Back to Frameworks
Security

ISO 27001

ISO/IEC 27001 is the leading international standard for building and certifying an Information Security Management System (ISMS) — a risk-based program for managing information security, not just a checklist of technical controls.

The current (2022) revision organizes its Annex A controls into four themes — organizational, people, physical, and technological — covering 93 controls in total. Certification is issued by an accredited certification body after a two-stage audit, and is maintained through annual surveillance audits across a three-year certification cycle.

See how LumiGRC handles ISO 27001

Get a Demo
93

Annex A controls

0%
Typical certification profile
Audit Rigor74%
Time to Certify69%
Surveillance Burden74%
Issued & Enforced By

ISO/IEC

ISO/IEC 27001:2022, Annex A

Key Points

  • Risk-based ISMS, not just a fixed control checklist
  • 93 Annex A controls across 4 themes (2022 revision)
  • Certified by an accredited body, 3-year cycle with annual surveillance
  • Widely recognized outside North America