ISO/IEC 27001:2022
Information Security Management System
Information security as a system, not as an antivirus.
Current edition: ISO/IEC 27001:2022.
What it is
What the standard covers
ISO/IEC 27001 sets the requirements to establish, operate and improve an information security management system. It starts from asset and risk identification, defines the statement of applicability across Annex A controls, and establishes how confidentiality, integrity and availability are protected across suppliers, people and processes, not technology alone.
Who it is for
- Technology, software and digital service companies
- BPO, contact centres and third-party data processors
- Financial and fiduciary institutions
- Any organisation handling personal or confidential data
Problems it helps manage
- Access rights without control or periodic review
- Dependence on technology vendors without risk assessment
- No plan for security incidents or data breaches
- Client security questionnaires that cannot be answered
Business benefits
- Information risks identified and treated
- Defined controls over access, suppliers and continuity
- Structured incident response
- Credibility with corporate clients and international contracts
Sectors
Where it applies
Support
What the engagement includes
- Documented initial gap analysis
- Management system design
- Complete, tailored documentation
- Implementation support, on site or remote
- Training for the key team
- Internal audit and closure of findings
- Readiness and support through the certification audit
Integration with other standards
This standard commonly integrates with: ISO 22301, ISO/IEC 20000-1, ISO/IEC 42001. An integrated system reduces duplicated documentation and audit time.
Stages
How the project runs
Gap analysis and planning
We review the real operation, not a questionnaire. We identify gaps against the standard, critical processes, existing evidence and regulatory risk.
Selecting the standard or combination
We define which standard answers the organisation's risk and objective. The choice is technical, not a matter of popularity.
Management system design
We structure processes, responsibilities, indicators and controls according to size, sector and applicable regulation.
Documentation development
We write policy, procedures, records and matrices tailored to the operation. No generic templates.
Guided implementation
We work with each process owner until the system is used day to day, not only stored in a folder.
Team training
We train the key team on the standard, on the system and on their role during the audit.
FAQ
Frequently asked questions — ISO/IEC 27001
Must all 93 Annex A controls be applied?
Is it only for the IT department?
Does it cover data protection compliance?
You may also need
Related standards
Business Continuity Management System
What the organisation does when something stops.
View details →ISO/IEC 20000-1:2018IT Service Management System
IT services with service levels committed and met.
View details →ISO/IEC 42001:2023Artificial Intelligence Management System
AI governance for organisations already using it.
View details →Next step
Every organisation is different. The right system starts with a gap analysis.
Write to us and we will arrange a strategy meeting: we review your current situation, define the right system, set scope and timelines and resolve technical and regulatory questions.
A certification done properly is not chased. It is built.
