What is ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It sets requirements for how an organization identifies information risks, decides how to address them and checks whether its approach works.
What does the management system do?
An ISMS brings together responsibilities, risk decisions, security measures and regular review. Its purpose is to protect the confidentiality, integrity and availability of information: who can access it, whether it is accurate and whether it is available when needed.
ISO is the International Organization for Standardization; IEC is the International Electrotechnical Commission. Their joint standard applies to organizations of different sizes and sectors. Certification assesses the management system within a defined scope, such as a service, business unit or organization.
Do we have to implement every Annex A control?
No. Annex A is a reference set, not a universal implementation checklist. Choose necessary controls using risk assessment and relevant stakeholder requirements, including legal and contractual obligations. Compare that selection with Annex A to check for omissions.
Controls can come from other sources or be designed by your organization. The Statement of Applicability records necessary controls, reasons for inclusion, implementation status and justified Annex A exclusions. Requirements in clauses 4 to 10 cannot be excluded.
What makes a control decision defensible?
Be able to explain the information or activity at risk, who depends on it, what could go wrong and why the selected response is appropriate. Risk acceptance criteria define what the organization considers acceptable. Risk owners approve the treatment plan and accept the remaining risk.
For example, a service provider may need to protect customer files because of both a contractual commitment and the risk of unauthorized access. Its chosen measures and supporting evidence should address that need. A preference to avoid implementing a measure does not remove a binding obligation.
Can we be certified while improvements are still in progress?
Some improvements may remain in progress, but a plan alone is not enough. Clause 8.3 requires implementation of the risk treatment plan. The audit needs evidence of an operating management system, treatment activities and evaluation of results.
Unfinished work is assessed against the requirements, the risks and the evidence. It may result in a nonconformity that must be addressed through the certification process. Annual surveillance checks continuing conformity; it is not a general extension for implementing necessary controls.
What will the auditor examine?
Expect discussion of your scope, risks, treatment decisions and Statement of Applicability, together with evidence from daily operations. Internal audit, management review, objectives, competence and corrective action are also part of the management system.
Stage 1 assesses the documented system and readiness for Stage 2. Stage 2 evaluates implementation and effectiveness. Complade makes the certification decision separately from the audit team. The detailed guide below explains requirements and examples of evidence.
When is ISO 27001 a useful choice?
It is a useful option when customers ask for an internationally recognized management system certificate or when an organization needs a consistent way to govern information risk across services and locations. Start with the actual customer requirement and the scope they expect.
CyberSecure Canada addresses a prescribed cybersecurity baseline. The two can be complementary, but one certificate does not automatically satisfy the other programme. SOC 2 (System and Organization Controls 2) is a separate assurance examination, not ISO management system certification.
From understanding to audit preparation
Sources and reference documents
This guide provides general explanations. The applicable standard and programme rules remain the basis for certification.
