
ISO 27001 Explained.
The Standard, The Process, And What Auditors Actually Check
ISO 27001 is the international standard for an Information Security Management System (ISMS). This guide walks through how the standard is structured, what happens at each stage of certification, and the evidence an auditor will expect to see.
the certification journey
Stage 1 To Recertification.
Certification runs on a three-year cycle. It begins with two audits, continues with annual surveillance, and ends with a full recertification in year three.
Stage 1 — Readiness Review
Is the ISMS documented?
The auditor reviews your scope, policy, risk assessment, Statement of Applicability and internal audit records. It is a documentation check — they are confirming you are ready for Stage 2, and will raise findings to close first.
Stage 2 — Certification Audit
Is it actually working?
Typically 2–8 weeks after Stage 1. The auditor samples evidence across the business to confirm controls operate in practice — interviews, records, tickets, logs. Clear the nonconformities and the certificate is issued.
Surveillance — Years 1 & 2
Has it stayed alive?
Shorter annual audits covering a subset of the ISMS. Internal audit, management review, corrective actions and any change to scope or risk are always in scope.
Recertification — Year 3
Does it still hold up?
A full audit of the entire ISMS, similar in depth to Stage 2, before a new three-year certificate is issued.
clauses 4 to 10
The Processes Auditors Audit.
Clauses 4–10 are the mandatory management system requirements. These are internal business processes, not IT controls — and they are where most nonconformities are raised.
Clauses 4 & 5 — Context & Leadership
Scope and accountability.
Defining the ISMS scope and interested parties, an approved information security policy, and documented top-management commitment with assigned roles and responsibilities.
Clause 6 — Planning & Risk
Your risk method, applied.
A documented risk assessment methodology, the risk assessment and treatment plan, the Statement of Applicability justifying every Annex A control included or excluded, and measurable security objectives.
Clauses 7 & 8 — Support & Operation
Making it run.
Competence and training records, awareness activity, control of documented information, plus evidence that planned security processes and risk treatments are actually operating.
Clauses 9 & 10 — Evaluation & Improvement
Proving it works.
Monitoring and measurement, a completed internal audit programme, management review minutes, and records of nonconformities with corrective action taken.
annex a controls
93 Controls, Four Themes.
The 2022 revision reorganised Annex A from 14 domains into four themes totalling 93 controls. You do not implement all of them — your Statement of Applicability justifies which apply to you.
A.5 Organizational — 37 Controls
Policies, people and suppliers.
Information security policies, roles and responsibilities, supplier and cloud service security, incident management, business continuity, and legal and regulatory compliance.
A.6 People — 8 Controls
The human layer.
Screening, terms and conditions of employment, awareness and training, disciplinary process, responsibilities after termination, and remote working.
A.7 Physical — 14 Controls
Doors, desks and disposal.
Secure areas and physical entry, equipment siting and protection, clear desk and clear screen, secure disposal or reuse of equipment, and cabling security.
A.8 Technological — 34 Controls
The technical estate.
Access control and authentication, cryptography, secure development, logging and monitoring, malware protection, backup, network security and data masking.
audit evidence
Evidence, Not Intentions.
Auditors sample. They pick a control, ask to see it working, and follow the trail. These four areas account for most findings.
A Complete Internal Audit
The most common gap.
Your internal audit programme must cover the whole ISMS across the cycle, be run by someone independent of the area being audited, and have findings closed out with evidence.
A Real Management Review
Not a diary entry.
Minutes showing leadership reviewed performance, risks, audit results, objectives and improvement — with decisions recorded and actions assigned.
A Living Risk Register
Dated and revisited.
Risks reassessed when things change, treatment plans with owners and dates, and residual risk formally accepted by management.
Records That Match The SoA
Say it, then show it.
Every control marked applicable in your Statement of Applicability needs evidence behind it — a policy, a log, a ticket, a signed record.
Need Help Getting ISO 27001 Certified?
We build and run ISO 27001 management systems for businesses across the UK, Ireland and the Isle of Man — and we stand with you at Stage 1 and Stage 2.













