Compliance glossary
What is ISO/IEC 27001?
ISO/IEC 27001 is the international standard for information-security management systems (ISMS). Certification is issued by an accredited certification body following an audit.
In one line: ISO/IEC 27001 is the globally recognised certification that proves an organisation runs a managed, audited system for protecting its information.
Definition
ISO/IEC 27001 is published jointly by ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission). It sets out the requirements for establishing and maintaining an information security management system.
The 2022 update restructured the controls into four themes: Organisational (37 controls), People (8), Physical (14), and Technological (34), for a total of 93 controls. Certification requires an accredited audit body and remains valid for three years with annual surveillance audits.
Core components
- Management-system clauses (4 to 10) covering context, leadership, planning, support, operation, performance evaluation, and improvement.
- 93 Annex A 2022 controls organised into the four themes (Organisational, People, Physical, Technological).
- Statement of Applicability, a document listing the status of each control.
- Documented risk assessment and treatment processes.
- Regular internal audits, typically annual.
- Top-management reviews at planned intervals.
Why it matters
ISO 27001 has become the international trust signal for information security. It carries particular weight in international procurement processes outside North America, where buyers often expect the certificate before they will sign.
Because the standard is a management-system standard rather than a fixed control checklist, it demonstrates that security is governed and reviewed on an ongoing basis, not just implemented once.
How Lavawall® helps with ISO/IEC 27001
Lavawall® includes ISO/IEC 27001 as a first-class framework. The Annex A 2022 controls map to live evidence collected across Windows, macOS, and Linux endpoints and M365, Entra, Azure, and Google Workspace tenants, so the technological controls are evidenced continuously rather than reconstructed before each audit.
Statement of Applicability tracking, risk register support, and co-branded reporting help an MSP or lean IT team carry a client from gap assessment through certificate issue and the annual surveillance cycle.
Frequently asked
- ISO 27001 or SOC 2?
- ISO 27001 is generally more accepted internationally, while SOC 2 is more common with North American technology buyers. Which one to pursue depends on where your customers and prospects are.
- What is the difference between ISO 27001 and ISO 27002?
- ISO 27001 is the certifiable management-system standard. ISO 27002 is the implementation guide for the controls referenced in ISO 27001's Annex A.
- How long does ISO 27001 certification take?
- Initial certification typically takes 6 to 12 months from the initial gap assessment to certificate issue, depending on starting maturity.