ISO/IEC 27001:2022 is an international standard that sets requirements for an information security management system (ISMS) — not a list of specific technical tools, but a process framework for systematically managing information risk. Certification confirms that an organisation has implemented and maintains a documented process, not that it owns a particular set of security technologies.
Quick Overview
What you’ll learn from this article:
- What an information security management system (ISMS) is under ISO 27001:2022
- How the standard’s Annex A is structured — 93 controls across four themes
- A step-by-step certification rollout plan, from risk analysis to the certification audit
- What resources (time and skills) to prepare before starting the project
Who this article is for: information security managers planning their first certification, IT leaders responsible for meeting customer or regulatory compliance requirements, consultants implementing an ISMS for clients.
Reading time: 7 minutes
ISO 27001: implementing an information security management system
At the standard’s core is the PDCA cycle (Plan-Do-Check-Act) applied to information security management: the organisation identifies risks to the confidentiality, integrity and availability of information, plans controls proportionate to those risks, implements them, monitors their effectiveness, and continually improves the process. This risk-based approach is what sets ISO 27001 apart from a technical checklist — two organisations with different risk profiles can implement a completely different set of controls and both remain compliant with the standard, as long as their decisions follow from documented risk analysis.
The 2022 version of the standard updated Annex A, reducing the number of controls from 114 (in the 2013 version) to 93, grouped into four themes instead of the previous fourteen domains: organisational controls, people controls, physical controls, and technological controls. This change reflects practice — many organisations already grouped controls functionally, and the new structure makes it easier to map controls to real business processes instead of abstract categories.
The four Annex A themes (ISO 27001:2022)
| Theme | Number of controls | Example scope |
|---|---|---|
| Organisational | 37 | Security policies, roles and responsibilities, supplier management |
| People | 8 | Pre-employment screening, awareness training, post-employment terms |
| Physical | 14 | Physical access control, equipment security, secure media disposal |
| Technological | 34 | Logical access control, cryptography, security monitoring, vulnerability management |
How to implement ISO 27001 step by step
- Define the ISMS scope — which processes, locations and information systems the certification covers; too broad a scope at the start extends the project without a proportionate benefit.
- Conduct a risk analysis for information within the defined scope, identifying threats, vulnerabilities and potential impact on confidentiality, integrity and availability.
- Select and implement Annex A controls proportionate to the identified risks, documenting the justification (Statement of Applicability) for each decision to implement or exclude a specific control.
- Run an internal audit before the certification audit, to catch gaps in documentation or implementation before the certification body does.
- Go through the two-stage certification audit — Stage 1 checks documentation completeness, Stage 2 (usually a few weeks later) verifies that the system actually works in practice.
Maintaining certification requires periodic surveillance audits (usually annually) and a full recertification every three years. Organisations that treat ISO 27001 as a one-off project rather than an ongoing risk-management process tend to lose the certificate at the first surveillance audit — documentation without an actually functioning review-and-improvement process doesn’t pass verification.
It’s worth distinguishing two things that often get conflated: implementing an information security management system aligned with ISO 27001, and formal certification by an accredited external body. An organisation can build and run an ISMS internally, without incurring certification cost, if the goal is purely to organise its security processes. Certification becomes necessary when customers or business partners require formal proof of compliance — in practice, increasingly a tender requirement in the public sector and in contracts with large enterprises. The choice of certification body matters: it’s worth checking whether the body is accredited by a national accreditation body, since a certificate from a non-accredited body may not be recognised by counterparts who require formal compliance.
Read Also
- How to Implement an Information Security Management System? Definition, Implementation, Key Elements and Best Practices
- The Importance of Information Security Management
Develop Your Skills
Planning to implement or certify ISO 27001 in your organisation? Check out our training led by experienced EITT instructors.
➡️ Introduction to ISO 27001 - the basics of the standard — EITT training ➡️ ISO 27001:2022 Data Protection Officer — EITT training
Frequently Asked Questions (FAQ)
How many controls does the ISO 27001:2022 Annex A contain?
93 controls grouped into four themes: organisational (37), people (8), physical (14) and technological (34). That’s down from 114 controls in the previous 2013 version of the standard, while keeping the same risk-based approach.
Does an organisation have to implement all 93 controls to get certified?
No — the standard requires documented justification for each decision, not implementation of every control. A control can be excluded if the risk analysis shows it doesn’t apply to the organisation, provided the exclusion is documented in the Statement of Applicability.
How long does a typical ISO 27001 implementation project take?
It depends on organisational maturity and certification scope, but a typical project from the start of risk analysis to the certification audit takes a few months to a year. Organisations with existing security management processes implement certification faster than those starting from scratch.
Does an ISO 27001 certificate expire?
Yes — the certificate is valid for three years, but requires annual surveillance audits confirming the system actually works, not just that it exists on paper. After three years, the organisation goes through full recertification.