Skip to main content
Category: NIST Standards & Publications

ISO/IEC 27001

Also known as: ISO 27001, ISO/IEC 27001:2022
Simply put

ISO/IEC 27001 is an internationally recognized standard that sets out the requirements for an information security management system (ISMS), which is a structured approach for protecting information and managing security risks. Organizations use it to establish, run, and continually improve their information security practices, and they can pursue certification to demonstrate conformity. It is a widely known information security standard, though readers should verify the current edition and its specific requirements against the official ISO text.

Formal definition

ISO/IEC 27001 is a jointly published standard specifying the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of an organization. The standard defines the ISMS requirements against which an organization can be independently assessed and certified; certification indicates conformity with the standard's management-system requirements as of the applicable edition. It should not be conflated with U.S. federal control frameworks such as NIST SP 800-53 or NIST SP 800-171, nor with authorization regimes such as FedRAMP or the DoD Risk Management Framework, and ISO/IEC 27001 certification does not by itself satisfy those distinct federal or defense compliance obligations. Practitioners should confirm the current revision, its scope, and any Annex control set against the authoritative ISO/IEC publication, as specific requirements and control references are established by that text rather than derived from this entry.

Why it matters

ISO/IEC 27001 is widely regarded as the world's best-known standard for information security management systems (ISMS), and certification against it has become a common way for organizations to demonstrate to customers, partners, and regulators that they follow a structured, independently assessable approach to managing information security risk. For organizations operating across international markets, an ISO/IEC 27001 certificate offers a recognizable, portable signal of conformity that does not depend on any single country's regulatory regime. This makes it particularly relevant to vendors and service providers whose clients span multiple jurisdictions and who need a common baseline to reference in contracts and due diligence.

For readers in the U.S. defense and public sector space, the most important point is one of scope. ISO/IEC 27001 is an international management-system standard and should not be conflated with U.S. federal control frameworks such as NIST SP 800-53 or NIST SP 800-171, nor with authorization regimes such as FedRAMP or the DoD Risk Management Framework. Holding an ISO/IEC 27001 certificate does not by itself satisfy those distinct federal or defense compliance obligations. An organization may be certified to ISO/IEC 27001 and still need to independently meet the requirements applicable to Controlled Unclassified Information, civilian agency systems under FISMA, or DoD systems under the RMF.

It is also worth stressing that certification indicates conformity with the standard's management-system requirements as of the applicable edition; it is not a permanent status and is generally subject to periodic surveillance and recertification activities defined by the certification scheme. As with any compliance credential, conformity with a standard is not the same as being secure, and practitioners should treat an ISO/IEC 27001 certificate as evidence of a managed process rather than as a guarantee of a particular security outcome.

Who it's relevant to

Compliance officers and ISMS managers
Those responsible for building or maintaining an information security management system use ISO/IEC 27001 as the reference standard for establishing, implementing, and continually improving their program. They should work from the current official ISO/IEC edition to confirm scope, requirements, and any associated control set, and should treat certification as a time-bound status subject to ongoing surveillance rather than a one-time achievement.
Government contractors and service providers
Vendors serving federal, defense, and international customers often hold or pursue ISO/IEC 27001 certification to demonstrate a managed approach to information security. These readers should be careful not to assume that certification satisfies distinct U.S. requirements such as NIST SP 800-171 for CUI, FedRAMP, or the DoD Risk Management Framework, which must be met independently and confirmed against their governing authorities.
Auditors and assessors
Professionals evaluating an organization's security posture may encounter ISO/IEC 27001 certificates as evidence of conformity with management-system requirements. They should verify the edition, the certified scope, and the currency of the certificate, and distinguish an assessment or certification against ISO/IEC 27001 from federal authorization decisions, which follow separate processes and criteria.
Authorizing officials and security leaders
Leaders making risk-acceptance and authorization decisions for federal or defense systems should understand where ISO/IEC 27001 fits relative to their governing frameworks. An ISO/IEC 27001 certificate can inform an understanding of a supplier's practices but does not by itself confer an Authority to Operate or replace the control baselines and continuous monitoring obligations applicable under FISMA or the RMF.

Inside ISO/IEC 27001

ISMS (Information Security Management System)
The central concept of ISO/IEC 27001 is the establishment, implementation, maintenance, and continual improvement of a documented management system for information security. The standard specifies requirements for this system rather than prescribing a fixed set of technical controls.
Management System Clauses
The main body of the standard sets out requirements addressing organizational context, leadership, planning, support, operation, performance evaluation, and improvement. These clauses form the auditable core against which certification is assessed.
Risk Assessment and Risk Treatment
The standard generally requires an organization to define and apply a risk assessment process, identify risks to the confidentiality, integrity, and availability of information, and select appropriate treatment options. The specific methodology is left to the organization to define.
Annex A Controls
ISO/IEC 27001 references a set of reference control objectives and controls in its Annex A, with implementation guidance provided in the companion standard ISO/IEC 27002. Organizations select applicable controls based on their risk treatment decisions; the applicable control set and its structure depend on the revision in force, which the reader should verify against the current published text.
Statement of Applicability (SoA)
A documented statement identifying which controls the organization has determined to be applicable, the justification for their inclusion, whether they are implemented, and the justification for any exclusions. The SoA links risk treatment decisions to selected controls.
Certification
Conformity to ISO/IEC 27001 can be independently assessed and certified by an accredited certification body. Certification attests to conformity with the management system requirements as of the assessment and is subject to surveillance and recertification cycles rather than being a permanent status.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27001.

Does holding ISO/IEC 27001 certification make an organization compliant with FISMA, FedRAMP, or CMMC?
No. ISO/IEC 27001 is a voluntary international standard for information security management systems maintained by ISO and IEC, and it is distinct from U.S. federal authorization regimes. FISMA compliance for civilian agencies, FedRAMP authorization for cloud services, and CMMC for the defense industrial base each rely on their own control sets, assessment processes, and authorizing authorities. While there can be conceptual overlap and some agencies or contracts may recognize ISO/IEC 27001 as supporting evidence, certification does not automatically satisfy these frameworks. Readers should confirm specific acceptance and mapping requirements against current official sources for the applicable framework.
Is ISO/IEC 27001 certification a one-time achievement that remains valid indefinitely?
No. Certification against ISO/IEC 27001 is generally time-bound and subject to ongoing surveillance activities and periodic recertification by an accredited certification body, rather than being permanent. The standard emphasizes continual improvement of the information security management system, which means the certified organization is expected to maintain and demonstrate the ongoing operation of its controls. This parallels a broader principle in security compliance that certification or authorization reflects a point-in-time and continuing state, not a permanent status. Organizations should verify current cycle and surveillance requirements with their certification body.
How does ISO/IEC 27001 relate to the risk-based approach used in NIST frameworks?
Both ISO/IEC 27001 and NIST frameworks generally emphasize a risk-based approach to information security, but they are separate bodies of guidance issued by different organizations. ISO/IEC 27001, maintained by ISO and IEC, centers on establishing, implementing, maintaining, and improving an information security management system, while NIST publications such as the Risk Management Framework serve U.S. federal contexts. Organizations sometimes map controls between the two, but such mappings are not exact or officially interchangeable in most implementations. Any crosswalk should be validated against current authoritative documentation rather than assumed to be complete.
What is the difference between certification and an internal implementation of ISO/IEC 27001?
An organization can implement the ISO/IEC 27001 standard internally and align its practices with its requirements without pursuing formal certification. Formal certification generally involves an independent audit by an accredited certification body, which is distinct from self-implementation or internal assessment. This distinction mirrors the broader compliance principle that assessment and authorization or certification are separate steps. Whether certification is required or merely encouraged depends on contractual, agency, or business drivers that readers should confirm for their specific situation.
How does ISO/IEC 27001 differ from the ISO/IEC 27002 guidance often referenced alongside it?
ISO/IEC 27001 and ISO/IEC 27002 are related but distinct documents within the same family maintained by ISO and IEC. In most editions, ISO/IEC 27001 sets out the requirements against which an information security management system may be certified, while ISO/IEC 27002 provides supporting guidance on information security controls. Because the specific structure, control organization, and content vary by revision, readers should confirm which edition applies to their circumstances and consult the current official texts rather than relying on prior versions.
Can ISO/IEC 27001 certification be scoped to only part of an organization?
Yes. Certification is generally tied to a defined scope, which the organization documents as part of its information security management system, and that scope may cover the entire organization or a specific set of systems, locations, or services. Because the scope statement determines what the certification actually covers, parties relying on a certificate should review the scope carefully rather than assuming enterprise-wide coverage. The precise scoping conventions and their acceptance for a given contract or agency requirement should be verified against the applicable current authoritative sources.

Common misconceptions

ISO/IEC 27001 certification means an organization is fully secure or that its systems cannot be breached.
Certification attests to conformity with the standard's management system requirements at a point in time; it does not guarantee security or the absence of incidents. Compliance and security are distinct, and an ISMS is intended to manage risk continually, not to eliminate it.
ISO/IEC 27001 certification satisfies U.S. federal or defense compliance obligations such as FISMA, FedRAMP, RMF, or CMMC requirements.
ISO/IEC 27001 is an international standard maintained by ISO and IEC and is separate from U.S. government authorization frameworks. It may inform or support parts of a compliance program, but it does not automatically satisfy obligations tied to NIST publications, FedRAMP authorization, the DoD RMF, or CMMC. Readers must confirm requirements against the applicable governing authority.
The standard prescribes a mandatory checklist of technical controls that every organization must implement.
ISO/IEC 27001 is risk-based and management-system oriented. Control selection flows from the organization's risk assessment and is documented in the Statement of Applicability, with justified inclusions and exclusions. The reference controls in Annex A are selected as applicable rather than adopted wholesale.

Best practices

Define and document a repeatable risk assessment and risk treatment methodology before selecting controls, so that control decisions are traceable to identified risks.
Maintain an accurate, current Statement of Applicability that justifies both included and excluded controls and reflects the actual state of implementation.
Treat certification as time-bound, planning for surveillance and recertification activities and sustaining the ISMS between assessments rather than only at audit time.
Verify the specific revision of ISO/IEC 27001 and ISO/IEC 27002 in force, since the control structure and requirements can change across revisions, and confirm details against the current official published text.
Do not assume ISO/IEC 27001 conformity satisfies federal, defense, or CUI-related obligations; map the ISMS to the applicable governing framework and confirm gaps with the relevant authority.
Establish performance evaluation, internal audit, and management review activities to support continual improvement, treating the ISMS as an ongoing process rather than a one-time project.