Skip to content

ISO/IEC 27001

27001

About the Standard

Nowadays, information plays a crucial part in many business products and processes from payroll information to company secret. Management of information becomes intricate as organizations are surrounded by a wide range of confidential information which requires effective protection against the growing threat from cyber-thieves, hackers, and accidental breaches.

International Organization for Standardization (ISO) establishes a globally recognized ISO/IEC 27001 standard and defines the requirements for establishment, implementation, documentation, and improvement of ISMS. With ISMS, the organization implementing this standard could close loopholes within information securities related processes, people, technology, and organization, and reduce information securities risks. This consequentially strengthens information security in three key areas, i.e., confidentiality, integrity, and availability.

Request a proposal
ISO/IEC 27001 and ISO/IEC 27000

Information security, cybersecurity and privacy protection - Information security management systems - Requirements

ISO/IEC 27000 Series

The ISO/IEC 27000 family of information security management standards (ISMS), also known as the 'ISO27K', is a series consisting of information security standards published together by ISO and the International Electrotechnical Commission (IEC). The series provides guidelines and recommendations on information security management through information security controls within the context of ISMS. The standards in the family can be integrated to deliver best-practice information security management to the organization that implements the standards.

Key Family Standards for Certification

  • ISO/IEC 27017:2026 Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
  • ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors.
  • ISO/IEC 27032:2012 - Information technology — Security techniques — Guidelines for cybersecurity.
  • ISO/IEC 27701:2025 Information security, cybersecurity and privacy protection — Privacy information management systems (PIMS) — Requirements and guidance (Now a stand-alone management system standard for PIMS).
  • ISO/IEC 27799:2025 Health informatics — Information security controls in health based on ISO/IEC 27002.

Advantages of ISO/IEC 27001 and Its Series Certification

  • Systematic detection of vulnerabilities and reduction in risks and disruption caused by information security incidents.
  • Lower costs due to fewer information security incidents.
  • Effective protection for the organization's information, data, and business processes.
  • Identifying opportunities for continuous improvement of the organization's IT and its relevant processes.
  • Fulfillment of internationally recognized requirements, i.e., ISO and IEC.
  • Reduce the burden of contractually required customer audits.
  • Building confidence and trust with clients, business partners, and even staff in the organization.
Factsheet (pdf)

Highlights of 2022 Version

  • In 2022, the International Organization for Standardization (ISO) released the most recent version of ISO 27001 and ISO 27002. This impacts the ISO 27001 standard compliance and certification for all organizations around the globe. Key changes made to the standard are listed below.
  • A simpler version of security controls. The number of controls decreases from 114 to 93 controls and are re-grouped into only 4 main themes, consisting of Organizational, People, Physical, Technological themes.
  • Eleven new controls are added in the control list.
  • Slight changes are made to Clause 4 to 10 of the standard's requirements.
  • Harmonized writing structure (HS) is applied to the standard document to ensure uniform use of core texts, terms and definitions enabling greater integration with systems of different disciplines.
  • New requirements to establish criteria for operational processes and implementing control of the processes.
  • New requirements to monitor information security objectives.
  • New requirements to define organization's process needs and their interactions as part of ISMS.
  • New requirements to communicate organization roles relevant to information security within an organization.

Certification Audit Process

1

01

Request for A Proposal: Company interested in certifying against ISO/IEC 27001 requests for a proposal from TUV NORD Thailand

2

02

Certification Audit:- Stage 1: Documentation Review- Stage 2: On-site Verification

3

03

Issue of ISO/IEC 22301 Certificate

4

04

Surveillance Audit 1 & 2 (within the next 2 years after the certificate is issued)

5

05

Re-certification within the next 3 years after the certificate issued.

FAQs About the ISO 27001 Audit

ISO 27001 is a globally recognised ‘blueprint’ for information security in organisations. Rather than simply installing individual IT programmes, it introduces a system (ISMS) that comprehensively regulates the handling of sensitive data – from technology and organisational structures right through to staff behaviour.

The aim is to protect three core values:

  • Confidentiality: Only authorised persons may access data.
  • Integrity: Data must not be altered or manipulated without detection.
  • Availability: Important systems and information must be available when needed.

In short: the certification proves in black and white that a company is aware of its risks and is doing everything possible to effectively prevent data breaches and cyberattacks.

No, ISO 27001 is not generally a legal requirement in Germany. However, it may be indirectly necessary or advisable if:

  • customers, tenders or clients require ISO 27001 certification,
  • your company falls under NIS-2 / BSIG,
  • you operate in the KRITIS, energy, healthcare, finance or regulated IT services sectors, as proof of ISMS compliance is often mandatory in these areas.

The standard currently applicable to organisations is ISO/IEC 27001:2022. It replaced the previous version from 2013 and contains updated security controls. DIN EN ISO/IEC 27006-1:2024, on the other hand, was published in August 2024 and is the latest version of the guidelines for certification bodies, designed to ensure a consistently high quality of audits. 

Taking into account legal, regulatory and contractual requirements, ISO 27001 sets out the requirements for the design, implementation, operation, monitoring and documentation of your ISMS.

In doing so, existing risks to your organisation are identified, analysed and addressed through appropriate measures. This applies not only to cyber-attacks but also to other disruptions that lead to unplanned interruptions in processes or even bring business operations to a standstill. 

The Plan-Do-Check-Act model, on which ISO 27001 is based, ensures continuous improvement throughout this process.

Thanks to its high-level structure, the information security standard can also be fully integrated into an existing management system compliant with ISO 9001 or ISO 14001.

If you wish to obtain ISO 27001 certification, you must have implemented a risk management system within your organisation, including the identification, analysis, assessment and treatment of risks, as well as a review of its applicability.

ISO 27001 is not limited to IT processes alone, but also takes into account aspects of infrastructure such as organisation, personnel and buildings. After all, data security is becoming an increasingly important competitive factor.

This applies in particular to operators of critical infrastructure (KRITIS), who are required by the BSI Act to ensure a minimum level of IT security.

A voluntary pre-audit (sometimes also referred to as a gap audit) can be used to check your readiness for certification. An auditor randomly checks your management system and provides information on its suitability for certification. A certificate is not issued. The pre-audit does not replace an internal audit.

A two-stage procedure for ISO 27001 certification consists of two audits:

  • Stage 1: Checks certifiability and management system documentation.
  • Stage 2: Evaluates the full implementation and effectiveness of the management system in the company.
    The certificate is only issued once both stages have been successfully completed.

The cost of ISO 27001 certification depends largely on the size of your organisation and the complexity of your IT infrastructure. It is important to distinguish between the audit fees charged by the certification body and the overall costs of implementation (consultancy, staff, tools). We would be happy to provide you with a detailed quote tailored to your specific needs.

Secure Information. Build Trust.

Enhance information security management to protect critical information, reduce the impact of cyber threats, and support business continuity.

As information becomes one of an organization’s most valuable assets, ISO 27001 helps establish a structured Information Security Management System (ISMS), reducing risks, protecting critical information, and strengthening stakeholder confidence.