ISO 27001 STANDARD
ISO 27001 – explained
The international standard for information security management.






WHAT IT MEANS TO GET CERTIFIED
ISO 27001 is not a legal requirement like NIS2, but it serves to demonstrate, through an independent external audit, that the organization manages information security according to an internationally recognized system.
Certification for contracts or tenders
Enterprise clients or public tenders that require it as a condition of supply
Certification to strengthen trust
Companies and universities that want to demonstrate structured information security management to clients, partners, and funders
Control domains
93 controls organized into 4 categories, updated to the ISO/IEC 27001:2022 revision
37 organizational
Security policies, roles and responsibilities, information asset management, information classification, supplier relationships, and process-level incident management
8 people
Pre-employment screening, employment terms and conditions, awareness and continuous training, disciplinary procedures, and termination of employment management
14 physical
Security perimeters, physical access control, protection against environmental threats, office and server room security, secure equipment disposal
34 technological
Access management and authentication, cryptography, network security, logging and monitoring, backup, vulnerability management, and secure software development
The phases of the certification process
Gap analysis and risk assessment
Asset mapping, risk assessment, comparison with Annex A controls
Implementation of controls
Policies, procedures, and technical measures for the controls selected in the Statement of Applicability
Internal audit
Independent internal verification of the management system prior to the external audit
Certification audit
Documentary review, followed by verification of the effectiveness of controls in the field, conducted by an accredited third-party body
Surveillance and renewal
Annual surveillance audits and re-certification every 3 years.
3 years
of certificate validity, with annual surveillance audits to keep it active.
93 controls
selectable based on the organization's actual risk profile, not all mandatory.
Contact us
