What it is
What ISO 27001 is
ISO 27001 is the international standard for an information security management system (ISMS) - a systematic way to protect the confidentiality, integrity and availability of information by assessing risk and applying controls. It is the recognised benchmark for “this organisation takes security seriously and can prove it”, and for defence, technology and dual-use suppliers it is increasingly a contractual expectation rather than a differentiator.
An ISMS is not a firewall or an antivirus product. It is the management system around your security: the policies, the risk decisions, the controls and the evidence that they are actually operating. ISO 27001 defines what that system must contain; the technology you use to satisfy it is your choice.
Why ISO 27001 exists
Security incidents rarely come from a lack of tools - they come from unmanaged risk: an unpatched system nobody owned, a supplier nobody assessed, an access right nobody revoked. ISO 27001 exists to make security a managed, evidenced discipline rather than a collection of good intentions. A certificate tells a customer that an independent auditor has checked not only that you have controls, but that you understand your risks and manage them on a cycle.
Who needs ISO 27001
Any organisation that holds information other people care about - customer data, intellectual property, controlled technical information. In practice it is driven by:
- Customer and contractual demand: enterprise and government buyers increasingly require it before sharing data or awarding work, and defence contracts may mandate it for handling controlled information.
- Regulation and adjacency: it is the backbone that frameworks such as ISO 27018 (cloud privacy), the EU NIS2 directive and many GDPR programmes lean on.
- Risk itself: for a company whose product or reputation depends on trust, a managed ISMS is simply how you avoid the incident that ends the conversation.
How the standard is structured
ISO 27001:2022 has two parts. The management-system clauses (4–10) mirror ISO 9001 - context, leadership, planning, support, operation, evaluation, improvement - so the two standards fit together naturally. What makes it an information-security standard is the risk process and Annex A:
- A risk assessment and treatment process: identify your information-security risks, decide how to treat each one, and record the decision.
- Annex A: a catalogue of 93 controls in the 2022 revision, grouped into organisational, people, physical and technological themes, to draw on when treating risk.
- The Statement of Applicability (SoA): the document that states which Annex A controls you apply, which you do not, and why - the spine of the whole certification.
Certification is awarded by an accredited body after a two-stage audit, with annual surveillance and a three-yearly recertification, exactly as with ISO 9001.
Common misconceptions
- It is not an IT-department project. Information security spans HR (joiners and leavers), procurement (supplier risk), facilities (physical access) and leadership (risk appetite) - the standard makes that explicit.
- It is not “buy the controls”. Annex A is a menu, not a checklist: you apply the controls your risk assessment justifies and must be able to explain the ones you leave out.
- It is not one-and-done. The certificate lapses without the ongoing risk reviews, internal audits and management reviews that keep the system alive.