Skip to content
ISO 27001

ISO 27001 — practitioner guides.

25 articles on ISO 27001, ordered newest first. From the SentinelPanda team.

ISO 27001 1 min
June 19, 2026

ISO 27001 vs ISO 27002

You get certified to 27001 and you implement using 27002. One is the requirement; the other is the how-to manual for the controls.

ISO 27001 1 min
June 19, 2026

The documented information ISO 27001 requires

ISO 27001 names the documents you must keep — fewer than people fear. The trap is producing documentation the standard never asked for.

ISO 27001 1 min
June 19, 2026

ISO 27001 surveillance audits and recertification

The certificate lasts three years, but the auditor comes back every year. Surveillance audits are how the certification stays honest.

ISO 27001 1 min
June 19, 2026

ISO 27001 leadership and roles (Clause 5)

ISO 27001 will not let leadership delegate security and walk away. Clause 5 makes top-management ownership an auditable requirement.

ISO 27001 1 min
June 19, 2026

ISO 27001 security objectives and measurement

Objectives you cannot measure are wishes. ISO 27001 asks for security goals with numbers behind them — and proof you actually watch them.

ISO 27001 1 min
June 19, 2026

The ISO 27001 risk treatment plan

The risk assessment finds the risks; the risk treatment plan does something about them. One without the other is half a control.

ISO 27001 1 min
June 19, 2026

Continual improvement in an ISMS

An ISMS that looks identical year to year is, by ISO 27001's logic, not being managed. Continual improvement is the engine the whole standard assumes.

ISO 27001 2 min
June 19, 2026

What is an ISMS? ISO 27001 explained

ISO 27001 does not certify that you are secure. It certifies that you run a managed, improving system for staying secure — that distinction is the whole framework.

ISO 27001 1 min
June 19, 2026

The ISO 27001 certification process

ISO 27001 certification is a two-stage external audit on top of your own internal audit. Knowing the sequence keeps the timeline honest.

ISO 27001 1 min
June 19, 2026

Running an ISO 27001 internal audit

The internal audit is not a dry run you fake — it is a required control, and a real one catches the gaps before the external auditor does.

ISO 27001 1 min
June 19, 2026

The ISO 27001 management review

The management review is where leadership owns the ISMS on the record. Skip it or fake it and you have a major nonconformity.

ISO 27001 1 min
June 19, 2026

How much does ISO 27001 cost?

The certification body is a recurring line item SOC 2 does not have. Scope and internal time are still the bigger numbers.

ISO 27001 1 min
June 19, 2026

ISO 27001 timeline: how long to certification

ISO 27001 is gated by your ISMS needing to actually run for a while before it can be audited — you cannot certify a system with no operating history.

ISO 27001 1 min
June 19, 2026

Defining your ISO 27001 scope

Your certificate is only as meaningful as its scope statement. Scope too wide and you drown; too narrow and buyers notice.

ISO 27001 1 min
June 19, 2026

ISO 27001 Annex A: organizational controls (A.5)

A.5 is the biggest Annex A theme and the most policy-heavy. It is also where most of your existing governance already lives.

ISO 27001 1 min
June 19, 2026

ISO 27001 Annex A: people controls (A.6)

A.6 is the people theme: hiring, training, offboarding, and the rules of working. Most of it lives with HR as much as security.

ISO 27001 1 min
June 19, 2026

ISO 27001 Annex A: physical controls (A.7)

For a cloud-first company, A.7 is mostly inherited from your data-centre providers — but "we use AWS" is an answer you still have to document.

ISO 27001 1 min
June 19, 2026

ISO 27001 Annex A: technological controls (A.8)

A.8 is where the engineering lives: access, crypto, logging, secure development, and network security. It overlaps almost entirely with SOC 2's technical controls.

ISO 27001 1 min
June 19, 2026

ISO 27001 nonconformities and corrective action

A nonconformity is not failure — an audit with zero findings is more suspicious than one with a few. What matters is how you close them.

ISO 27001 1 min
June 19, 2026

ISO 27001 for startups

ISO 27001 looks heavier than SOC 2 because of the management-system machinery. For a startup, the trick is keeping that machinery small but real.

ISO 27001 2 min
June 17, 2026

Access reviews that pass an ISO 27001 audit

Access creep is the most common audit finding there is. A repeatable review closes it — and one record satisfies four frameworks.

ISO 27001 3 min
April 28, 2026

What changed in ISO 27001:2022 Annex A

The 2022 revision is structural, not philosophical. Most of the old controls survived under new numbers; the change is in the grouping and the 11 controls that did not exist before.

ISO 27001 3 min
April 7, 2026

ISO 27001 risk assessment and treatment under clause 6.1

A good ISMS is a chain of decisions: identify risks, evaluate them, treat them, and document the result. Clause 6.1 is where that chain is built, and where most certification findings start.

ISO 27001 1 min
February 18, 2026

The ISO 27001 Statement of Applicability, done right

The SoA is the single document a certification auditor measures everything else against. Get it right and the audit goes smoothly.

ISO 27001 4 min
February 13, 2026

ISO 27001 mandatory clauses 4 to 10, explained

ISO 27001 is a management system standard. The 93 Annex A controls are the visible half; clauses 4 to 10 are the management system itself, and they decide whether the audit goes well.