Skip to content
Oluma Cyber Security Awareness
Oluma Cyber Security
Framework Files · No. 10
Standard · Security Management

ISO 27001

The international standard for managing information security — and the certificate customers around the world ask to see before they trust you.

:2022 edition 93 Controls 4 Themes Certifiable
01 The Problem

“Trust us, we’re secure” — but how would anyone know?

Companies could buy every security tool on the market and still be a mess, because security isn’t about products — it’s about managing risk consistently over time. And when one business wanted to trust another with its data, there was no neutral, globally recognized way to prove that the other side actually had its act together.

Every customer ran its own questionnaire; every vendor answered differently. There was no shared yardstick for “well-managed security.”

02 Why It Was Created

A certifiable system, not just a checklist

ISO 27001 defines an Information Security Management System (ISMS) — a structured, repeatable way to identify risks and manage them — that an independent auditor can certify. That certificate becomes a portable proof of trust.

The core idea

Don’t just install controls — build a living management system that finds your risks, treats them, and continually improves. Then have a third party verify it.

03 The Story Behind It

From a British standard to a global passport

1995
British roots
It began as the UK’s BS 7799 — one of the first attempts to codify information-security best practice.
2005
Goes international
Adopted by ISO and IEC as ISO/IEC 27001, making it a globally recognized standard.
2013
Modernized
A major revision aligned it with other ISO management standards.
2022
The current edition
ISO 27001:2022 streamlined Annex A to 93 controls across four themes. Organizations had until 31 October 2025 to transition off the 2013 version.
04 How It Works

A management system, plus a menu of controls

ISO 27001 has two halves. The core clauses (4–10) define the ISMS itself — understanding context, leadership, risk assessment and treatment, operation, evaluation, and continual improvement. These are what you’re actually certified against. The second half, Annex A, is a menu of 93 controls grouped into four themes:

Organizational · 37
Policies & governance
The administrative backbone — policies, supplier management, access rules, cloud governance.
People · 8
The human layer
Training, awareness, screening, remote work, and incident reporting.
Physical · 14
The tangible world
Facilities, equipment, clear-desk practices, and physical monitoring.
Technological · 34
The digital perimeter
Encryption, access control, logging, secure coding, and network defense.

You don’t implement all 93 — you choose based on a risk assessment and justify your choices in a Statement of Applicability (SoA). An accredited body then certifies you, with annual check-ins over a three-year cycle.

05 Real-World Example

A SaaS company chasing enterprise deals

A growing SaaS startup keeps hitting the same wall: big customers won’t sign without proof of security. So it pursues ISO 27001.

The road to certification
Turning security into a sales asset
  • Define the ISMS scope and get leadership behind it
  • Run a risk assessment and build a treatment plan
  • Select controls and write the Statement of Applicability
  • Pass the Stage 1 (documentation) and Stage 2 (practice) audits
  • Earn the certificate — and put it on the sales deck

Suddenly, the security questionnaire becomes a one-line answer: “We’re ISO 27001 certified.”

06 Who Uses It

The world’s go-to security certification

☁️
SaaS & cloud
Vendors proving security to enterprise and global customers.
🏢
Enterprises
Large organizations standardizing security across the business.
🌐
Global firms
Anyone needing an internationally recognized proof of trust.

It pairs with ISO 27002 (the how-to guide for the controls) and maps cleanly to the NIST CSF, SOC 2, and many regulations.

guided by ISO 27002maps to NIST CSFoverlaps SOC 2
07 Career Relevance

Among the most valuable GRC credentials

ISO 27001 is core GRC territory. Building and running an ISMS — risk assessments, SoAs, internal audits — is everyday work, and the Lead Implementer and Lead Auditor certifications are gold on a résumé.

Because it’s globally recognized, the skills travel anywhere. Together with SOC 2, it accounts for the lion’s share of certifications companies pursue — so demand is steady and worldwide.

08 Strengths & Challenges

Honest trade-offs

✦ Strengths

  • Globally recognized and certifiable
  • Risk-based and flexible to any organization
  • Builds a lasting system, not a one-off effort
  • Maps to almost every other framework

⚠ Challenges

  • Real cost, time, and effort to certify
  • Documentation-heavy
  • Certification must be maintained continuously
  • Can become bureaucratic if done for the badge alone
09 Final Takeaway
ISO 27001 is the international passport for trust.

It proves you don’t just own security tools — you manage security as a living system, verified by an independent auditor. It’s the certificate customers ask for by name, and one of the most portable credentials a GRC career can be built on.

Rising together.Oluma Cyber Security · Framework Files
Next in the series → SOC 2