ISO 27001 — practitioner guides.
25 articles on ISO 27001, ordered newest first. From the SentinelPanda team.
ISO 27001 vs ISO 27002
You get certified to 27001 and you implement using 27002. One is the requirement; the other is the how-to manual for the controls.
The documented information ISO 27001 requires
ISO 27001 names the documents you must keep — fewer than people fear. The trap is producing documentation the standard never asked for.
ISO 27001 surveillance audits and recertification
The certificate lasts three years, but the auditor comes back every year. Surveillance audits are how the certification stays honest.
ISO 27001 leadership and roles (Clause 5)
ISO 27001 will not let leadership delegate security and walk away. Clause 5 makes top-management ownership an auditable requirement.
ISO 27001 security objectives and measurement
Objectives you cannot measure are wishes. ISO 27001 asks for security goals with numbers behind them — and proof you actually watch them.
The ISO 27001 risk treatment plan
The risk assessment finds the risks; the risk treatment plan does something about them. One without the other is half a control.
Continual improvement in an ISMS
An ISMS that looks identical year to year is, by ISO 27001's logic, not being managed. Continual improvement is the engine the whole standard assumes.
What is an ISMS? ISO 27001 explained
ISO 27001 does not certify that you are secure. It certifies that you run a managed, improving system for staying secure — that distinction is the whole framework.
The ISO 27001 certification process
ISO 27001 certification is a two-stage external audit on top of your own internal audit. Knowing the sequence keeps the timeline honest.
Running an ISO 27001 internal audit
The internal audit is not a dry run you fake — it is a required control, and a real one catches the gaps before the external auditor does.
The ISO 27001 management review
The management review is where leadership owns the ISMS on the record. Skip it or fake it and you have a major nonconformity.
How much does ISO 27001 cost?
The certification body is a recurring line item SOC 2 does not have. Scope and internal time are still the bigger numbers.
ISO 27001 timeline: how long to certification
ISO 27001 is gated by your ISMS needing to actually run for a while before it can be audited — you cannot certify a system with no operating history.
Defining your ISO 27001 scope
Your certificate is only as meaningful as its scope statement. Scope too wide and you drown; too narrow and buyers notice.
ISO 27001 Annex A: organizational controls (A.5)
A.5 is the biggest Annex A theme and the most policy-heavy. It is also where most of your existing governance already lives.
ISO 27001 Annex A: people controls (A.6)
A.6 is the people theme: hiring, training, offboarding, and the rules of working. Most of it lives with HR as much as security.
ISO 27001 Annex A: physical controls (A.7)
For a cloud-first company, A.7 is mostly inherited from your data-centre providers — but "we use AWS" is an answer you still have to document.
ISO 27001 Annex A: technological controls (A.8)
A.8 is where the engineering lives: access, crypto, logging, secure development, and network security. It overlaps almost entirely with SOC 2's technical controls.
ISO 27001 nonconformities and corrective action
A nonconformity is not failure — an audit with zero findings is more suspicious than one with a few. What matters is how you close them.
ISO 27001 for startups
ISO 27001 looks heavier than SOC 2 because of the management-system machinery. For a startup, the trick is keeping that machinery small but real.
Access reviews that pass an ISO 27001 audit
Access creep is the most common audit finding there is. A repeatable review closes it — and one record satisfies four frameworks.
What changed in ISO 27001:2022 Annex A
The 2022 revision is structural, not philosophical. Most of the old controls survived under new numbers; the change is in the grouping and the 11 controls that did not exist before.
ISO 27001 risk assessment and treatment under clause 6.1
A good ISMS is a chain of decisions: identify risks, evaluate them, treat them, and document the result. Clause 6.1 is where that chain is built, and where most certification findings start.
The ISO 27001 Statement of Applicability, done right
The SoA is the single document a certification auditor measures everything else against. Get it right and the audit goes smoothly.
ISO 27001 mandatory clauses 4 to 10, explained
ISO 27001 is a management system standard. The 93 Annex A controls are the visible half; clauses 4 to 10 are the management system itself, and they decide whether the audit goes well.