What ISO 27001 is
ISO 27001 is the international Information Security Management System (ISMS) standard published by the International Organization for Standardization (ISO) and revised jointly with the International Electrotechnical Commission (IEC). It is in force since 2005 and was last revised in 2022; the current citation is ISO/IEC 27001:2022. The standard itself is one document; the certification an enterprise customer asks for is a separate artifact — an attestation issued by an accredited third-party Certification Body (CB) following the standard. Those certifiers are independent entities accredited by national accreditation bodies (for example the UKAS in the UK, IAS in the United States), and they hold the public certificate against ISO/IEC 27001:2022, not against their own variant of it.
The standard has two structural pillars. The first is the mandatory management-system clauses (Sections 4 through 10): the ISMS scope, leadership, planning, support, operation, performance evaluation, and improvement — the management-system spine. Sections 4 through 10 are what the cert auditor opens first at a Stage 1 documentation review, before any Annex A control is walked. The second pillar is Annex A, a normative reference containing the control catalog the ISMS must address; the 2022 consolidation reduced the legacy 114 controls (across A.5 through A.18 in the 2013 version) to 93 controls grouped under four themes — Organizational (A.5), People (A.6), Physical (A.7), and Technological (A.8). The Annex A controls are what the SoA maps against row by row.
The auditor-issued certification runs on a fixed clock. Stage 1 is a documentation review where the cert auditor walks the Sections 4–10 clauses, the SoA, the risk-assessment methodology, and the policy set before any site walk happens. Stage 2 is the on-site (or virtual site) audit against Annex A — the auditor samples controls, traces evidence, interviews control owners, and writes the audit report that precedes initial certification. After initial certification, surveillance audits run typically annually to confirm the ISMS is still operating effectively and improving. Recertification happens on a three-year cycle, with a full re-audit on the renewed scope. A GRC analyst is supporting that clock day to day — the ISMS does not freeze between surveillance visits, and a missed internal audit or a stale SoA is the most common nonconformity the cert auditor writes up at surveillance.