Skip to main content

Certification you can stand behind.

ISO/IEC 27001:2022

ISO 27001 Information Security Management Systems

Protect the data your customers trust you with, and prove it to their security teams.

Information security
  1. Information assets

    Customer data in

    In scope

  2. Access control

    Least privilege

  3. Encryption

    In transit and at rest

  4. Supplier security

    Vendors monitored

  5. Risk treatment

    SoA selects controls

  6. Incident response

    Detect and learn

    Learn returns to Risk treatment

  7. Threats

    External and internal

    Deflected returns to Incident response

  8. Trusted information

    Deals unblocked

SYS/04 · Control gates

Information assets pass risk-selected gates in the ISMS; incident response deflects threats, evidence earns trust.

What ISO 27001 is

ISO/IEC 27001 defines an information security management system: risk assessment, a statement of applicability across the Annex A controls, and the governance that keeps security decisions current as threats change. The 2022 edition restructured the controls into organizational, people, physical and technological themes.

CORE audits ISO 27001 by testing whether the Statement of Applicability describes a system that exists. Your auditor works from the risk assessment outward: does the scope match the services and data flows you claim, is each Annex A inclusion and exclusion justified by assessed risk, and does the operating evidence support the control as written. Access reviews, change records, log and monitoring output, supplier assessments, incident tickets and awareness records are sampled at source. The findings raised most often concern a Statement of Applicability drafted once and never revisited, risk treatment plans without owners or dates, and access reviews that were signed but not performed.

Who it is for

  • Software, SaaS and technology companies whose enterprise customers require an ISO 27001 certificate
  • Organizations whose contracts or regulators require independently audited information security
  • Suppliers to government and regulated industries with certification written into the tender
  • Certified organizations transferring an active ISO 27001 certificate from another certification body
  • Organizations that certified to the 2013 edition and need the 2022 transition assessed

Business outcomes

What leadership should expect the system to change, in operational terms.

Sales acceleration

A certificate of registration gives enterprise procurement a third-party answer to the questions a security questionnaire asks, so vendor review turns on evidence rather than assertion.

Risk-based spending

Controls are selected and justified against assessed risk, so budget follows exposure.

Incident readiness

Defined detection, response and learning processes reduce the cost and chaos of security events.

Regulatory alignment

The ISMS provides the organizational measures data-protection regulation expects to see.

Benefits beyond the certificate

  • One security narrative

    Policies, risk register and statement of applicability tell a consistent story to every stakeholder.

  • Supplier chain assurance

    Supplier security requirements and monitoring extend protection to your critical vendors.

  • Board-level ownership

    Governance requirements put information risk where it belongs, with leadership.

  • Culture of care

    Awareness, screening and acceptable-use controls make people part of the defense.

  • Compatibility

    Integrates with ISO 9001 governance and pairs naturally with ISO 22301 for resilience.

Fiber-optic strands glowing electric blue
ISO 27001 in the field

The main requirements

The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.

01

Context and scope (Clause 4)

Define the ISMS boundary: services, locations, data flows and interested parties.

02

Leadership and policy (Clause 5)

Information security policy, roles and top-management commitment.

03

Risk assessment and treatment (Clause 6)

A repeatable risk methodology, risk treatment plan and the Statement of Applicability across Annex A.

04

Support (Clause 7)

Competence, awareness, communication and documented information control.

05

Operation (Clause 8)

Execute the risk treatment plan and control operational security processes.

06

Annex A control themes

93 controls across organizational, people, physical and technological themes, applied as risk requires.

07

Evaluation and improvement (Clauses 9 and 10)

Monitoring, internal ISMS audits, management review and corrective action.

What each requirement buys you

Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.

Requirement themes

Context and scope (Clause 4) chiefly drives 2 of 4 ISO 27001 outcomes.

Outcomes it drives

Sales acceleration

A certificate of registration gives enterprise procurement a third-party answer to the questions a security questionnaire asks, so vendor review turns on evidence rather than assertion.

Risk-based spending

Controls are selected and justified against assessed risk, so budget follows exposure.

Incident readiness

Defined detection, response and learning processes reduce the cost and chaos of security events.

Regulatory alignment

The ISMS provides the organizational measures data-protection regulation expects to see.

How CORE audits ISO 27001

Step 1

Stage 1 reviews scope, risk method and the Statement of Applicability

Your auditor confirms the ISMS boundary against the services, locations and data flows you have declared, reads the risk assessment methodology and results, examines the Statement of Applicability for justified inclusions and exclusions, and checks that an internal ISMS audit and management review have taken place.

Step 2

Stage 2 tests the controls against evidence

The audit samples the applicable Annex A controls across the organizational, people, physical and technological themes: access provisioning and review, change and vulnerability management, logging and monitoring, cryptography and key handling, supplier security, physical access, incident handling, and the execution of the risk treatment plan.

Step 3

Surveillance samples risk and change

Year 1 and Year 2 audits sample changes to scope, services and infrastructure, updates to the risk assessment and Statement of Applicability, security incidents and their handling, access reviews and supplier assessments performed since the last visit, and the closure of previous findings.

Step 4

Recertification revisits the whole cycle

In Year 3 the audit reviews three years of the ISMS: whether risk assessment has genuinely been repeated, whether treatment plans completed, whether incidents changed the control set, whether the scope still matches what customers are told, and whether governance has held through changes of personnel.

What your auditor expects to see

Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.

  1. 01Internal ISMS audit completed

    A full internal audit of the clauses and applicable Annex A controls, performed by auditors independent of the systems and teams they audited, with reports available.

  2. 02Management review held

    Minuted review covering risk status, incidents, control performance, audit results, supplier and interested-party feedback, and improvement, with decisions recorded.

  3. 03Records covering a meaningful period

    Access reviews, change approvals, vulnerability remediation, backup and restore tests, monitoring output and awareness completion spanning enough time to show the controls running rather than being configured.

  4. 04Corrective actions closed

    Nonconformities and incidents showing root-cause analysis, the control change made, and evidence that the change is operating.

  5. 05Competence demonstrable

    Records connecting named people to defined security responsibilities, including risk owners, control owners and anyone with privileged access.

  6. 06Scope and Statement of Applicability defined

    A written scope naming services, locations and data flows, and a current Statement of Applicability whose justifications trace back to the risk assessment.

  7. Certification decision

    With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.

CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.

The optional pre-assessment

Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of the governance clauses and the applicable Annex A themes of ISO/IEC 27001:2022. It samples evidence the way a Stage 2 audit does and returns a written report identifying where the ISMS would not currently satisfy an auditor, including any gap between the Statement of Applicability and the controls in operation.

The report describes findings only. It does not draft your Statement of Applicability, choose your controls or design your risk methodology, because authoring that work would disqualify CORE from auditing it under ISO/IEC 17021-1. Organizations moving from the 2013 edition often use the pre-assessment to see the effect of the restructured control set before Stage 1; where implementation help is needed, see /resources/find-a-consultant.

What you receive

  • Findings against each clause of the standard
  • Where the evidence is missing or incomplete
  • Whether Stage 2 could proceed on today's records
  • The same sampling method a certification audit uses
How the pre-assessment works

Training for ISO 27001

Courses that teach how the standard is written and how it is audited.

All courses

ISO 27001 questions, answered straight

Ready to certify to ISO 27001?

Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.