Start a free trial
Menu

ISO 27001

ISO 27001 compliance software

Organisations that must protect information - including defence suppliers handling controlled data.

ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.

ComplyTrain fully supports this standard

What ISO 27001 is

ISO 27001 is the international standard for an information security management system (ISMS) - a systematic way to protect the confidentiality, integrity and availability of information by assessing risk and applying controls. It is the recognised benchmark for “this organisation takes security seriously and can prove it”, and for defence, technology and dual-use suppliers it is increasingly a contractual expectation rather than a differentiator.

An ISMS is not a firewall or an antivirus product. It is the management system around your security: the policies, the risk decisions, the controls and the evidence that they are actually operating. ISO 27001 defines what that system must contain; the technology you use to satisfy it is your choice.

Why ISO 27001 exists

Security incidents rarely come from a lack of tools - they come from unmanaged risk: an unpatched system nobody owned, a supplier nobody assessed, an access right nobody revoked. ISO 27001 exists to make security a managed, evidenced discipline rather than a collection of good intentions. A certificate tells a customer that an independent auditor has checked not only that you have controls, but that you understand your risks and manage them on a cycle.

Who needs ISO 27001

Any organisation that holds information other people care about - customer data, intellectual property, controlled technical information. In practice it is driven by:

  • Customer and contractual demand: enterprise and government buyers increasingly require it before sharing data or awarding work, and defence contracts may mandate it for handling controlled information.
  • Regulation and adjacency: it is the backbone that frameworks such as ISO 27018 (cloud privacy), the EU NIS2 directive and many GDPR programmes lean on.
  • Risk itself: for a company whose product or reputation depends on trust, a managed ISMS is simply how you avoid the incident that ends the conversation.

How the standard is structured

ISO 27001:2022 has two parts. The management-system clauses (4–10) mirror ISO 9001 - context, leadership, planning, support, operation, evaluation, improvement - so the two standards fit together naturally. What makes it an information-security standard is the risk process and Annex A:

  • A risk assessment and treatment process: identify your information-security risks, decide how to treat each one, and record the decision.
  • Annex A: a catalogue of 93 controls in the 2022 revision, grouped into organisational, people, physical and technological themes, to draw on when treating risk.
  • The Statement of Applicability (SoA): the document that states which Annex A controls you apply, which you do not, and why - the spine of the whole certification.

Certification is awarded by an accredited body after a two-stage audit, with annual surveillance and a three-yearly recertification, exactly as with ISO 9001.

Common misconceptions

  • It is not an IT-department project. Information security spans HR (joiners and leavers), procurement (supplier risk), facilities (physical access) and leadership (risk appetite) - the standard makes that explicit.
  • It is not “buy the controls”. Annex A is a menu, not a checklist: you apply the controls your risk assessment justifies and must be able to explain the ones you leave out.
  • It is not one-and-done. The certificate lapses without the ongoing risk reviews, internal audits and management reviews that keep the system alive.

How ComplyTrain helps you meet it

ComplyTrain gives you the framework to build and run your ISMS, and to hold the evidence an ISO 27001 audit asks for:

  • Security policies and procedures under version control, with signed acknowledgement - Document Control
  • Annex A controls captured as requirements and traced to the evidence that meets them - Requirements Management
  • Your information-security risk assessment and treatment, kept as a living register - Risk Management
  • Supplier security assessed and recorded - Vendor Management
  • Security-awareness training assigned, tested and recorded - Training Management

ComplyTrain is not itself ISO 27001 certified, and does not need to be: it is the system you build and run your own ISO 27001 program in. The certificate is yours to earn - ComplyTrain is where the evidence for it lives.

Questions

Is ComplyTrain ISO 27001 certified?

No - and we will not imply otherwise. ComplyTrain is the software you use to build, run and evidence your own ISO 27001 information security management system. Your certificate is awarded to your organisation by an accredited body; ComplyTrain is where the policies, risk assessments, controls and records that earn it are managed.

What is the difference between ISO 27001 and ISO 27018?

ISO 27001 is the management-system standard for information security generally. ISO 27018 is a code of practice that extends it specifically to the protection of personal data (PII) in public cloud services. Organisations that process personal data in the cloud often address both together.

What is Annex A and the Statement of Applicability?

Annex A is ISO 27001’s catalogue of information-security controls (93 in the 2022 revision). The Statement of Applicability is the document that records which of those controls you apply, which you exclude, and the justification for each - decided by your risk assessment. It is the reference an auditor works from, so keeping it accurate and evidenced is central to certification.

How long does ISO 27001 certification take?

Typically six to twelve months for a first certification, depending on the size of your organisation and how much of a security management system already exists. The longest part is usually operating the ISMS long enough to produce real evidence - risk reviews, internal audits and a management review - before the Stage 2 audit.

Does ISO 27001 cover GDPR?

Not directly - ISO 27001 is about information security management, while the GDPR is a data-protection law with its own obligations. But a working ISMS provides much of the technical and organisational security the GDPR expects, and organisations frequently run the two together, adding ISO 27018 for the cloud-and-personal-data specifics.

Implementation

How to implement ISO 27001 - a practical path

An ISMS is built on a risk assessment and proven by evidence of operation. The route is well-trodden.

  1. Scope and context

    Define what the ISMS covers - which information, systems, sites and people - and set the security policy and objectives leadership will own.

  2. Assess and treat risk

    Identify your information-security risks, decide how to treat each, and select the Annex A controls that justify your Statement of Applicability.

  3. Apply the controls

    Put the chosen controls in place across the organisation - access, suppliers, joiners and leavers, physical security - with the policies and records to evidence them.

  4. Operate, audit and review

    Run the ISMS long enough to generate evidence, then internal-audit it and hold a management review - the proof of operation a certification body looks for.

  5. Certification and surveillance

    An accredited body runs the Stage 1 and Stage 2 audits; you close findings and the certificate is issued, kept live by annual surveillance and three-yearly recertification.

Manage your ISO 27001 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.