Start a free trial
Menu

ISO/IEC 27001

ISO 27001 information security management

Organisations that must protect information - including defence suppliers handling controlled data.

ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.

What it is

What ISO 27001 is

ISO 27001 is the international standard for an information security management system (ISMS) - a systematic way to protect the confidentiality, integrity and availability of information by assessing risk and applying controls. It is the recognised benchmark for “this organisation takes security seriously and can prove it”, and for defence, technology and dual-use suppliers it is increasingly a contractual expectation rather than a differentiator.

An ISMS is not a firewall or an antivirus product. It is the management system around your security: the policies, the risk decisions, the controls and the evidence that they are actually operating. ISO 27001 defines what that system must contain; the technology you use to satisfy it is your choice.

Why ISO 27001 exists

Security incidents rarely come from a lack of tools - they come from unmanaged risk: an unpatched system nobody owned, a supplier nobody assessed, an access right nobody revoked. ISO 27001 exists to make security a managed, evidenced discipline rather than a collection of good intentions. A certificate tells a customer that an independent auditor has checked not only that you have controls, but that you understand your risks and manage them on a cycle.

Who needs ISO 27001

Any organisation that holds information other people care about - customer data, intellectual property, controlled technical information. In practice it is driven by:

  • Customer and contractual demand: enterprise and government buyers increasingly require it before sharing data or awarding work, and defence contracts may mandate it for handling controlled information.
  • Regulation and adjacency: it is the backbone that frameworks such as ISO 27018 (cloud privacy), the EU NIS2 directive and many GDPR programmes lean on.
  • Risk itself: for a company whose product or reputation depends on trust, a managed ISMS is simply how you avoid the incident that ends the conversation.

How the standard is structured

ISO 27001:2022 has two parts. The management-system clauses (4–10) mirror ISO 9001 - context, leadership, planning, support, operation, evaluation, improvement - so the two standards fit together naturally. What makes it an information-security standard is the risk process and Annex A:

  • A risk assessment and treatment process: identify your information-security risks, decide how to treat each one, and record the decision.
  • Annex A: a catalogue of 93 controls in the 2022 revision, grouped into organisational, people, physical and technological themes, to draw on when treating risk.
  • The Statement of Applicability (SoA): the document that states which Annex A controls you apply, which you do not, and why - the spine of the whole certification.

Certification is awarded by an accredited body after a two-stage audit, with annual surveillance and a three-yearly recertification, exactly as with ISO 9001.

Common misconceptions

  • It is not an IT-department project. Information security spans HR (joiners and leavers), procurement (supplier risk), facilities (physical access) and leadership (risk appetite) - the standard makes that explicit.
  • It is not “buy the controls”. Annex A is a menu, not a checklist: you apply the controls your risk assessment justifies and must be able to explain the ones you leave out.
  • It is not one-and-done. The certificate lapses without the ongoing risk reviews, internal audits and management reviews that keep the system alive.

Put ISO/IEC 27001 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

How ComplyTrain helps you meet it

ComplyTrain gives you the framework to build and run your ISMS, and to hold the evidence an ISO 27001 audit asks for:

  • Security policies and procedures under version control, with signed acknowledgement - Document Control
  • Annex A controls captured as requirements and traced to the evidence that meets them - Requirements Management
  • Your information-security risk assessment and treatment, kept as a living register - Risk Management
  • Supplier security assessed and recorded - Vendor Management
  • Security-awareness training assigned, tested and recorded - Training Management

ComplyTrain is not itself ISO 27001 certified, and does not need to be: it is the system you build and run your own ISO 27001 program in. The certificate is yours to earn - ComplyTrain is where the evidence for it lives.

Request access to this standard

Tell us how you need to work with ISO/IEC 27001 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Is ComplyTrain ISO 27001 certified?

No - and we will not imply otherwise. ComplyTrain is the software you use to build, run and evidence your own ISO 27001 information security management system. Your certificate is awarded to your organisation by an accredited body; ComplyTrain is where the policies, risk assessments, controls and records that earn it are managed.

What is the difference between ISO 27001 and ISO 27018?

ISO 27001 is the management-system standard for information security generally. ISO 27018 is a code of practice that extends it specifically to the protection of personal data (PII) in public cloud services. Organisations that process personal data in the cloud often address both together.

What is Annex A and the Statement of Applicability?

Annex A is ISO 27001’s catalogue of information-security controls (93 in the 2022 revision). The Statement of Applicability is the document that records which of those controls you apply, which you exclude, and the justification for each - decided by your risk assessment. It is the reference an auditor works from, so keeping it accurate and evidenced is central to certification.

How long does ISO 27001 certification take?

Typically six to twelve months for a first certification, depending on the size of your organisation and how much of a security management system already exists. The longest part is usually operating the ISMS long enough to produce real evidence - risk reviews, internal audits and a management review - before the Stage 2 audit.

Does ISO 27001 cover GDPR?

Not directly - ISO 27001 is about information security management, while the GDPR is a data-protection law with its own obligations. But a working ISMS provides much of the technical and organisational security the GDPR expects, and organisations frequently run the two together, adding ISO 27018 for the cloud-and-personal-data specifics.

Implementation

How to implement ISO 27001 - a practical path

An ISMS is built on a risk assessment and proven by evidence of operation. The route is well-trodden.

  1. Scope and context

    Define what the ISMS covers - which information, systems, sites and people - and set the security policy and objectives leadership will own.

  2. Assess and treat risk

    Identify your information-security risks, decide how to treat each, and select the Annex A controls that justify your Statement of Applicability.

  3. Apply the controls

    Put the chosen controls in place across the organisation - access, suppliers, joiners and leavers, physical security - with the policies and records to evidence them.

  4. Operate, audit and review

    Run the ISMS long enough to generate evidence, then internal-audit it and hold a management review - the proof of operation a certification body looks for.

  5. Certification and surveillance

    An accredited body runs the Stage 1 and Stage 2 audits; you close findings and the certificate is issued, kept live by annual surveillance and three-yearly recertification.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Manage your ISO 27001 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Information security management (ISO/IEC 27000 family)

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.