Skip to content
Amrani Academy

1. What ISO 27001 is

ISO 27001:2022, Annex A, and certification

The current version of the standard is ISO/IEC 27001:2022, which replaced the 2013 edition. If you see references to the old version, the core ideas are the same, but the control set was reorganised.

The structure of the standard

The main body of the standard (clauses 4 to 10) contains the mandatory requirements for the ISMS itself: understanding the organisation's context, leadership commitment, planning and risk assessment, resources and awareness, operating the controls, evaluating performance, and improvement.

Annex A then provides a reference set of 93 security controls, grouped into four themes:

  • Organisational controls, such as policies, supplier security, and incident management
  • People controls, such as screening, training, and responsibilities after employment ends
  • Physical controls, such as secure areas, entry controls, and clear desk rules
  • Technological controls, such as access management, malware protection, and backups

An organisation does not blindly apply all 93. It selects the controls its risk assessment justifies and records that reasoning in a document called the Statement of Applicability.

Certification and external audits

An organisation can claim to follow ISO 27001, but certification means an independent, accredited certification body has audited the ISMS and confirmed it meets the standard. Certification runs on a cycle: an initial audit, then regular surveillance audits, then a full recertification audit, typically on a three-year cycle. Auditors can and do speak to ordinary staff, not just managers.

Why organisations pursue it

Certification is a strong, independently verified signal that an organisation takes security seriously. Customers increasingly demand it before sharing their data. Many tenders, especially public sector and enterprise ones, require it or score it heavily. Some contracts make it a binding obligation. It also genuinely reduces the chance and impact of security failures, which is the point of the whole exercise.

Everyone's behaviour is in scope

The certificate belongs to the organisation, but it is earned and kept through everyday behaviour. Auditors judge what actually happens, not what the policy binder says should happen. That makes your habits, your awareness, and your willingness to report problems part of what keeps the certification valid.

Check your understanding

A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.

Try the section quiz →
Course contents