ISO/IEC 27001: Information Security Management

The certifiable standard for running security as a managed system, and what a certificate does and does not tell you about a vendor.

StandardISO/IEC 27001
Applies toOrganizations of any size running an information security management system; buyers who rely on certification as vendor evidence.
When it appliesVoluntary, but contractually demanded across supply chains; certification audits run on a three-year cycle with annual surveillance.

ISO/IEC 27001 is the standard you certify against when someone needs proof your security program is real. It is not a list of technical controls; it is a management system standard, and understanding that distinction is most of understanding what a certificate means.

What it actually requires

27001 requires an information security management system, an ISMS: leadership commitment, a defined scope, a risk assessment process, risk treatment decisions, measurable objectives, internal audit, management review, and continual improvement. The technical and organizational controls live in its Annex A (currently 93 of them, elaborated in ISO/IEC 27002), but the standard’s demand is not “implement all the controls.” It is “run a system that identifies your risks and applies the controls your risks justify,” with a Statement of Applicability documenting which controls apply and why. Certification means an accredited auditor examined that system and found it operating.

How to read a vendor’s certificate

Buyers, including security integrators evaluating VMS and cloud vendors, should read three things before being impressed. The scope statement: certificates cover a defined scope, and “our marketing office in one country” is a very different claim from “the engineering and operations behind the product you are buying.” The certificate body: accredited certification bodies mean something; certificates from nobody-accredited mills do not. And the date: certificates run a three-year cycle with annual surveillance audits, so a lapsed certificate is a data point too. Ask for the certificate and the scope, not the logo on the website.

Is it worth pursuing?

For Canadian security companies, MSSPs, and consultancies, the honest calculus is commercial. Enterprise and public-sector procurement increasingly gates on 27001 or SOC 2, and certification is the cleanest answer to a hundred-question security questionnaire. The cost is real: building the ISMS, the certification audit, and the annual maintenance. The trap to avoid is the paper ISMS, built by a consultant in a month, operated by no one, and visible as such to any competent auditor or customer. If the practices are not lived, the certificate buys one sales cycle and a renewal crisis.

What trips people up

Treating 27001 as an IT project instead of a management commitment: the standard explicitly requires leadership involvement, and audits probe it. Scoping too broadly on the first attempt, which multiplies cost, or so narrowly the certificate is meaningless to customers. And confusing alignment with certification: “aligned to ISO 27001” on a website is a self-claim. Only certification involves independent audit.

How it fits

27001 answers “is security managed?” Control catalogues like the CIS Controls answer “what should we technically do?”, and the NIST CSF offers a lighter framework for organizing the same work without certification. Many organizations use CSF or CIS to build the program and 27001 to prove it.

Related guides

This is a plain-language guide, not the standard. It paraphrases and interprets; it does not reproduce the text. Requirements change between editions and provinces modify the codes that reference them. For design, installation, or compliance decisions, work from the current official text and your authority having jurisdiction.

References

  1. ISO/IEC 27001, Information security management systemsInternational Organization for Standardization · retrieved 2026-07-24
  2. ISO/IEC 27002, Information security controlsInternational Organization for Standardization · retrieved 2026-07-24

Last updated 2026-07-24.