ISO 27001
In Short
ISO/IEC 27001 is an international standard for information security management systems. Rather than prescribing a fixed control list, it requires an organization to define a scope, assess risk methodically, select controls that address the risks it identified, and demonstrate continual improvement — verified by an accredited certification body.
Definition
An ISO 27001 information security management system, or ISMS, is a management framework rather than a technical configuration. The organization establishes a scope stating which parts of the business and which systems are covered, conducts a risk assessment, then produces a risk treatment plan selecting controls to mitigate, accept, transfer, or avoid each risk.
Control selection is justified against Annex A, a reference set of controls that the 2022 revision reorganized into four themes: organizational, people, physical, and technological. Annex A is a checklist to be reasoned against, not adopted wholesale — the organization records applicability in a Statement of Applicability, including why a control was excluded.
Certification runs on a three-year cycle: an initial audit in two stages, then annual surveillance audits, then recertification. Because certification is issued by an accredited body against a declared scope, the scope statement is the first thing worth reading.
Why It Matters
ISO 27001 answers a different question than SOC 2. SOC 2 asks whether stated controls operated effectively over a period; ISO 27001 asks whether the organization runs a functioning process for identifying and managing security risk. Multinational procurement often prefers it because certification is internationally recognized and the certificate itself can be shared.
The practical caution is scope. A certificate covering a corporate function but not the product being purchased is a common and easily missed gap.
How QueryTek Uses It
QueryTek documents ISO 27001 so teams can distinguish a management-system certification from a controls attestation and ask about scope rather than certificate existence. Current QueryTek certification status is communicated through the approved claims register and direct engagement.
Related Terms