Request Demo

ISO 27001 Framework

Automate and elevate your security protocols in line with the only internationally recognized information security framework.

ISO 27001 Framework Basics

ISO 27001 seeks to secure the confidentiality, integrity, and availability of an organization’s data. It requires a Statement of Applicability, which lists the security controls and measures an organization intends to implement.

Key Takeaways

  1. ISO 27001:2022 has 93 Annex A controls in four themes — organizational, people, physical, technological. The 114 controls across 14 domains figure belongs to the retired 2013 edition.
  2. Clauses 4 through 10 carry the certifiable requirements. Clauses 0 through 3 are introduction, scope, normative references, and terms, and are not audited.
  3. The Statement of Applicability is a separate required document that lists every Annex A control and justifies its inclusion or exclusion. It is not a section of the standard.
  4. ISO 27001:2013 certificates expired on October 31, 2025. Any certificate valid today is against the 2022 edition.
  5. CyberStrong maps assessed control posture to risks and to financial impact, so ISO 27001 evidence accumulates as a byproduct of running the program rather than as a separate audit-prep effort.

How Many Clauses and Controls Does ISO 27001 Have?

The standard splits into two halves that people constantly confuse.

The clauses define the management system: how you scope it, who owns it, how you assess risk, how you measure it, and how you improve it. Clauses 4 through 10 are what an auditor tests, and every requirement in them is mandatory. You can't pick and choose at the clause level.

Annex A is the control catalog you select from, driven by your risk assessment. You can exclude controls, but every exclusion needs a documented reason.

Annex A theme Clause Controls Representative controls
Organizational A.5 37 Policies, threat intelligence, supplier relationships, cloud service security
People A.6 8 Screening, terms of employment, awareness, disciplinary process
Physical A.7 14 Secure areas, physical security monitoring, equipment siting, clear desk
Technological A.8 34 Access rights, cryptography, configuration management, secure coding, data masking

What Changed Between ISO 27001:2013 and ISO 27001:2022?

The 2022 edition reorganized the control set rather than expanding it. Fifty-seven controls were consolidated into 24, one was split into two, 11 were added, and the remaining 58 were revised or carried forward.

  ISO 27001:2013 ISO 27001:2022
Annex A controls 114 93
Grouping 14 domains 4 themes
New controls 11
Control attributes None 5 attribute types (defined in ISO 27002:2022)
Certificate status Expired October 31, 2025 Current

The 11 new controls track where enterprise risk actually moved: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).

Amendment 1:2024 added a requirement to clause 4.1 to determine whether climate change is a relevant issue, and a note to clause 4.2 acknowledging that interested parties may have climate-related requirements. It is a small change with real audit consequences: it must be addressed in your context analysis.

What Is the Statement of Applicability?

The Statement of Applicability (SoA) is a mandatory document, required by clause 6.1.3(d). It lists all 93 Annex A controls and records, for each one, whether it applies, why, and its implementation status. Controls excluded from scope need a stated justification. Auditors read the SoA before anything else because it defines what they are actually assessing, making it the single document most worth getting right.

How Long Does ISO 27001 Certification Take?

Certification is a two-stage audit followed by ongoing surveillance.

Stage 1 reviews documentation and ISMS design, scope, policies, risk assessment method, and SoA,  and surfaces gaps before they become findings. Stage 2 tests whether the ISMS operates as documented, through evidence and interviews. Surveillance audits follow in years one and two, with recertification in year three.

Timeline depends on starting maturity. An organization with documented controls and existing evidence can reach Stage 2 in three to six months; building an ISMS from nothing typically takes nine to twelve. The binding constraint is that Stage 2 auditors expect several months of operating records, including a completed internal audit and management review. Cost follows scope, headcount, and number of sites — but certification body fees are usually the smaller line. Internal effort spent collecting evidence and reconciling it against controls is the larger one, and it recurs every cycle.

Comparing ISO 27001 to SOC 2, NIST CSF, and ISO 27002

  ISO 27001 ISO 27002 SOC 2 NIST CSF 2.0
What it is Certifiable ISMS standard Implementation guidance for Annex A controls Attestation on control effectiveness Voluntary risk management framework
Output Certificate from an accredited body None — guidance only Auditor's report (Type I or Type II) Self-assessed profile
Scope Whole management system Control detail Selected Trust Services Criteria Six functions, including Govern
Prescribes controls Yes, via Annex A Explains them Criteria, not controls No
Recognized Globally Globally Primarily US Globally, US-anchored

The practical distinction: ISO 27002 tells you how to implement a control; ISO 27001 certifies that you run a system to choose and manage them. SOC 2 attests to control operation over a period, for a customer audience. NIST CSF organizes risk without certifying anything.

Running ISO 27001 Alongside Everything Else

Few enterprise programs maintain ISO 27001 in isolation. It sits alongside SOC 2, NIST CSF, PCI DSS, and customer-specific requirements, and the same control evidence answers to several of them. Kept in separate spreadsheets and portals, one control gets assessed four times and produces four different answers.

CyberSaint built CyberStrong to assess a control once and map it across every framework in scope, connecting posture to risk and risk to financial impact. Evidence stays current because it comes from the tools already generating it, so a surveillance audit confirms what the program already tracks.

Want to see your ISO 27001 posture mapped against the rest of your framework set? Request a demo.

FAQs About ISO 27001 Framework Basics

How many controls are in ISO 27001?

ISO 27001:2022 has 93 controls in Annex A, split into 37 organizational, 8 people, 14 physical, and 34 technological. The earlier 2013 edition had 114 controls across 14 domains. If a source still cites 114, it is describing a version whose certificates expired in October 2025.

How many clauses does ISO 27001 have?

Eleven numbered clauses, 0 through 10, but only clauses 4 through 10 contain auditable requirements: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. Clauses 0 through 3 cover the introduction, scope, normative references, and terms and definitions.

What are the four themes of ISO 27001 Annex A?

Organizational (A.5, 37 controls), people (A.6, 8), physical (A.7, 14), and technological (A.8, 34). The 2022 edition replaced the 14 domains of the 2013 edition with these four themes. ISO 27002:2022 also assigns each control five attribute types, which makes cross-framework mapping practical.

Is ISO 27001:2013 still valid?

No. The transition period closed on October 31, 2025, and all ISO 27001:2013 certificates expired then. Any valid certificate today is against ISO 27001:2022, including Amendment 1:2024.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard defining the management system and the Annex A control set. ISO 27002 is a guidance document that explains how to implement each control, with purpose statements and implementation guidance. You certify against 27001; you consult 27002 while building. No organization is certified to ISO 27002.

What is a Statement of Applicability in ISO 27001?

A required document listing every Annex A control with a decision on whether it applies, the justification for that decision, and its implementation status. Clause 6.1.3(d) mandates it, and auditors use it to define audit scope. Exclusions are permitted, but each needs a documented reason tied to the risk assessment.

Is ISO 27001 mandatory?

Not by law in most jurisdictions. It becomes effectively mandatory through contracts — enterprise procurement, EU customers, and regulated supply chains commonly require it.

How long does ISO 27001 certification take?

Three to six months for an organization with documented controls and existing evidence; nine to twelve when building an ISMS from scratch. The constraint isn't audit scheduling—it is that Stage 2 auditors expect several months of ISMS operating records, including at least one completed internal audit and management review.

Learn More: 

Learn more about CyberStrong

Download the Solution Sheet

Download the CyberStrong Solution Sheet