Default
Article

ISO 27001 Explained: Requirements, Controls and Certification


Warning: Trying to access array offset on value of type bool in /var/www/new_portal/html/wp-content/themes/cyberx/single.php on line 61

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /var/www/new_portal/html/wp-includes/formatting.php on line 4558

Warning: Trying to access array offset on value of type bool in /var/www/new_portal/html/wp-content/themes/cyberx/single.php on line 61
Writer:
Huzaifa.Hamza

You cannot buy ISO 27001. There is no appliance, no licence, and no vendor that can hand it to you.

What gets certified is a management system — a documented, running set of processes for identifying information security risks and doing something measurable about them.

That distinction explains most failed certification attempts. Organisations buy tooling, write policies the week before the audit, and discover that the auditor is asking for twelve months of evidence that the system actually operated.

This guide walks through the mandatory clauses, the Annex A controls, the certification process, and the failures that show up most often.

What Is ISO 27001?

ISO 27001 is the international standard for an Information Security Management System (ISMS). It specifies how an organisation establishes, implements, maintains, and continually improves information security as a managed process.

The current version is ISO/IEC 27001:2022, which revised the control set from the 2013 edition. Background on the standard’s history and structure is available in the Wikipedia entry for ISO/IEC 27001.

The ISMS Is the Thing That Gets Certified

An ISMS is the framework of policies, procedures, roles, and records through which an organisation manages information risk. NIST’s glossary defines the term in similar operational language — see the NIST CSRC entry for ISMS.

The practical implication: the auditor is checking whether decisions were made, recorded, reviewed, and acted upon — not whether you own a particular product.

ISO 27001 vs ISO 27002 vs the NIST CSF

ISO 27001 contains the certifiable requirements. It is what you get audited against.

ISO 27002 is guidance: implementation detail for the controls, not certifiable in itself.

NIST Cybersecurity Framework is a voluntary framework for organising security outcomes; useful alongside ISO 27001 but not a substitute, and there is no certification against it.

The Mandatory ISO 27001 Clauses (4–10)

Clauses 4 through 10 are the non-negotiable part of ISO 27001. You cannot risk-assess your way out of them.

Clause 4 — Context of the Organisation

Identify internal and external issues relevant to information security.

Determine interested parties and their requirements — customers, regulators, partners.

Define the ISMS scope precisely, including what is excluded and why.

Clause 5 — Leadership

Top management must demonstrate commitment, not delegate it entirely.

An information security policy must exist, be approved, and be communicated.

Roles, responsibilities, and authorities must be assigned and understood.

Clause 6 — Planning

This is the heart of ISO 27001 and where auditors spend disproportionate time:

A defined, repeatable risk assessment methodology.

Identified risks with owners.

A risk treatment plan stating how each risk is handled.

A Statement of Applicability listing which Annex A controls apply and justifying exclusions.

Measurable information security objectives.

Clause 7 — Support

Adequate resources allocated to the ISMS.

Competence: people in security-relevant roles are demonstrably capable.

Awareness: staff understand the policy and their contribution to it.

Documented information under version and access control.

Clause 8 — Operation

Planning has to actually run. Risk assessments performed on schedule, treatment plans executed, changes controlled, and outsourced processes governed.

Clause 9 — Performance Evaluation

Monitoring and measurement against the objectives set in Clause 6.

Internal audit programme covering the whole ISMS over a defined cycle.

Management review at planned intervals, with recorded decisions.

Clause 10 — Improvement

Nonconformities recorded, root-caused, and corrected.

Evidence of continual improvement, not just corrective firefighting.

ISO 27001 Annex A Controls in the 2022 Revision

Annex A is the catalogue of controls you select from to treat the risks you identified. It is the part of ISO 27001 people quote most often and understand least.

Four Themes, 93 Controls

The 2022 revision reorganised the previous 114 controls across 14 domains into 93 controls grouped under four themes:

Organisational — policies, supplier relationships, threat intelligence, incident management.

People — screening, terms of employment, awareness, disciplinary process, remote working.

Physical — secure areas, equipment, clear desk and screen, physical monitoring.

Technological — access control, cryptography, logging, secure development, data masking.

You Do Not Implement All 93

This is the most common misunderstanding. Unlike Clauses 4–10, Annex A controls are selected based on your risk assessment.

A company with no software development function does not implement secure development controls. It documents why.

The Statement of Applicability

The SoA is the bridge between your risks and your controls. For each Annex A control it records:

Whether the control is applicable.

The justification for including or excluding it.

Whether it is currently implemented.

Where the implementing evidence lives.

Auditors read the SoA first. A vague SoA signals a risk assessment that was written to fit a predetermined answer, and it is the fastest way to lose auditor confidence in the rest of your ISO 27001 documentation.

The ISO 27001 Certification Process Step by Step

Gap analysis. Compare current practice against the requirements. Expect the gaps to be documentation and evidence, not technology.

Define scope. Which entities, locations, systems, and data. Narrow and defensible beats broad and aspirational.

Build the risk methodology. How you identify, analyse, evaluate, and treat risk — written down before you use it.

Run the risk assessment. With named risk owners and recorded decisions.

Produce the risk treatment plan and SoA.

Implement controls and run the ISMS. This is where the calendar matters; you need operating evidence.

Internal audit. Conducted by someone independent of the area audited.

Management review. Documented, with decisions and actions.

Certification audit. Stage 1 reviews documentation and readiness; Stage 2 tests whether the ISMS operates as described.

Most organisations need several months of operating history before Stage 2 is realistic, because the auditor is sampling records over time.

What Happens After Certification

The certificate is not the finish line:

Surveillance audits typically occur annually to confirm the ISMS is still operating.

Recertification runs on a three-year cycle.

Continual improvement evidence is expected at each visit — new risks assessed, incidents learned from, objectives updated.

Scope changes — new products, offices, or cloud platforms — need to be brought into the ISMS deliberately.

Organisations that treat ISO 27001 as an annual event rather than an operating rhythm tend to rebuild their evidence pack from scratch every year, at several times the cost.

Common Reasons Organisations Fail the Audit

Scope defined too broadly early on, creating evidence obligations nobody can meet.

Risk assessment written retrospectively to justify controls already purchased.

Policies with no evidence of use — approved, published, never referenced, never acknowledged.

No records of awareness training, or completion records with no assessment of understanding.

Incident response plan never tested, so Clause 8 operation cannot be demonstrated.

Internal audit performed by the person who built the ISMS, breaking independence.

Supplier controls ignored despite critical processes being outsourced.

The pattern is consistent: ISO 27001 failures are almost never about missing technology. They are about missing evidence that decisions were made and reviewed.

ISO 27001 in the GCC Context

For organisations operating in Saudi Arabia and the wider Gulf, ISO 27001 rarely stands alone. It typically sits alongside national regulatory requirements and sector-specific controls.

The advantage of leading with ISO 27001 is structural: it gives you a management system that other obligations can be mapped into, rather than a checklist that expires.

The ISMS gives you a single risk register and control framework to map multiple obligations onto.

Much of the evidence — asset inventory, access reviews, awareness records, incident logs — satisfies more than one regime.

Treating each framework as a separate project is the expensive path; mapping them once is not.

Organisations adopting new technologies while pursuing certification face an additional layer; our article on navigating AI securely in digital Saudi Arabia covers that intersection. For a foundational overview of the discipline itself, see what cybersecurity means.

Conclusion

ISO 27001 certifies a working management system, not a set of purchases. The clauses are mandatory; the Annex A controls are selected against your own risks.

Get the scope, the risk methodology, and the Statement of Applicability right and the rest of the programme has a spine. Get them wrong and no amount of tooling will carry you through Stage 2.

Above all, build for evidence. Every requirement in the standard eventually resolves to the same audit question: show me. You can see how we support that operationally across the CyberX platform range, and our cyber security tips guide covers the day-to-day habits behind several Annex A people controls.

Turn Policies Into Auditable Evidence — PLCY-X

The hardest part of ISO 27001 is rarely writing the policy. It is proving that every relevant employee received it, read it, acknowledged it, and got the current version rather than last year’s.

PLCY-X manages policy distribution, version control, and attestation, and produces the acknowledgement records and audit trail that Clause 7 and the Annex A people controls require — on demand, not reconstructed the week before the audit.

Contact us for a demo and see what your evidence pack could look like.

Frequently Asked Questions

How long does ISO 27001 certification take?

It depends on scope and starting maturity. The binding constraint is usually operating evidence: auditors sample records over a period, so an ISMS that started last month cannot demonstrate a full cycle of internal audit and management review.

Is ISO 27001 mandatory?

No. It is voluntary, but it is frequently required contractually — particularly by enterprise customers, in public procurement, and in regulated supply chains.

Do we have to implement all 93 Annex A controls?

No. You select controls based on your risk assessment and record the reasoning in the Statement of Applicability. Excluding a control is acceptable when the justification is defensible.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 certifies a management system against an international standard. SOC 2 is an attestation report by an auditor against trust services criteria, more common in North America. Many organisations pursuing both find substantial evidence overlap.

Can a small company get certified?

Yes. The standard scales with scope and risk rather than headcount. A small organisation with a tightly defined scope often certifies faster than a large one attempting to cover everything at once.

Newsletter

Subscribe to our newsletter and never miss latest insights and security news.

Similar Articles

Languages: