- Standard
- ISO/IEC 27001:2022
- What it certifies
- An Information Security Management System (ISMS)
- Structure
- Management clauses 4–10 plus an Annex A control catalog
- Annex A (2022)
- 93 controls across four themes — Organizational (37), People (8), Physical (14), Technological (34)
- Audit
- Stage 1 and Stage 2 assessments by an accredited certification body
- Validity
- A three-year cycle with annual surveillance audits
01What it is
ISO/IEC 27001 is the international standard for an information security management system — a governing system for how you identify risk and then select, operate, and continually improve controls. Unlike a SOC 2 attestation, it results in a formal certification issued by an accredited certification body, recognized by buyers worldwide.
02How it’s structured
The standard’s management clauses (4 through 10) cover context, leadership, planning, support, operation, performance evaluation, and improvement — the machinery of the ISMS. Annex A provides the control catalog. The 2022 revision reorganized Annex A into 93 controls across four themes: Organizational (37), People (8), Physical (14), and Technological (34). It also introduced 11 new controls reflecting modern practice — including threat intelligence, information security for cloud services, and secure development.
03How certification works
An accredited body runs a Stage 1 review of your documentation and readiness, followed by a Stage 2 audit of the ISMS in operation. Certification is valid for three years, with annual surveillance audits to confirm the system is being maintained and a full recertification at the end of the cycle.
04ISO 27001 vs SOC 2
The two overlap heavily at the control level. The real differences are the deliverable — a certificate versus an attestation report — and the audience that prefers each. Many firms eventually need both; with a shared control set, the second framework is far less than a second project.
05What RedOps delivers
RedOps builds the ISMS and gets you to a successful Stage 2 — reusing your SOC 2 work wherever the controls align.
- ISMS scoping and the supporting documentation set
- A risk assessment and a risk treatment plan
- A Statement of Applicability mapped to the 2022 Annex A controls
- Annex A control implementation and evidence
- Internal audit and the required management review
- Liaison with your accredited certification body
- A control set shared with SOC 2 to avoid duplicate work
For how ISO 27001 and SOC 2 differ and when you genuinely need both, read the field note →