Documentation / Platform glossary / ISO 27001

ISO 27001

In Short

ISO/IEC 27001 is an international standard for information security management systems. Rather than prescribing a fixed control list, it requires an organization to define a scope, assess risk methodically, select controls that address the risks it identified, and demonstrate continual improvement — verified by an accredited certification body.

ISO 27001 concept diagram

Definition

An ISO 27001 information security management system, or ISMS, is a management framework rather than a technical configuration. The organization establishes a scope stating which parts of the business and which systems are covered, conducts a risk assessment, then produces a risk treatment plan selecting controls to mitigate, accept, transfer, or avoid each risk.

Control selection is justified against Annex A, a reference set of controls that the 2022 revision reorganized into four themes: organizational, people, physical, and technological. Annex A is a checklist to be reasoned against, not adopted wholesale — the organization records applicability in a Statement of Applicability, including why a control was excluded.

Certification runs on a three-year cycle: an initial audit in two stages, then annual surveillance audits, then recertification. Because certification is issued by an accredited body against a declared scope, the scope statement is the first thing worth reading.

Why It Matters

ISO 27001 answers a different question than SOC 2. SOC 2 asks whether stated controls operated effectively over a period; ISO 27001 asks whether the organization runs a functioning process for identifying and managing security risk. Multinational procurement often prefers it because certification is internationally recognized and the certificate itself can be shared.

The practical caution is scope. A certificate covering a corporate function but not the product being purchased is a common and easily missed gap.

How QueryTek Uses It

QueryTek documents ISO 27001 so teams can distinguish a management-system certification from a controls attestation and ask about scope rather than certificate existence. Current QueryTek certification status is communicated through the approved claims register and direct engagement.

Related Terms