to trust services criteria, such as security, availability, confidentiality, processing integrity and privacy. Both can support customer trust, but they have different structures, requirements and assessment approaches. 

How can GRC software help with ISO 27001? 

GRC software can help organizations manage ISO 27001 by connecting risks, controls, owners, policies, evidence, audits and corrective actions in one place. This makes it easier to track control performance, prepare for audits, maintain the Statement of Applicability and show that the ISMS is operating in practice. 

Why does ISO 27001 evidence matter? 

ISO 27001 evidence matters because auditors, customers and internal stakeholders need proof that controls are working. Policies alone are not enough. Teams need to show what was reviewed, who approved it, what evidence supports it and what actions were taken when gaps were found. 

  • UK Corporate Governance Code

    UK Corporate Governance Code

    What is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…

  • AI governance

    AI governance

    What is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…

  • The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    Key takeaways  Introduction: the AI compliance deadline GRC teams have been racing toward just moved  For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…