ISO/IEC 27001
The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.
2022 (Amd 1:2024) · ISO/IEC 27001:2022 · published 2022-10-25
00Answer
01Standing
A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.
Blueprint with 5 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.
- Engagement
- ISO/IEC 27001 readiness — Annex A and management-system evidence
- Control set
- ISO/IEC 27001:2022 is a licensed standard, so no verbatim Annex A control text or management-system clause text is ingested for this regime. The five lanes carry the published Annex A theme structure (Organizational, People, Physical, Technological controls) and the management-system clause structure (clauses 4 through 10) only — there is no checksummed control catalog for this regime.
- Native identifiers
- Annex A control identifiers A.5.1 through A.8.34 and management-system clause numbers 4 through 10.
- Evidence lanes
- 01Management System — Clauses 4–10ISMS scope statement and context analysis · information security policy and top-management commitment records · risk assessment and risk treatment plan, including the Statement of Applicability · documented ISMS procedures and controlled records · internal audit programme and results · management review minutes · nonconformity and corrective action records
- 02Annex A.5 — Organizational Controlsinformation security policy set and ownership records · roles and responsibilities matrix · supplier and third-party agreement register · asset inventory and acceptable-use records · access control policy and authorization records
- 03Annex A.6 — People Controlsscreening and background check records · employment terms and confidentiality agreements · security awareness and training completion records · disciplinary process records · termination and change-of-employment checklist evidence
- 04Annex A.7 — Physical Controlsfacility access control records or provider attestation · secure area and equipment siting records · media handling and disposal records · clear desk and clear screen policy evidence · equipment maintenance and off-site asset records
- 05Annex A.8 — Technological Controlsendpoint and privileged-access configuration export · malware protection and logging configuration · vulnerability management and patch records · cryptographic controls and key management evidence · secure development and change control records
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Organizational · People · Physical · Technological
- Applies to
- all sectors · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2013 | Superseded | date not published |
| 2022 (Amd 1:2024) | Current edition · supersedes 2013 | 2022-10-25 |
05Change history
06Related frameworks
- ISO/IEC 270022022
Also applies to all sectors · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.
- SOC 22017 TSC (revised points of focus, 2022)
Same framework family · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
- ISO/IEC 238942023
Also applies to all sectors · International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.
- ASD Essential EightMaturity Model (November 2023)
Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.