What is an ISO/IEC 27001?

ISO/IEC 27001 is an internationally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) — a structured set of policies, risk assessments, and controls for protecting information assets.

Unlike SOC 2, which is an American attestation report, ISO 27001 is a certifiable standard: an accredited external registrar audits an organization against it in two stages — a documentation review (Stage 1) and an implementation audit (Stage 2) — and issues a certificate valid for three years with annual surveillance audits in between. The 2022 revision of the standard organizes its requirements into Clauses 4–10 (the management-system obligations: context, leadership, planning, support, operation, evaluation, improvement) plus Annex A, a reference set of 93 security controls spanning organizational, people, physical, and technological categories. A central artifact of any ISO 27001 program is the Statement of Applicability — a document justifying, for every one of the 93 Annex A controls, whether it applies to the organization and how it's implemented (or why it's excluded). The standard also requires a living risk register, periodic internal audits, and management review, meaning certification isn't a one-time checkbox — the ISMS has to keep operating and producing evidence between audits, not just at audit time.

In practice with Neotask

Neotask's ISO 27001 program reuses the same control spine as its SOC 2 evidence layer — a shared risk register and control matrix viewed through the ISO lens via the Statement of Applicability — so a new feature that touches a protected route or a secret store gets logged once and reflected across both frameworks in the same change.

Related terms

Start free

Plans

Free

$0/mo

Download without a card and start for free.

Individual

$50/mo

The full personal agent platform for one person.

Enterprise

$200/mo

Multiple workspaces and capacity for larger teams.

Continue