ISAO — International Standards Accreditation Organization home pageVerify a certificate

Menu

Information and technology

ISO/IEC 27001:2022

Information security management systems

ISO/IEC 27001 sets out requirements for an information security management system.

Key facts

Edition
Current edition (2022)

A certified organisation assesses the risks to the confidentiality, integrity and availability of the information it holds or handles, chooses controls to treat those risks, and checks and improves them over time. It is published jointly by ISO and the International Electrotechnical Commission (IEC).

Who it suits

Software and cloud providers, IT and managed service companies, data centres, payroll and business process outsourcers, financial and professional services firms, and any organisation that holds customer or personal data and is asked to show how it protects it. It is a common request in supplier due diligence and tenders.

What certification involves

ISAO, or a certification body accredited for ISO/IEC 27001, audits the system in two stages. Stage 1 reviews the scope, the risk assessment, the risk treatment plan and the statement of applicability: the document that lists which controls the organisation applies and why any are excluded. Stage 2 tests whether the chosen controls and management processes work in practice, using interviews, records, observation and technical evidence. The certificate states the scope: the organisation, locations, services and systems covered. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.

Key themes

  • A clearly defined scope: the information, systems, locations and processes inside the system
  • A repeatable method for assessing information security risks
  • Controls chosen to treat those risks and recorded in a statement of applicability
  • A reference set of organisational, people, physical and technological controls
  • Leadership, roles, awareness and competence
  • Monitoring, internal audit, management review and correction of nonconformities

Edition

Current edition
ISO/IEC 27001:2022

ISO/IEC 27001:2022, the third edition, was published in October 2022. It replaced ISO/IEC 27001:2013, which has been withdrawn. The main change aligned its reference set of controls with ISO/IEC 27002:2022 and its text with ISO's common structure for management system standards. An amendment published in February 2024 asks the organisation to consider whether climate change matters to it when it reviews its context, and adds a note that interested parties may have expectations about climate change. A certificate that still names the 2013 edition refers to a withdrawn edition: ask the issuing body about it.

Check a certificate for ISO/IEC 27001:2022

  • Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
  • Compare the organisation name, scope and sites on the record with the copy you were given. Check that the services, systems and locations you rely on are inside the stated scope: a certificate for one department or data centre does not cover the whole organisation.
  • Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO/IEC 27001:2022 when the certificate was issued.
  • The statement of applicability is not published on the register. If you need to know which controls apply, ask the certified organisation.
  • If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.

This is ISAO’s own summary, not the text of the standard. Copies of ISO/IEC 27001:2022 can be bought from ISO or from national standards bodies.