International information security management standard guide.

Overview

ISO/IEC 27001 is the international standard for information security management systems (ISMS).

Who needs it: Organizations worldwide seeking information security certification
Status in AuditKit: Production
Coverage: 53 controls, derived via the NIST 800-53 crosswalk - 53 on AWS, Azure and GCP alike, out of the 93 controls in Annex A
What's covered: Technical controls (A.8), organizational (A.5), people (A.6), physical (A.7)

Important Disclaimer

AuditKit's ISO 27001 support covers technical controls only - NOT sufficient for ISO 27001 certification.

What AuditKit covers:

  • Annex A technological controls (A.8) - 32 of 34 automated
  • Some organizational controls (A.5) - via configuration checks
  • Limited people controls (A.6) - user/account management only
  • Limited physical controls (A.7) - cloud provider inheritance

What AuditKit does NOT cover:

  • ISMS documentation (policies, procedures, records)
  • Risk assessment and treatment
  • Internal audits
  • Management review
  • Continual improvement processes
  • Organizational controls requiring human processes

Use for: Technical control assessment as part of ISO 27001 compliance program
Don't use for: Sole evidence of ISO 27001 certification
Hire a consultant for: Complete ISMS implementation and certification audit

ISO 27001:2022 Changes

The 2022 version reduced controls from 114 to 93 and reorganized into 4 themes:

Changes from 2013 version:

  • Consolidated from 14 to 4 control categories
  • 11 new controls (cloud, threat intelligence, data masking)
  • 24 merged controls
  • 58 controls with updated titles
  • Stronger focus on cloud security

AuditKit supports ISO 27001:2022

Annex A Controls

A.5: Organizational Controls (37 controls)

Focus on policies, roles, responsibilities, asset management:

AuditKit Coverage:

  • A.5.1: Information security policies
  • A.5.9: Asset inventory
  • A.5.10: Acceptable use
  • A.5.14: Information transfer
  • A.5.23: Information security for cloud services
  • A.5.30: ICT readiness for business continuity

Manual/Organizational:

  • Risk assessment processes
  • Roles and responsibilities
  • Contact with authorities
  • Project management security
  • Supplier relationships

A.6: People Controls (8 controls)

Focus on HR security, awareness, training:

AuditKit Coverage:

  • A.6.2: Terms and conditions of employment (via account policies)
  • A.6.3: Information security awareness (training logs)

Manual/Organizational:

  • Background screening
  • Security responsibilities documentation
  • Disciplinary process

A.7: Physical Controls (14 controls)

Focus on facility security, equipment protection:

AuditKit Coverage:

  • A.7.4: Physical security monitoring (cloud provider docs)
  • A.7.13: Equipment maintenance (cloud provider SLAs)

Manual/Organizational (or Cloud Provider Inherited):

  • Physical security perimeters
  • Physical entry controls
  • Securing offices and facilities
  • Clear desk and screen policies
  • Equipment disposal

A.8: Technological Controls (34 controls) - PRIMARY FOCUS

Fully Automated by AuditKit:

  • A.8.2: Privileged access rights
  • A.8.3: Information access restriction
  • A.8.5: Secure authentication
  • A.8.6: Capacity management
  • A.8.7: Protection against malware
  • A.8.8: Management of technical vulnerabilities
  • A.8.9: Configuration management
  • A.8.10: Information deletion
  • A.8.13: Information backup
  • A.8.15: Logging
  • A.8.16: Monitoring activities
  • A.8.20: Networks security
  • A.8.21: Security of network services
  • A.8.22: Segregation of networks
  • A.8.24: Use of cryptography
  • A.8.32: Change management

Partially Automated:

  • A.8.1: User endpoint devices (cloud access policies)
  • A.8.4: Access to source code (repository settings)
  • A.8.17: Clock synchronization (NTP configuration)
  • A.8.23: Web filtering (network policies)

Manual/Policy-Based (the only two A.8 controls with no automated check):

  • A.8.14: Redundancy of information processing facilities
  • A.8.25: Secure development life cycle

Running ISO 27001 Scans

# ISO 27001 scan
auditkit scan -provider aws -framework iso27001

# Azure
auditkit scan -provider azure -framework iso27001

# GCP
auditkit scan -provider gcp -framework iso27001

# Generate report
auditkit scan -provider aws -framework iso27001 -format pdf -output iso27001-report.pdf

# CSV for control tracking
auditkit scan -provider aws -framework iso27001 -format csv -output iso27001-controls.csv

ISO 27001 Certification Process

Stage 1: Planning (Months 1-6)

  1. Gap Analysis
  2. Run AuditKit to assess technical controls
  3. Identify missing organizational controls
  4. Document current state

  5. ISMS Design

  6. Define ISMS scope
  7. Establish security policy
  8. Conduct risk assessment
  9. Create Statement of Applicability (SoA)

  10. Implementation Plan

  11. Prioritize control implementation
  12. Assign responsibilities
  13. Set timelines

Stage 2: Implementation (Months 7-12)

  1. Technical Controls
  2. Remediate gaps found by AuditKit
  3. Implement security configurations
  4. Deploy monitoring and logging

  5. Documentation

  6. Develop policies and procedures
  7. Create work instructions
  8. Document control implementation

  9. Training

  10. Security awareness for all staff
  11. Role-specific training
  12. ISMS process training

Stage 3: Internal Audit (Month 13)

  • Conduct internal ISMS audit
  • Test control effectiveness
  • Document findings
  • Remediate gaps

Stage 4: Management Review (Month 14)

  • Present ISMS performance to management
  • Review audit findings
  • Approve changes and improvements

Stage 5: Certification Audit (Months 15-16)

  1. Stage 1 Audit (Documentation review)
  2. Certifying body reviews ISMS documentation
  3. Checks scope definition
  4. Reviews SoA
  5. Identifies major gaps

  6. Stage 2 Audit (On-site assessment)

  7. Certifying body assesses control implementation
  8. Interviews staff
  9. Reviews evidence
  10. Tests control effectiveness

  11. Certification Decision

  12. Address any non-conformities
  13. Receive ISO 27001 certificate (valid 3 years)

Stage 6: Surveillance (Ongoing)

  • Annual surveillance audits
  • Continuous improvement
  • Internal audits (at least annually)
  • Management reviews (at least annually)
  • Recertification every 3 years

ISO 27001 vs Other Frameworks

Framework Overlap with ISO 27001 Notes
SOC2 High Similar technical controls
NIST 800-53 Very High Most ISO controls map to 800-53
PCI-DSS Medium PCI more prescriptive
CMMC High Both based on similar principles
ISO 27017 Extension ISO 27001 + cloud-specific controls
ISO 27018 Extension ISO 27001 + privacy controls

Key Differentiators:

  • ISO 27001 is international (global recognition)
  • Requires formal ISMS (not just controls)
  • Risk-based approach (tailor controls to risks)
  • 3-year certification cycle
  • Requires internal audits and management review

Cost Breakdown

Item Small Org (<50 people) Medium Org (50-250) Large Org (250+)
AuditKit Free $0 $0 $0
Gap analysis $5K-15K $15K-30K $30K-60K
ISMS implementation $20K-50K $50K-100K $100K-200K
Documentation $10K-25K $25K-50K $50K-100K
Training $5K-10K $10K-25K $25K-50K
Internal audit $5K-10K $10K-20K $20K-40K
Certification audit $10K-20K $20K-40K $40K-80K
Initial certification $55K-130K $130K-265K $265K-530K
Annual surveillance $10K-20K $20K-40K $40K-80K
Recertification (Year 3) $10K-20K $20K-40K $40K-80K

Timeline: 12-18 months from start to certification

Choosing a Certification Body

Accredited certification bodies (CB) vary by:

Accreditation: Look for UKAS (UK), ANAB (US), DAkkS (Germany), JAB (Japan)

Industry Experience: Choose CB with experience in your industry

Global Recognition: Major CBs:

  • BSI (British Standards Institution)
  • SGS
  • Bureau Veritas
  • LRQA
  • TUV
  • DNV

Cost: $10K-80K depending on organization size and scope

Common ISO 27001 Gaps

Based on certification audit findings:

  1. Incomplete risk assessment (most common)
  2. Inadequate ISMS documentation
  3. Insufficient logging and monitoring (A.8.15, A.8.16)
  4. Weak access controls (A.8.2, A.8.3, A.8.5)
  5. Missing internal audits
  6. Poor change management (A.8.32)
  7. Inadequate security awareness (A.6.3)
  8. Incomplete Statement of Applicability

AuditKit helps with #3, #4, #6 - you need consultants for #1, #2, #5, #7, #8

FAQ

Q: Can I get ISO 27001 certified using only AuditKit? A: No. AuditKit covers technical controls, but ISO 27001 requires complete ISMS documentation, risk assessments, internal audits, and formal certification audit. Hire a consultant.

Q: How long does ISO 27001 certification take? A: 12-18 months for initial certification. Smaller organizations may achieve it faster (9-12 months).

Q: What's the difference between ISO 27001 and ISO 27002? A: ISO 27001 is the certifiable standard (requirements). ISO 27002 is the implementation guide (best practices). You get certified to 27001, not 27002.

Q: Do I need to implement all 93 controls? A: No. ISO 27001 allows risk-based exclusions. Document justification in your Statement of Applicability (SoA).

Q: How much does ISO 27001 certification cost? A: Small org: $55K-130K initial, $10K-20K annual. Medium org: $130K-265K initial, $20K-40K annual.

Q: Is ISO 27001 recognized globally? A: Yes. ISO 27001 is the most widely recognized information security certification worldwide.

Q: What happens if I fail the certification audit? A: You receive non-conformity reports. Address them within specified timeframe, then CB re-audits. Most organizations pass on second attempt.

Q: Can I transfer my certificate if I change certification bodies? A: Yes, though the new CB may require a transfer audit to verify your ISMS.

Q: Does ISO 27001 help with GDPR compliance? A: Yes. ISO 27001 addresses many GDPR security requirements, though GDPR has additional privacy-specific requirements.

ISO 27001 and Cloud

Shared Responsibility:

  • Cloud providers (AWS, Azure, GCP) have ISO 27001 certification for their infrastructure
  • You're responsible for your applications and configurations
  • Use cloud provider inherited controls in your SoA

Cloud-Specific Controls:

  • A.5.23: Information security for use of cloud services
  • A.8.20-22: Network security (cloud networks)
  • A.8.24: Cryptography (cloud encryption)

AuditKit helps verify your cloud configurations align with ISO 27001 requirements.

Recommended Path

Phase 1: Assessment (Months 1-3)

  • Run AuditKit for technical gap analysis
  • Conduct full ISMS gap assessment
  • Define ISMS scope
  • Select certification body

Phase 2: Design (Months 4-6)

  • Establish security policy
  • Conduct risk assessment
  • Create Statement of Applicability
  • Design ISMS processes

Phase 3: Implementation (Months 7-12)

  • Implement controls (use AuditKit for technical)
  • Develop ISMS documentation
  • Deploy monitoring and logging
  • Train all personnel

Phase 4: Audit (Months 13-15)

  • Conduct internal audit
  • Management review
  • Remediate findings
  • Prepare for certification audit

Phase 5: Certification (Months 16-18)

  • Stage 1 audit (documentation review)
  • Address Stage 1 findings
  • Stage 2 audit (on-site assessment)
  • Receive ISO 27001 certificate

Phase 6: Maintain (Ongoing)

  • Annual surveillance audits
  • Internal audits (minimum annually)
  • Management reviews (minimum annually)
  • Continuous improvement
  • Recertification every 3 years

Next Steps

Remember: AuditKit covers technical controls (Annex A.8). Hire an ISO 27001 consultant for complete ISMS implementation and certification.

Scan your environment

Point AuditKit at AWS, Azure or GCP with read-only credentials and get every finding with the command to fix it. Full results in about thirty minutes.

Start 14-Day Free Trial

$297/month after the trial. Cancel any time. The Community Edition is free and open source.