Standard
Advanced

ISO 27001 Quick-Start

A beginner-friendly walk of ISO 27001 — the international ISMS standard published by ISO, the mandatory clauses and Annex A controls that structure it, the Plan-Do-Check-Act cycle that runs the ISMS, the Statement of Applicability that ties it together, the day-in-the-life roles for a GRC analyst on a certification program, and two real analyst briefs (gap assessment and audit prep) that show the certification clock firing in practice.

Last updated:

Pair this primer with the full course: Full /courses/iso-27001 walk →

What ISO 27001 is

ISO 27001 is the international Information Security Management System (ISMS) standard published by the International Organization for Standardization (ISO) and revised jointly with the International Electrotechnical Commission (IEC). It is in force since 2005 and was last revised in 2022; the current citation is ISO/IEC 27001:2022. The standard itself is one document; the certification an enterprise customer asks for is a separate artifact — an attestation issued by an accredited third-party Certification Body (CB) following the standard. Those certifiers are independent entities accredited by national accreditation bodies (for example the UKAS in the UK, IAS in the United States), and they hold the public certificate against ISO/IEC 27001:2022, not against their own variant of it.

The standard has two structural pillars. The first is the mandatory management-system clauses (Sections 4 through 10): the ISMS scope, leadership, planning, support, operation, performance evaluation, and improvement — the management-system spine. Sections 4 through 10 are what the cert auditor opens first at a Stage 1 documentation review, before any Annex A control is walked. The second pillar is Annex A, a normative reference containing the control catalog the ISMS must address; the 2022 consolidation reduced the legacy 114 controls (across A.5 through A.18 in the 2013 version) to 93 controls grouped under four themes — Organizational (A.5), People (A.6), Physical (A.7), and Technological (A.8). The Annex A controls are what the SoA maps against row by row.

The auditor-issued certification runs on a fixed clock. Stage 1 is a documentation review where the cert auditor walks the Sections 4–10 clauses, the SoA, the risk-assessment methodology, and the policy set before any site walk happens. Stage 2 is the on-site (or virtual site) audit against Annex A — the auditor samples controls, traces evidence, interviews control owners, and writes the audit report that precedes initial certification. After initial certification, surveillance audits run typically annually to confirm the ISMS is still operating effectively and improving. Recertification happens on a three-year cycle, with a full re-audit on the renewed scope. A GRC analyst is supporting that clock day to day — the ISMS does not freeze between surveillance visits, and a missed internal audit or a stale SoA is the most common nonconformity the cert auditor writes up at surveillance.

The Annex A control domains

  • Organizational controls (A.5) — policies, roles, supplier relationships, and the information security governance the whole ISMS sits on.
  • People controls (A.6) — screening, awareness training, disciplinary process, and the post-offboarding duties that survive a contractor ending.
  • Physical controls (A.7) — perimeter security, equipment siting, clear-desk policy, and the disposal chain for storage media.
  • Technological controls (A.8) — the largest domain: identity and access, cryptography, system hardening, malware protection, backup, logging, and the SDLC.
  • Note: ISO 27001:2022 consolidated the legacy 114 controls across A.5 through A.18 into these four domains; if you are reading a 2013-vintage Annex A, the mapping is documented in Annex A itself.

The Plan-Do-Check-Act cycle

Plan — Establish the ISMS scope, the risk assessment methodology, and the risk treatment plan. The output is a Statement of Applicability (see next section) and a leadership-signed risk appetite. This is the part where the management system is actually defined, on paper, before any control is deployed.

Do — Implement the selected controls and the training and awareness program that keeps them in use. Day-to-day operations run here: access provisioning runs off the A.5/A.8 identity policy, the change ticket closes against the A.8 secure-development guidance, the backup schedule follows the A.8 backup control.

Check — Monitor, measure, and review the ISMS. Internal audits, control-effectiveness reviews, and the management review meeting all live in this phase. This is where the auditor will look first at certification audit: a missing internal-audit log is the most common major nonconformity.

Act — Address nonconformities and drive continual improvement. Corrective actions, treatment-of-risks updates, and the lessons-learned from incidents all get folded back into the Plan phase. ISO 27001 is explicit about this: an ISMS that does not improve over the audit cycle loses certification at surveillance.

The Statement of Applicability

The Statement of Applicability (SoA) is the single document that ties ISO 27001 together. It lists every Annex A control, marks each as applicable or not applicable, states the justification for any exclusion or inclusion, and names the control implementation status for the applicable ones.

An SoA that says "all 93 are applicable and implemented" with no justification is the second most common major nonconformity. The auditor expects each row to defend itself: why this control is in scope, where it is implemented (which document, which system), and how compliance with it is measured.

In practice the SoA is also the onboarding document for new analysts. Once you can locate the A.8.24 (data masking) row and trace it to the production pseudonymization pipeline, you can read every other control the same way. Treat it as the ISMS table of contents.

How it maps to a GRC analyst role

Risk owner — owns the risk-assessment methodology (Sections 6.1.2 and 6.1.3) and the Risk Treatment Plan. The work product opens the Plan phase of the PDCA cycle: an asset-and-risk inventory with threat, vulnerability, likelihood, and impact scoring; a defensible risk-acceptance call against a C-level sponsor; and the residual-risk memo the cert auditor reads before any control evidence is sampled. A risk owner who cannot defend the risk-acceptance criteria is the most common opening finding at Stage 1.

Control owner — owns a subset of the Annex A controls end to end. An A.5.x owner authors and maintains the policy text (the Statement of Applicability justification column reads as a one-paragraph version of the policy); an A.8.x owner maintains the technical implementation evidence (configuration baselines, access-review output, log retention, the SDLC control slug). The control owner updates the SoA row for each control when scope, evidence, or implementation shifts, and the role is the one that runs the corrective-action discipline in the Act phase — the input to the management review and the audit trail for next year's surveillance visit.

Internal auditor — runs the Check-phase internal audits on a documented cadence (typically annual, with coverage of all Annex A controls across the three-year certification cycle). The work product is the internal-audit report — a finding list with severity, root cause, owner, and a corrective-action due date — that feeds the management review meeting and is the document the cert auditor asks to see first at Stage 1. A missing or stale internal-audit log is the most common major nonconformity the cert auditor writes up; an internal-audit program that covers all 93 controls across the cycle, with documented findings and follow-ups, is what the management review minutes need to record.

SoA steward — keeps the Statement of Applicability defensible across changes. Each of the 93 rows holds four data points: applicable or not applicable, justification for that call, implementation status (implemented / partially implemented / planned / not applicable), and the evidence trail (which document, which system, which log, which ticket). The steward is also the onboarding vector for new analysts — a new joiner who can locate A.8.24 (data masking) on the SoA, follow it to the data-classification policy, and trace it to the production pseudonymization pipeline can read every other row the same way. Treat the SoA as the ISMS table of contents, and the steward as its editor.

Surveillance-audit coordinator — runs the annual surveillance-audit calendar for the three-year certification cycle. The work product is the package the cert auditor reads on arrival: the SAR-equivalent (internal audit summary, corrective-action log, management review minutes, incident log), the SoA delta since the last visit (new controls, removed justifications, scope changes), and the recurrence check on prior-year findings. The role drives the recertification prep roughly six months before the three-year cycle closes, when the cert auditor expects a full re-audit on the renewed scope rather than the sampling logic used at surveillance.

Two beginner briefs — gap assessment and audit prep

  • WovenCart (D2C apparel on Shopify Plus, PCI scope in marketing tooling, now being asked by a global enterprise customer for an ISO 27001 letter). Open as a gap assessment: walk all 93 Annex A controls, mark each applicable / not applicable with justification, score implementation status, and produce a SoA delta against the certification target. The Concrete artifact is the SoA itself plus a Plan-of-Action list sorted by audit-readiness impact.
  • Atlas Health Partners (regional integrated delivery network, post-merger HITRUST foundation that needs ISO 27001 cert for a cross-border data-processing contract). Open as audit prep: confirm the PDCA rhythm is real (signed internal-audit reports, dated management review minutes, a corrective-action log), rehearse the Stage 1 documentation review with the cert auditor, and walk the Stage 2 site audit on the A.8 technological controls first because that is where findings concentrate.

Next steps

Once you can name which PDCA phase a brief opens first — and which Annex A row the SoA delta is being scored against — you are no longer reading ISO 27001 as a 93-item checklist; you are using it as a management system with a certification clock. The next concrete move is to draft the actual control-language you would feed to a Policy Drafter. The Policy Drafter lab below turns a one-line intent into policy text that maps cleanly onto an Annex A row and justifies the SoA entry alongside it.

When you are ready to read the matching course, the full /courses/iso-27001 walk covers the Section 6 mandatory clauses and the Annex A control text clause by clause. Until then, the laminate for ISO 27001 is: name the Annex A row, name the PDCA phase, name the next concrete artifact.

Next
Next: try the Policy Drafter lab

Turn a one-line control intent into policy text mapped to an Annex A row — the editable draft, the SoA justification, and the evidence list an ISO 27001 cert auditor will ask for.

Open the Policy Drafter lab →
Browse the Labs index

Every hands-on lab the platform ships — DPIA, Gap Analysis, Risk Register, Policy Drafter, Compliance Checklist — on one page, with the framework selector and the free sub-form marked.

Browse the Labs index →
Browse Interview Prep

Question banks, scenario walk-throughs, and laminated answers for the GRC interview — for the analyst who is reading ISO 27001 ahead of a certification-program hire conversation.

Browse Interview Prep →