Information security
ISO 27001: requirements, controls and how to stay continuously audit-ready
In short
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It sets out how an organization should identify information security risks and manage them with a documented set of policies, processes and controls. Certification is issued by an accredited body after a two-stage audit and is maintained through annual surveillance over a three-year cycle.
Last reviewed: August 2026
Who it applies to
ISO 27001 is voluntary and applies to any organization that wants to demonstrate systematic management of information security — most commonly SaaS and technology companies, financial services, healthcare, and any business handling sensitive customer data. It is increasingly requested in B2B procurement and security questionnaires as a baseline for trust.
Core requirements
The standard has two parts. Clauses 4–10 define the management system itself: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A is a reference set of 93 controls (in the 2022 revision) grouped into four themes — organizational, people, physical and technological.
- Define the ISMS scope and obtain leadership commitment
- Run a risk assessment and risk treatment process
- Produce a Statement of Applicability (SoA) justifying included/excluded controls
- Set security objectives and measure them
- Operate internal audits and a management review
- Drive continual improvement through corrective actions
Typical compliance challenges
- Keeping the risk register, SoA and evidence in sync as the business changes
- Proving controls actually operate all year — not just the week before an audit
- Collecting evidence from many systems (identity, cloud, code, HR)
- Reconstructing an audit trail months after decisions were made
- Avoiding duplicate work when ISO 27001 overlaps SOC 2, NIS2 or GDPR
How organizations traditionally handle it
The classic approach is a consulting project: an external specialist runs the gap analysis, writes the policies, and prepares evidence for the audit. It works, but it is expensive, front-loaded, and the knowledge often leaves with the consultant. Between audits the ISMS drifts, and the next surveillance audit becomes another scramble.
What can reasonably be automated
A large share of the ongoing work is repetitive and rules-based, which makes it a good fit for automation:
- Continuous control checks against live system state (e.g. access reviews, MFA, logging)
- Evidence collection and time-stamping instead of manual screenshots
- Mapping one control to multiple frameworks so evidence is reused
- Gap analysis against the requirements
- Reminders and ownership for recurring tasks and the audit calendar
Evidence and documentation auditors expect
- ISMS scope, information security policy and objectives
- Risk assessment methodology, risk register and risk treatment plan
- Statement of Applicability
- Records that controls operate: access reviews, change logs, training records, supplier assessments
- Internal audit reports and management review minutes
- Corrective actions and nonconformity records
Continuous monitoring and verification
The 2022 revision strengthens the expectation that controls are monitored, not just documented. Continuous verification — checking control state on a schedule and opening a finding the moment something drifts — keeps the ISMS true between audits and turns the surveillance audit into a formality rather than a project.
How Isodora supports ISO 27001
Isodora runs the ongoing ISMS work so your team spends time on judgement, not paperwork.
Fit/Gap analysis
Map your current state to every ISO 27001 requirement and get a prioritized path to certification-ready.
Automated controls
Controls are verified against live system state on a schedule; drift opens an owned, prioritized finding automatically.
Evidence that reuses itself
Evidence collected for ISO 27001 counts toward SOC 2, NIS2 and GDPR — map one control to many frameworks.
Regulator-grade audit trail
A complete, time-stamped trail is already there when the auditor asks — no months of reconstruction.
Isodora helps you prepare and maintain an ISMS. Certification is issued by an independent accredited body after its own audit; no software can guarantee a certificate.
Frequently asked questions
- How long does ISO 27001 certification take?
- For a small or mid-sized company, first certification typically takes three to nine months, depending on how mature your controls already are and how quickly you can close gaps. The certificate is then valid for three years with annual surveillance audits.
- What is the difference between ISO 27001 and SOC 2?
- ISO 27001 certifies a management system against an international standard; SOC 2 is a US attestation report where an auditor gives an opinion on controls against the Trust Services Criteria. They share a lot of underlying evidence, so many companies pursue both and reuse controls across them.
- How many controls are in ISO 27001?
- The 2022 revision of Annex A lists 93 controls across four themes: organizational, people, physical and technological. You justify which apply in your Statement of Applicability.
- Does ISO 27001 cover GDPR?
- Partly. A strong ISMS supports GDPR’s security-of-processing requirement, but GDPR adds obligations ISO 27001 does not — records of processing, DPIAs, data-subject rights and breach notification. Isodora treats them as overlapping frameworks so shared evidence is reused.