Standard

Information security management system (ISO 27001)

An ISMS under ISO 27001 is a way of governing information security: management decides, risk drives the measures, and the work is followed up and improved. We help you build one that is used day to day, not only at the audit.

  • ISO 27001
  • Annex A
  • Risk management
  • Internal audit
  • Certification

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It does not tell you which firewalls to buy. It describes how the organisation decides what needs protecting, assesses the risks, chooses measures, checks that they work and improves them, with management accountable. The current version is ISO/IEC 27001:2022 with a 2024 amendment on climate change. The transition from the previous version, ISO/IEC 27001:2013, ended in October 2025.

A management system is worth something when it carries the decisions in the business: when the risk register is used to prioritise, when the management review leads to decisions, and when the internal audit finds things that are then put right. It is also the structure that lets NIS2 and the Swedish Cybersecurity Act, DORA and the GDPR be handled in one system rather than four tracks. To see where you stand, take the ISO 27001 quick check.

At a glance

Who
Organisations seeking certification, those for whom a customer or owner requires ISO 27001, or those that want a proven structure for security work without certifying
What
Scope, management responsibility, risk assessment and treatment, Statement of Applicability, policies and procedures, monitoring, internal audit, management review and continual improvement
How
Gap analysis, build and implementation in the business, independent internal audit, preparation for certification, and ongoing management

What the standard requires

The requirements are in clauses 4 to 10 of the standard. They apply to every organisation that wants to follow it, whatever its size.

ClauseWhat it means in practice
4 Context of the organisationYou have described the business, the interested parties’ requirements and what the ISMS covers
5 LeadershipManagement has adopted an information security policy, assigned responsibilities and stands behind the work
6 PlanningYou have a risk method, a risk assessment, a risk treatment plan, a Statement of Applicability and measurable objectives
7 SupportResources, competence, awareness, communication and controlled documentation are in place
8 OperationRisk treatment is carried out, and the risk assessment is repeated when something changes
9 Performance evaluationYou measure, carry out internal audits and hold management reviews
10 ImprovementNonconformities lead to corrective action, and the system improves over time

What must be documented is relatively little: the scope, the policy, the risk method and the results of risk assessment and treatment, the Statement of Applicability, the objectives, evidence of competence, monitoring results, the internal audit programme and results, management review results, and nonconformities and actions. The rest you decide yourselves, based on risk.

Annex A and ISO 27002

Annex A of ISO 27001 is a catalogue of 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). You do not have to implement all of them. You compare your risk treatment with the catalogue so that nothing necessary is missed, and justify each inclusion or exclusion in a Statement of Applicability.

ISO/IEC 27002 is the guidance for the same 93 controls: what each is for and how it can be implemented. You cannot certify against it, but it is the practical support when the controls are designed.

To certify or not

Certification is voluntary. A certificate is issued by an accredited certification body after a two-stage audit, is valid for three years and is followed by a surveillance audit every year. Certification is right when customers, tenders or owners require it, or when you need external proof. Without certification the standard can still be the best framework for the work, followed with the same internal audit and management review. How long the build takes is described in the offer ISO 27001 from gap analysis to certification.

A management system that lives

The most common problem we see is not a missing ISMS but one that stops being used after certification. A living ISMS has a few signs:

  • the risk assessment is repeated when the business, systems or suppliers change, not only once a year;
  • management reviews end in decisions with owners and dates;
  • internal audits are done by someone who is not auditing their own work, and nonconformities get closed;
  • the objectives can be measured, and someone follows them up;
  • staff know what applies to them, and new starters learn it from day one.

That is also what a certification auditor looks for at the surveillance audits.

One system for several regulations

NIS2 and the Swedish Cybersecurity Act, DORA, the GDPR and the CRA make overlapping demands: risk analysis, policies, incident handling, continuity, supplier management and management accountability. An ISMS under ISO 27001 handles the common parts once. Our experience is that a working ISMS provides about 80 per cent of the governance and security structure the Cybersecurity Act requires. What remains are the Act’s own obligations, such as registration, incident reporting within fixed deadlines and management training. We build those into the same system rather than a separate track. The same applies to DORA’s ICT risk requirements and register of ICT third-party arrangements, the GDPR’s requirements on processing personal data and the CRA’s requirements on secure development and vulnerability handling.

If you also want management systems for privacy (ISO 27701), continuity (ISO 22301) or quality (ISO 9001), the standards share the same high-level structure, so they can share policy, internal audit and management review.

Common pitfalls

  • The scope is too wide or too narrow: the whole group at once, or only the IT department when the information sits in the business.
  • The risk assessment is done in a workshop and never used again.
  • The Statement of Applicability is filled in but has no justifications.
  • Policies are written for the auditor, not for the people who have to follow them.
  • The internal audit is done by the same people who built the system.
  • Management is there at the start but not in the management review.

How we help

The team includes certified ISO 27001 Lead Implementers and Lead Auditors. Read about a software company that built its ISMS.

Want to know what it would look like for you? Contact us and we will tell you more. Read more about how we work and about ISO 27001 from gap analysis to certification.

Frequently asked questions

Do we have to implement all 93 Annex A controls?

No. You choose controls based on your risk assessment and then compare with Annex A so that nothing necessary is missed. In the Statement of Applicability you justify why each control is included or not.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 contains the requirements for the ISMS and is the standard you certify against. ISO 27002 is guidance on how the Annex A controls can be designed, and you cannot certify against it.

How long is a certificate valid?

For three years, with a surveillance audit by the certification body every year. After three years there is a recertification.

Is ISO 27001 enough for the Swedish Cybersecurity Act?

No, not on its own. A working ISMS covers much of the governance and the security measures, but the Act has its own obligations, such as registration, incident reporting within fixed deadlines and management training, that have to be built in.

Can we run the ISMS ourselves afterwards?

Yes, that is the aim. We hand over procedures, templates and responsibilities so that you can run it yourselves, and can support with internal audit or ongoing advice when you want.

Does a smaller company need a management system?

The standard can be applied at any size. For a smaller company the scope and the documentation are smaller, but the basis is the same: management decisions, risk assessment, measures and follow-up.

Reviewed by Kristensson i Skåne AB. .

Sources: ISO/IEC 27001:2022, information security management systems · ISO/IEC 27001:2022/Amd 1:2024 · ISO/IEC 27002:2022

Would you like a management system that is used day to day?

Contact us