Skip to main content
—
Framework library
Framework module · iso-27001-2022

ISO/IEC 27001

The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.

2022 (Amd 1:2024) · ISO/IEC 27001:2022 · published 2022-10-25

Standing today
Onboardable
5 evidence lanes

00Answer

from the registry record
What is ISO/IEC 27001?
The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.
Who does ISO/IEC 27001 apply to?
ISO/IEC 27001 applies to all sectors, global, per ISO/IEC 27001:2022.
What is the current version of ISO/IEC 27001?
The current edition is 2022 (Amd 1:2024), issued by ISO/IEC 27001:2022 and published 2022-10-25. Source: https://www.iso.org/standard/27001.
What does an assessment under ISO/IEC 27001 require?
No control catalog has been ingested for ISO/IEC 27001 yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Onboardable

A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.

Blueprint with 5 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.

Engagement
ISO/IEC 27001 readiness — Annex A and management-system evidence
Control set
ISO/IEC 27001:2022 is a licensed standard, so no verbatim Annex A control text or management-system clause text is ingested for this regime. The five lanes carry the published Annex A theme structure (Organizational, People, Physical, Technological controls) and the management-system clause structure (clauses 4 through 10) only — there is no checksummed control catalog for this regime.
Native identifiers
Annex A control identifiers A.5.1 through A.8.34 and management-system clause numbers 4 through 10.
Evidence lanes
  1. 01Management System — Clauses 4–10ISMS scope statement and context analysis · information security policy and top-management commitment records · risk assessment and risk treatment plan, including the Statement of Applicability · documented ISMS procedures and controlled records · internal audit programme and results · management review minutes · nonconformity and corrective action records
  2. 02Annex A.5 — Organizational Controlsinformation security policy set and ownership records · roles and responsibilities matrix · supplier and third-party agreement register · asset inventory and acceptable-use records · access control policy and authorization records
  3. 03Annex A.6 — People Controlsscreening and background check records · employment terms and confidentiality agreements · security awareness and training completion records · disciplinary process records · termination and change-of-employment checklist evidence
  4. 04Annex A.7 — Physical Controlsfacility access control records or provider attestation · secure area and equipment siting records · media handling and disposal records · clear desk and clear screen policy evidence · equipment maintenance and off-site asset records
  5. 05Annex A.8 — Technological Controlsendpoint and privileged-access configuration export · malware protection and logging configuration · vulnerability management and patch records · cryptographic controls and key management evidence · secure development and change control records

02Registry record

checked 2026-08-30
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Organizational · People · Physical · Technological
Applies to
all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
2013Supersededdate not published
2022 (Amd 1:2024)Current edition · supersedes 20132022-10-25

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to all sectors · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.

  2. SOC 22017 TSC (revised points of focus, 2022)

    Same framework family · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

  3. Also applies to all sectors · International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.

  4. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

ISO/IEC 27001 | ControlFrame