International Standard

ISO 27001:2022 · Information Security

The international standard for information security management. Establishes the requirements for implementing, maintaining and improving an Information Security Management System (ISMS).

Latest version: 2022 Applies to: Any organization, of any size or sector Controls: 93 controls across 4 categories

What is ISO 27001?

ISO 27001:2022 is the international standard that establishes the requirements for an Information Security Management System (ISMS). It is the most globally recognized standard for information security management.

ISO 27001 certification demonstrates to clients, providers and regulators that your organization manages information security systematically and effectively.

Key change: The 2022 version restructured the Annex A controls (from 114 to 93) and introduced 11 new controls, including cloud security, threat intelligence and secure information deletion.

Who does it apply to?

ISO 27001 applies to any organization, regardless of size, sector or geographic location:

  • Companies in any sector: Technology, finance, health, education, public administration, etc.
  • Organizations of any size: From startups to large corporations.
  • Service providers: Especially those handling sensitive third-party information.

Structure of ISO 27001:2022

The standard is organized into two main parts:

  • Clauses 1-10: ISMS requirements. Includes organizational context, leadership, planning, support, operation, performance evaluation and improvement.
  • Annex A: Security controls. 93 controls organized into 4 categories: organizational, people, physical and technological.

Main Annex A controls

  • Organizational controls: Security policies, roles and responsibilities, risk management, provider management.
  • People controls: Personnel screening, security training, management of external personnel.
  • Physical controls: Physical perimeters, access control, equipment protection.
  • Technological controls: Logical access control, vulnerability management, network and application security.

How can I help you with ISO 27001?

ISO 27001:2022 Implementation

We design and implement your Information Security Management System, preparing your organization for certification.

View service →

Internal Audit

We conduct internal audits to assess your compliance level and prepare for external certification.

View service →

Integration with NIS2 and DORA

We integrate ISO 27001 with NIS2 and DORA requirements, creating a unified management system.

View service →

Do you need to implement ISO 27001 in your organization?

Request an assessment meeting →

20–30 minutes · No commitment · We review context, need and next steps.