Frameworks /  Global

ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented, risk-driven management process for securing information, against which an organisation can be independently certified by an accredited body.

What it requires

The certifiable requirements sit in Clauses 4-10: understanding the organisation and its interested parties, leadership and an information security policy, risk assessment and risk treatment, resources and competence, operational planning, monitoring and internal audit, management review, and continual improvement including corrective action. Risk treatment decisions are documented in a Statement of Applicability (SoA), which lists every Annex A control and states whether it is applied, and if not, why. Annex A of the 2022 edition contains 93 controls grouped into four themes: organizational (37), people (8), physical (14) and technological (34). Certification is granted after a two-stage audit, Stage 1 (documentation and readiness) and Stage 2 (implementation and effectiveness), and runs on a three-year cycle with annual surveillance audits and recertification in year three. The controls in Annex A are not a checklist to be adopted wholesale; they are selected on the basis of the organisation's own risk assessment.

ISO 27001 is voluntary. No law requires it. In practice it is demanded contractually: enterprise customers, EU and multinational procurement teams, and channel partners increasingly make it a gate for signing. For Israeli mid-market companies the trigger is almost always a specific stuck deal, a security questionnaire that has escalated, or an investor or acquirer performing diligence. It applies to any organisation of any size or sector, because the scope is defined by the organisation itself, which is exactly why scope definition is the most consequential decision in the whole project.

The controls people actually fail

  • The risk register is built once for the certification audit and then never updated: no new risks added after go-live, no re-scoring, no evidence that treatment plans were actually completed.
  • User access reviews are defined in policy as quarterly and are never performed, or are performed as an unrecorded conversation with no reviewer sign-off, no list of accounts reviewed, and no record of what was revoked.
  • Management review (Clause 9.3) has no evidence: no agenda, no minutes, no attendance, and none of the mandatory inputs (audit results, nonconformities, risk status, interested-party feedback, improvement opportunities) can be shown.
  • The Statement of Applicability drifts away from reality: controls are marked applicable and implemented, but the underlying process changed, the tool was replaced, or the owner left the company.
  • Supplier security (Annex A organizational controls) exists as a policy but not as a practice: no vendor inventory, no evidence that any supplier was ever assessed, and no security clauses in the contracts actually signed.
  • Internal audit is either skipped, or performed by the same person who built the ISMS, which is a nonconformity in itself, since the auditor must be objective and impartial with respect to the area audited.
  • Corrective actions from the last audit are recorded as "closed" with no evidence of root cause analysis or verification of effectiveness.
A certificate is a photograph of one week in a three-year cycle. The audit ends, the ISMS owner returns to their day job, and within two quarters the access reviews stop, the risk register goes stale, the asset inventory misses the new cloud accounts, and the SoA describes a company that no longer exists. Nothing breaks visibly, right up until the surveillance audit, or the customer whose contract requires you to be continuously compliant, not merely certified.

How long does ISO 27001 certification take?

For a mid-market company starting from scratch, typically 4 to 9 months to the Stage 2 audit. The work splits into scoping and gap analysis, building the ISMS (risk assessment, policies, Statement of Applicability), implementing missing controls, then running the ISMS long enough to generate evidence. Most certification bodies expect to see the ISMS operating, including at least one internal audit and one management review, before Stage 2. Companies with an existing security function and clean documentation can move faster; the constraint is usually evidence, not effort.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard certifying that you operate a management system for information security; a SOC 2 report is a US attestation, issued by a licensed CPA firm, describing whether your controls were suitably designed (Type I) and operating effectively over a period (Type II). ISO 27001 produces a certificate from an accredited certification body and is generally preferred in Europe and Israel; SOC 2 produces a long report your customer reads and is generally preferred in the US. They overlap heavily on the underlying controls (access management, change management, monitoring, vendor risk), so most companies doing both can run one control set and satisfy both.

How many controls does ISO 27001:2022 have?

Annex A of ISO/IEC 27001:2022 contains 93 controls, organised into four themes: organizational (37 controls), people (8), physical (14) and technological (34). The 2013 edition had 114 controls in 14 clauses; the 2022 revision consolidated and restructured them and added new controls covering areas such as threat intelligence, cloud services, and data leakage prevention. You are not required to implement all 93. You are required to consider each one, decide on the basis of your risk assessment whether it applies, and justify exclusions in the Statement of Applicability.

Do I need to be certified, or is being "ISO 27001 aligned" enough?

It depends entirely on what the customer wrote in the contract. "Aligned" or "compliant with" means nothing verifiable (there is no third party attesting to it) and sophisticated procurement teams increasingly reject it. If a deal is blocked, read the exact wording: if it says "certified by an accredited certification body", only a real certificate closes it. Note also that a certificate is only meaningful if the scope statement on it covers the products, systems and locations your customer cares about; a certificate scoped to a single office and one product line will not satisfy a customer buying something else.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.