O Oluma Cyber Security Framework Files · No. 10 Standard · Security Management ISO 27001 The international standard for managing information security — and the certificate customers around the world ask to see before they trust you. :2022 edition 93 Controls 4 Themes Certifiable ISO :2022 · the ISMS How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem “Trust us, we’re secure” — but how would anyone know? Companies could buy every security tool on the market and still be a mess, because security isn’t about products — it’s about managing risk consistently over time. And when one business wanted to trust another with its data, there was no neutral, globally recognized way to prove that the other side actually had its act together. Every customer ran its own questionnaire; every vendor answered differently. There was no shared yardstick for “well-managed security.” 02 Why It Was Created A certifiable system, not just a checklist ISO 27001 defines an Information Security Management System (ISMS) — a structured, repeatable way to identify risks and manage them — that an independent auditor can certify. That certificate becomes a portable proof of trust. The core ideaDon’t just install controls — build a living management system that finds your risks, treats them, and continually improves. Then have a third party verify it. 03 The Story Behind It From a British standard to a global passport 1995British rootsIt began as the UK’s BS 7799 — one of the first attempts to codify information-security best practice. 2005Goes internationalAdopted by ISO and IEC as ISO/IEC 27001, making it a globally recognized standard. 2013ModernizedA major revision aligned it with other ISO management standards. 2022The current editionISO 27001:2022 streamlined Annex A to 93 controls across four themes. Organizations had until 31 October 2025 to transition off the 2013 version. 04 How It Works A management system, plus a menu of controls ISO 27001 has two halves. The core clauses (4–10) define the ISMS itself — understanding context, leadership, risk assessment and treatment, operation, evaluation, and continual improvement. These are what you’re actually certified against. The second half, Annex A, is a menu of 93 controls grouped into four themes: Organizational · 37Policies & governanceThe administrative backbone — policies, supplier management, access rules, cloud governance. People · 8The human layerTraining, awareness, screening, remote work, and incident reporting. Physical · 14The tangible worldFacilities, equipment, clear-desk practices, and physical monitoring. Technological · 34The digital perimeterEncryption, access control, logging, secure coding, and network defense. You don’t implement all 93 — you choose based on a risk assessment and justify your choices in a Statement of Applicability (SoA). An accredited body then certifies you, with annual check-ins over a three-year cycle. 05 Real-World Example A SaaS company chasing enterprise deals A growing SaaS startup keeps hitting the same wall: big customers won’t sign without proof of security. So it pursues ISO 27001. The road to certificationTurning security into a sales asset Define the ISMS scope and get leadership behind it Run a risk assessment and build a treatment plan Select controls and write the Statement of Applicability Pass the Stage 1 (documentation) and Stage 2 (practice) audits Earn the certificate — and put it on the sales deck Suddenly, the security questionnaire becomes a one-line answer: “We’re ISO 27001 certified.” 06 Who Uses It The world’s go-to security certification ☁️SaaS & cloudVendors proving security to enterprise and global customers. 🏢EnterprisesLarge organizations standardizing security across the business. 🌐Global firmsAnyone needing an internationally recognized proof of trust. It pairs with ISO 27002 (the how-to guide for the controls) and maps cleanly to the NIST CSF, SOC 2, and many regulations. guided by ISO 27002maps to NIST CSFoverlaps SOC 2 07 Career Relevance Among the most valuable GRC credentials ISO 27001 is core GRC territory. Building and running an ISMS — risk assessments, SoAs, internal audits — is everyday work, and the Lead Implementer and Lead Auditor certifications are gold on a résumé. Because it’s globally recognized, the skills travel anywhere. Together with SOC 2, it accounts for the lion’s share of certifications companies pursue — so demand is steady and worldwide. 08 Strengths & Challenges Honest trade-offs ✦ StrengthsGlobally recognized and certifiableRisk-based and flexible to any organizationBuilds a lasting system, not a one-off effortMaps to almost every other framework ⚠ ChallengesReal cost, time, and effort to certifyDocumentation-heavyCertification must be maintained continuouslyCan become bureaucratic if done for the badge alone 09 Final Takeaway ISO 27001 is the international passport for trust.It proves you don’t just own security tools — you manage security as a living system, verified by an independent auditor. It’s the certificate customers ask for by name, and one of the most portable credentials a GRC career can be built on.