ISO/IEC 27001
The international standard for an information security management system, certified against by an accredited body, with 93 Annex A controls in the 2022 revision.
ISO 27001 certifies a management system, not a set of controls — a distinction that trips up teams approaching it from a SOX or SOC 2 background. The clauses covering context, leadership, planning, support, operation, evaluation and improvement are the certifiable core; Annex A is a reference set of controls you select from based on risk.
The 2022 revision restructured Annex A from 114 controls in 14 domains to 93 in four themes (organisational, people, physical, technological), and introduced eleven new controls covering threat intelligence, cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring, web filtering and secure coding.
The Statement of Applicability is the document that matters most and receives the least care. It records which Annex A controls apply, which do not, and why — and an exclusion justified by inconvenience rather than risk is the most reliable way to fail a certification audit.
For an organisation also pursuing SOC 2, the sensible order is to design unified controls first and let both reports draw from them.
Related