ISO/IEC 27001Free Resource

ISO/IEC 27001 Run the ISMS from scope to certification evidence

ISO/IEC 27001:2022 is a voluntary, certifiable management-system standard for managing information security risks through an . Its requirements apply to organizations of any type, size, or nature. An organization can set a bounded ISMS scope, but it cannot exclude any requirement in Clauses 4-10 and still claim conformity.

By Sorena AIUpdated 2026No signup required
Quick scan
ISO/IEC 27001
Scope and leadership
Document the boundary, relevant interested-party requirements, policy, roles, objectives, resources, communications, and the effect of the 2024 climate-action amendment.
Risk, SoA, and controls
Determine necessary controls from risk treatment, compare them with Annex A, justify Annex A exclusions, record implementation status, and obtain risk-owner approval and residual-risk acceptance.
Certification readiness
Keep monitoring results, audit programs and results, management-review decisions, nonconformities, corrective actions, and treatment results tied to the current scope.

A usable keeps scope, risk decisions, controls, evidence, approvals, and review triggers connected. The required record depends on the applicable clause, the organization's own process, and the controls it selected.

Key dates
Guides
Deep pages
FAQ
Standalone answers
Compare
Side-by-side
Evidence
Reusable
What this hub helps you do
Scope and leadership
Determine internal and external issues, relevant interested parties and requirements, climate-change relevance, interfaces, and dependencies. Then document the boundary and assign accountable roles.
Risk, SoA, and controls
Connect risk criteria and assessment results to treatment options, necessary controls, the , the treatment plan, and risk-owner approval. Annex A is a 93-control reference set grouped into 37 organizational, 8 people, 14 physical, and 34 technological controls, not a requirement to implement every control.
Certification readiness
First make the operate: implement the treatment plan, monitor performance, conduct internal audits, complete management reviews, and correct nonconformities. A certification body then audits the defined scope and samples this evidence.
Scope
Evidence
Review
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Use the October 2022 third edition together with ISO/IEC 27001:2022/Amd 1:2024, published in February 2024. The amendment adds climate-change consideration to organizational context and interested-party requirements. The IAF transition from the 2013 edition ended on 31 October 2025, so current accredited certification work should use the 2022 edition. Certification is optional: a certificate attests to the scoped , not automatic compliance with every applicable law, contract, or security outcome.

Recommended reading path

Move from ISMS scope to evidence and assurance

New to ISO/IEC 27001? Start with the requirements and implementation roadmap. If the already exists, jump to risk treatment, the SoA, control evidence, audit, certification, or a comparison without reading every guide in order.

1

Start here: understand and plan the ISMS

Understand the certifiable requirements, define a practical implementation sequence, and see how the management system operates as a whole.

2

Risk treatment and the Statement of Applicability

Turn risk decisions into approved treatments, necessary controls, justified Annex A inclusions or exclusions, owners, status, and evidence.

3

Control evidence, evaluation, and improvement

Keep selected controls operating, test effectiveness, conduct independent internal audits, hold management reviews, and close corrective actions.

4

Certification and ongoing assurance

Prepare for Stage 1 and Stage 2, understand the roles of the organization and certification body, and maintain evidence through surveillance and recertification.

5

Compare frameworks and answer focused questions

Separate voluntary certification from legal duties and other assurance models, then use focused answers for recurring implementation decisions.

Next step

Manage ISO/IEC 27001 as governed ISMS work

Route ISO/IEC 27001 implementation into owned tasks, risk decisions, SoA updates, evidence requests, internal reviews, and certification checkpoints so the stays current after the first audit.

What this unlocks
  • Start from the page that matches the current gap: scope, risk treatment, SoA, control evidence, audit, or management review.
  • Use Research Copilot to answer ISO/IEC 27001 interpretation questions with cited source support.
  • Use SSOT to keep owners, risk decisions, evidence records, nonconformities, and review history governed.