ISO 27001
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Its subject is not a firewall configuration but the management system: how an organisation decides what to protect, chooses controls, and keeps checking that they work.
The current edition is ISO/IEC 27001:2022.
What an ISMS is
An ISMS is the set of policies, processes, roles and records through which an organisation manages information risk. Three commitments define it:
- Risk-driven. Controls follow from assessed risks, not from a wish list.
- Documented. Decisions, including decisions not to act, are recorded.
- Improving. Plan–Do–Check–Act: it is audited, measured and corrected.
The objective is protecting the confidentiality, integrity and availability of information.
Structure of the standard
Clauses 4–10 are the requirements an organisation must meet:
| Clause | Requirement |
|---|---|
| 4 | Context of the organisation — scope, interested parties |
| 5 | Leadership — policy, roles, responsibilities |
| 6 | Planning — risk assessment and treatment, objectives |
| 7 | Support — resources, competence, awareness, documentation |
| 8 | Operation — running the risk treatment plan |
| 9 | Performance evaluation — monitoring, internal audit, management review |
| 10 | Improvement — nonconformity and corrective action |
Annex A lists 93 controls in the 2022 edition, reorganized into four themes:
- Organizational (37)
- People (8)
- Physical (14)
- Technological (34)
The 2022 edition added controls covering threat intelligence, cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, activity monitoring, web filtering and secure coding.
Annex A is a reference set. The Statement of Applicability records which controls apply, which do not, and why.
Implementation path
- Scope — which systems, sites, services and data are covered.
- Risk assessment — identify assets, threats and vulnerabilities; score consistently against defined criteria.
- Risk treatment — mitigate, transfer, avoid or accept, with an owner for each decision.
- Statement of Applicability — justify inclusion and exclusion.
- Operate — implement controls, train people, keep evidence.
- Internal audit and management review.
- Certification audit (Stage 1 documentation, Stage 2 implementation), if certification is required.
In healthcare
Health data raises the stakes of every control decision. Two companions to ISO 27001 matter here:
- ISO 27799 — health-specific guidance on applying ISO 27002 controls to personal health information.
- GDPR and national data protection law — legal obligations that an ISMS supports but does not replace.
See also data governance, which answers who may decide about data, where the ISMS answers how it is protected.
Honest caveats
- Certification is a scope statement, not a security guarantee. Always read what the certificate covers.
- An ISMS that lives only in documents fails its first real incident. Evidence of operation is the point.
- Alignment is not certification. Organisations may implement an ISMS aligned with the standard without holding a certificate; the two claims should be stated distinctly.
References
- ISO/IEC 27001:2022 — https://www.iso.org/standard/27001
- ISO/IEC 27002:2022 — control implementation guidance
- ISO 27799 — health informatics security management