ISO/IEC 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS). What it requires, what Annex A covers, where pentests fit in.
Updated This page as Markdown
In short
ISO/IEC 27001 is the international standard that sets the requirements for an information security management system (ISMS). It describes how an organisation runs security as a managed process: risk assessment, selected controls, measurement, internal audits and improvement. The current edition is ISO/IEC 27001:2022 with 93 reference controls in Annex A. Certification is optional and is issued by accredited certification bodies, not by ISO.
What is ISO/IEC 27001?
ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, usually shortened to ISMS. It is a management standard, not a technical one: it tells an organisation how to run security as a repeatable process with risk assessment, selected controls, measurement, internal audits and management reviews.
The current edition is ISO/IEC 27001:2022. Clauses 4 to 10 hold the mandatory requirements: context of the organisation, leadership, planning (including risk assessment and risk treatment), support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: organisational, people, physical and technological. Which controls apply is decided in the Statement of Applicability, which has to justify every inclusion and every exclusion.
Certification is optional. An accredited certification body audits the ISMS in two stages and issues a certificate valid for three years with annual surveillance audits. ISO itself certifies nobody, and neither does Zyberum; the certificate comes from a certification body.
Where is it defined?
ISO/IEC 27001:2022 is published jointly by ISO and IEC through their Joint Technical Committee 1, subcommittee 27. The companion standard ISO/IEC 27002:2022 explains each Annex A control and how to implement it. ISO/IEC 27005 covers information security risk management. Sector extensions exist, for example ISO/IEC 27019 for the energy industry and ISO/IEC 27701 for privacy.
The 2022 edition replaced the 2013 edition; certificates to the old edition could not be maintained after the end of the transition period on 31 October 2025. In Germany the BSI offers a second route to the same certificate: ISO 27001 certification on the basis of IT-Grundschutz, which uses the IT-Grundschutz methodology to meet the standard’s requirements.
What it means in practice
For a security team the standard matters in two places: the controls it expects and the evidence auditors ask for. The controls most relevant to testing are 8.8 (management of technical vulnerabilities), 8.29 (security testing in development and acceptance), 8.9 (configuration management), 8.16 (monitoring activities), 8.28 (secure coding) and 5.7 (threat intelligence, new in 2022). Clause 9.1 then asks how you know those controls are effective. The honest answer is usually a penetration test, a vulnerability management process with measurable patch times, and logs that someone actually reads.
Three patterns we see when organisations prepare for or hold a certificate:
- The scope ends at the office network. Production systems, OT, the product itself or the cloud environment are excluded from the ISMS scope, and the certificate says so in small print that customers rarely read.
- Controls exist on paper. The vulnerability management policy says 30 days for critical patches; the pentest finds a web server with a two-year-old version. Auditors sample, testers measure.
- Risk assessment without attackers. The risk register lists “malware” and “data loss” but not the concrete paths an attacker would take through the environment. A test report turns those into risks with owners and dates.
Zyberum runs gap analyses against ISO/IEC 27001, penetration tests as control evidence, and the technical parts of the implementation. We do not audit for certification.
Common misunderstandings
A certificate means the management system meets the standard, not that the systems in scope are free of vulnerabilities. ISO/IEC 27001 covers an organisation, not a product: product security is the domain of the Cyber Resilience Act, IEC 62443-4-1 and 4-2 for industrial components, and ISO/SAE 21434 for vehicles. The Annex A controls are not individually mandatory; what is mandatory is deciding about each one in the Statement of Applicability and being able to defend the decision.
FAQ
Frequently asked questions
Does ISO/IEC 27001 require a penetration test?
Not in those words. The standard requires that you assess risks, select controls and evaluate whether they are effective (clause 9.1). Annex A control 8.8 on technical vulnerabilities and control 8.29 on security testing in development and acceptance are where auditors look for evidence. A regular penetration test is the most common way to show that the controls work, which is why nearly every certified organisation has one.
How long does ISO/IEC 27001 certification take?
From a standing start, organisations typically need between six and eighteen months to build the ISMS, run a full risk cycle, hold an internal audit and a management review, and then pass the two-stage certification audit. A company that already runs structured security processes is at the lower end.
What is the difference between ISO/IEC 27001 and ISO/IEC 27002?
ISO/IEC 27001 contains the requirements you can be certified against. ISO/IEC 27002 is the guidance document that explains each of the Annex A controls in detail and how to implement them. You certify against 27001 and use 27002 to do the work.
Sources
Related pages
- GlossaryBSI IT-GrundschutzIT-Grundschutz is the BSI method for building an ISMS: BSI Standards 200-1 to 200-4 plus a Compendium of building blocks. How it works and when to use it.
- GlossaryTISAXTISAX is the automotive industry information security assessment, run by ENX on the VDA ISA catalogue. Assessment levels, labels, validity and practical demands.
- ComparisonsIEC 62443 vs ISO 27001: Plant Security or Information Security Management?ISO 27001 certifies an organisation's security management system. IEC 62443 secures industrial automation, from plant to PLC. Where they overlap and who needs which.
- For your industryCybersecurity for CISOs and IT Managers: NIS2 Duties, Pentests and DetectionWhat CISOs and IT managers in mid-sized companies need: NIS2 and BSIG duties, management liability, internal attack surface, typical findings and a first-year plan.
- GlossaryPenetration testA penetration test is an authorised, mostly manual attack on a system to find and prove exploitable vulnerabilities. Definition, types, process and the report.
- ServicesA resilient IT foundation for your business.IT security for businesses: infrastructure, web application and cloud penetration testing, managed SOC and incident readiness, including healthcare.
