Back to glossary

ISO 27001

2 min read

In security governance, ISO/IEC 27001:2022 is the international standard for an information security management system: a framework for managing security risk, not a checklist of controls. The edition is the point a client asks about first. The 2022 revision reorganised Annex A into ninety-three controls grouped in four themes, and it is the current version.

July 30, 2026
Compartir:

What it is

ISO 27001 is the international standard that sets the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS) within an organisation. It is a framework for managing risk.

Four features define it. It starts from risk: security risks are identified, assessed and treated systematically. It requires continual improvement, with periodic reviews of the ISMS. It supports legal and regulatory compliance by giving a structure the controls fit into. And certification, issued by an independent body, is what an organisation shows its customers.

How it works

ISO/IEC 27001 certifies an ISMS, an information security management system. The standard’s requirements are about the system: defining scope, assessing risk, selecting controls to treat that risk, documenting the selection in a Statement of Applicability, and running a continual cycle of monitoring and improvement. The controls themselves live in Annex A, and the 2022 revision restructured that annex into ninety-three controls grouped under four themes (organisational, people, physical and technological). A companion standard, ISO/IEC 27002, gives the detailed guidance on implementing those controls. The certificate attests that the management system exists and functions, decided by risk and evidenced in operation; it does not attest to a fixed list of technical measures.

What goes wrong

The version matters because certificates and controls differ between editions, and quoting ISO 27001 without the edition leaves a client without the one actionable detail: the current standard is the 2022 revision. Beyond that, the common misunderstanding is treating the standard as a control checklist rather than a management system, so a team implements Annex A controls and misses that certification is about the process that selects, evidences and improves them. From a security standpoint the failure is a static ISMS: risk assessed once at certification, controls chosen and never revisited, so the system manages nothing while the certificate stays valid. The standard’s value is the loop, and a loop that runs once is not a loop.

Where this shows up in an audit

Several Annex A controls concern testing security and managing technical vulnerabilities, and the standard requires evidence that selected controls operate effectively. Technical testing supplies that evidence: an assessment demonstrates whether the controls the ISMS relies on actually resist attack, and the report becomes the proof a certification body and an internal risk process both need. We name the 2022 edition in the work and frame findings so they feed the risk treatment and any neighbouring obligation, such as the ENS or NIS2. This is the testing that evidences your ISO 27001 controls work.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.