Skip to content

What is an ISMS? ISO 27001 explained

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 2 min read · ISO 27001

ISO 27001 does not certify that you are secure. It certifies that you run a managed, improving system for staying secure — that distinction is the whole framework.

A system, not a checklist

An Information Security Management System (ISMS) is how an organisation manages security as an ongoing discipline: the policies, the risk process, the controls, and — crucially — the management cycle that keeps them running and improving. ISO 27001 certifies that this system exists and works, which is a different claim from "we passed a control checklist at a point in time."

Two halves of the standard

ISO 27001 has two parts. Clauses 4–10 are the mandatory management requirements: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A is a catalogue of controls you select from based on your risk assessment, documented in a Statement of Applicability. You must do the clauses; you choose the Annex A controls that fit your risk.

Why the management cycle matters

The defining feature is the Plan-Do-Check-Act loop: set objectives, run controls, measure and audit them, and act on what you find. Internal audits, management reviews, and corrective actions are not bureaucracy — they are the "management" in management system, and they are exactly what the certification body checks.

What certification gives you

An accredited ISO 27001 certificate is recognised internationally and often carries more weight than SOC 2 with European and global buyers. It says an independent auditor confirmed your ISMS meets the standard — building the trust the management system is designed to earn. SentinelPanda runs the controls and evidence behind the ISMS; an accredited certification body issues the certificate.

ISO 27001 clauses 4 to 10 ISO 27001 Statement of Applicability SOC 2 or ISO 27001: which first?

Run your compliance program in one workspace.