StandardGlobal

ISO/IEC 27001

ISO / IEC · Version 2022 · October 2022

The international standard for Information Security Management Systems.

Overview

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. The 2022 revision reduced the Annex A control set from 114 controls across 14 domains to 93 controls organized into four themes: Organizational, People, Physical, and Technological. Eleven new controls were added to address threat intelligence, cloud security configuration, data masking, web filtering, and physical security monitoring, all of which were absent from the 2013 edition.

Certification is issued by accredited national certification bodies such as BSI, TÜV Rheinland, and Bureau Veritas. The audit runs in two stages: Stage 1 reviews your ISMS documentation and scoping decisions, Stage 2 assesses whether those controls are actually operating. Certificates run for three years with annual surveillance audits. The Statement of Applicability is the document auditors read before anything else. It maps every Annex A control to your environment, records whether each one applies, and justifies exclusions. Every exclusion you make will be examined.

Who Needs This

Technology and SaaS companies selling into enterprise or regulated markets

Cloud service providers whose enterprise customers require it contractually

Financial services, healthcare, and government technology suppliers

Organizations pursuing international business where customers request proof of certification

Companies seeking a structured ISMS before pursuing SOC 2, FedRAMP, or CMMC

Structure at a Glance

Policies, roles, responsibilities, threat intelligence, information classification, supply chain security, and intellectual property rights.

Pre-employment screening, terms of employment, security awareness training, remote working, and off-boarding procedures.

Physical entry security, protection against environmental threats, equipment maintenance, clear desk and screen policies, and physical media disposal.

User endpoints, access management, authentication, cryptography, network security, application security, vulnerability management, configuration management, and data leakage prevention.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

Statement of Applicability Entry

Use this when drafting or updating SoA entries for each Annex A control.

You are a certified ISO 27001:2022 Lead Implementer. I need to write a Statement of Applicability entry for the following Annex A control: [CONTROL ID AND NAME]. My organization is a [TYPE AND SIZE OF ORGANIZATION] operating in [SECTOR]. Our current implementation of this control is: [DESCRIBE CURRENT STATE]. Provide: (1) an applicability determination with business justification, (2) an implementation description in present tense suitable for the SoA, (3) three specific evidence artifacts an auditor would expect to see, and (4) any dependencies on other Annex A controls or clauses.

Risk Assessment Scenario

Use this during formal risk assessment to evaluate a specific threat scenario.

You are assisting with an ISO 27001:2022 risk assessment. Asset: [DESCRIBE ASSET]. Threat scenario: [DESCRIBE THREAT]. Existing controls in place: [LIST CURRENT CONTROLS]. Using a likelihood and impact scale from 1 to 5, evaluate this risk. Provide: likelihood score with rationale, impact score across Confidentiality, Integrity, and Availability separately, inherent risk rating, residual risk rating with current controls applied, and a list of Annex A controls most relevant to reducing this risk further.

Gap Assessment per Control

Use this to assess conformance with a specific control during a readiness audit.

You are a certified ISO 27001:2022 Lead Auditor conducting a Stage 2 readiness review. Evaluate the following evidence for control [CONTROL ID] — [CONTROL NAME]: [PASTE EVIDENCE DESCRIPTION OR DOCUMENT SUMMARY]. Rate conformance as: Fully Conformant, Partially Conformant, or Not Conformant. Provide: the gap description, the root cause, a recommended remediation action with an estimated effort level, and a sample audit finding written in the format used in formal certification audit reports.

Internal Audit Checklist

Use this to generate a structured internal audit checklist for a control theme.

Generate an ISO 27001:2022 internal audit checklist for the [THEME] theme (Organizational, People, Physical, or Technological). For each control in this theme that applies to a [TYPE OF ORGANIZATION], provide: the control objective in plain language, two interview questions for the control owner, two document requests, and one observation or testing procedure. Format as a table with columns: Control ID, Control Name, Interview Questions, Documents Requested, Testing Procedure.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Treating the SoA as a checkbox list. Auditors examine every exclusion. If you exclude A.8.23 (Web Filtering) because you think it does not apply, you need a documented business reason that holds up to scrutiny.

2

Risk assessment methodology defined after the risk assessment is already done. Clause 6.1.2 requires the methodology to be established first. The order matters and auditors will check it.

3

ISMS scope defined too broadly to avoid difficult conversations. An overly broad scope creates more audit surface. Define it tightly and accurately.

4

Stage 1 audit passed but controls not yet operational. Stage 2 tests whether controls are working, not just documented. If your vulnerability management process was implemented the week before Stage 2, that shows.

5

Surveillance audits treated as formalities. Findings from surveillance audits accumulate. Unresolved major nonconformities from the first surveillance can lead to certificate suspension at the second.

Cross-Framework Mapping

SOC 2

ISO 27001 Annex A maps substantially to SOC 2 Common Criteria. Organizations with ISO 27001 certification often use it as the foundation for a SOC 2 readiness program.

View Detailed Mapping ↗

NIST CSF 2.0

ISO 27001:2022 aligns closely with the Protect and Detect functions. NIST provides an official mapping document.

View Detailed Mapping ↗

CMMC Level 2

A mature ISO 27001 ISMS addresses a significant portion of NIST 800-171 practices, particularly in the AC, IA, AU, and SC families.

View Detailed Mapping ↗

All content sourced from official issuing body documentation.

Official source ↗

Standard

ISO/IEC 27001