ISO 27001 Explained Simply (Beginner-Friendly Guide)

By | March 21, 2026

Some organizations survive a data breach with their reputation intact. Others do not. The difference usually comes down to whether security was a system or a set of good intentions.

ISO 27001 is the most widely recognized framework for turning security into a system. The name sounds intimidating. The idea behind it is not.

This guide covers what ISO 27001 actually is, what it requires, what certification costs and how long it takes, and — because most guides skip this — what it does and does not do if you run industrial systems.

What Is ISO 27001?

ISO 27001 is an international standard for managing information security. Its full name is ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

It was developed jointly by the International Organization for Standardization and the International Electrotechnical Commission.

At its core, the standard describes how to build and run an Information Security Management System (ISMS) — a working combination of people, processes, and technology that protects information from threats.

Think of it less like a product and more like a management method. It tells you how to organize your security effort. It does not tell you which firewall to buy.

If the acronym is new to you, we break down what an ISMS is in a separate guide.

Which Version Is Current

This matters more than most beginners expect, because certificates were affected.

VersionStatus
ISO/IEC 27001:2013Withdrawn. Transition ended 31 October 2025
ISO/IEC 27001:2022Current
ISO/IEC 27001:2022/Amd 1:2024Adds climate change considerations to Clauses 4.1 and 4.2

Organizations certified against the 2013 version had a transition window that closed on 31 October 2025. Certificates that were not transitioned are no longer valid.

If a supplier hands you a certificate, check two things: the version, and the expiry date. A 2013 certificate is not evidence of anything today.

Why the Standard Exists

Every industry and country has its own security rules. Healthcare has HIPAA. Payment processors follow PCI DSS. European organizations deal with GDPR and NIS2. U.S. federal agencies use NIST SP 800 series.

A company operating across three countries has to satisfy several of these at once, each with its own vocabulary and its own auditors.

ISO 27001 gives them one internationally recognized framework that maps across most of the others. Instead of building a separate security program per regulation, you build one management system and demonstrate how it meets each obligation.

That is the practical value. Not the certificate — the common structure underneath it.

The Three Pillars: Confidentiality, Integrity, Availability

Everything in ISO 27001 protects three properties of information, usually called the CIA triad.

Confidentiality — only authorized people can see the information. Weak access control, missing encryption, and untrained staff are the usual failure points.

Integrity — the information is accurate and has not been altered without detection. If someone can quietly change a record, you cannot trust anything built on it.

Availability — the information and the systems holding it are there when people need them. Redundancy, backups, and tested recovery plans keep this true.

Remember the order. It becomes important later, because in industrial environments the order is different.

The ISMS Is Not a Folder of Policies

A common misconception is that an ISMS is a set of documents. Documentation is part of it, but a folder that nobody opens is not a management system.

A working ISMS has three components:

  • People — they design it, run it, and are the most common point of failure
  • Processes — how information is handled, how incidents get reported, how risks are assessed
  • Technology — the tools that enforce the rules, reviewed as threats change

If the documents describe something nobody actually does, an auditor will find out. That is what Stage 2 of the certification audit is for.

How It Works: Plan-Do-Check-Act

ISO 27001 does not treat security as a project with an end date. It uses the Plan-Do-Check-Act (PDCA) cycle, the same continual improvement model used across ISO management standards.

Show Image

Plan — set security objectives, identify risks, write the policies and procedures to manage them.

Do — implement them. Run the processes, train people, put controls in place.

Check — measure. Internal audits, performance metrics, results against objectives.

Act — fix what the checking found. Close gaps, correct nonconformities, feed it into the next cycle.

The loop is what makes certification meaningful. A certificate proves the loop is turning, not that the organization is secure on one particular afternoon.

Clauses 4–10: The Core Requirements

ISO 27001 contains ten clauses. The first three are introductory — scope, references, terms. The auditable requirements start at Clause 4.

Show Image

Clause 4 — Context of the Organization. Understand what you are protecting and why. Internal environment, external environment, interested parties, legal obligations. This is where the scope of the ISMS gets defined, and scope decides everything that follows. Read industry threats as part of this.

Clause 5 — Leadership. Senior management has to demonstrate commitment, approve the information security policy, and assign roles. Not sign-off. Commitment. Auditors ask executives direct questions.

Clause 6 — Planning. Identify and assess information security risks, decide how to treat them, set measurable objectives. This clause produces the Statement of Applicability, covered below.

Clause 7 — Support. Resources, competence, awareness, communication, documented information. Security responsibilities belong inside people’s actual jobs, not in a side project.

Clause 8 — Operation. Run the risk assessments, apply the controls, keep the evidence. Regular risk assessment is a requirement, not a one-time exercise.

Clause 9 — Performance Evaluation. Monitoring, measurement, internal audit, management review. Somebody has to check whether the system works, and management has to look at the answer.

Clause 10 — Improvement. Nonconformities get recorded, prioritized, and fixed within a defined timeframe. Continual improvement is mandatory.

See Clauses 4–10 explained for how each requirement works in practice.

Annex A: The 93 Security Controls

Annex A is a reference catalogue of security controls. The 2022 version contains 93 controls grouped into four themes.

ThemeControlsCovers
Organizational37Policies, roles, supplier security, incident management
People8Screening, training, disciplinary process, remote working
Physical14Secure areas, equipment, clear desk, cabling security
Technological34Access control, cryptography, logging, malware, secure development
Total93

Show Image

If you learned the older structure, this will look unfamiliar. The 2013 version had 114 controls in 14 domains. The 2022 revision consolidated them into four themes and added 11 new controls, including threat intelligence, cloud services security, data leakage prevention, and secure coding.

Nothing was really removed. Controls were merged and reorganized.

You Do Not Implement All 93

This is the point beginners miss most often. Annex A is a reference list, not a checklist.

You run a risk assessment, decide which risks need treating, and select the controls that treat them. Then you justify — in writing — every control you selected and every control you excluded.

That justification document is the Statement of Applicability (SoA).

The SoA is the single most scrutinized document in a certification audit. It is where an auditor sees whether your ISMS reflects real risk analysis or a template someone downloaded.

The full catalogue is covered in our guide to Annex A security controls.

What ISO 27001 Means If You Run Industrial Systems

This section does not appear in most ISO 27001 guides, because most are written by people who have never stood in a substation. It matters, and it changes the answer.

The Priorities Invert

ISO 27001 was written for information assets. The CIA triad puts confidentiality first.

In operational technology, the order flips:

EnvironmentPriority order
ITConfidentiality → Integrity → Availability
OTAvailability → Integrity → Confidentiality

A leaked register value from a pump station is embarrassing. A pump station that stops responding is a process incident. And safety — the property that matters most in industrial systems — does not appear in the CIA triad at all.

Scope Usually Excludes the Plant

Read the scope statement on any industrial company’s ISO 27001 certificate. It typically covers corporate IT, data centers, and business applications. The control network is often outside it.

That is a legitimate choice under the standard. Scope is defined by the organization. But it means a certificate says nothing about whether the PLCs are protected.

When a supplier sends you a certificate as evidence of OT security, the scope statement is the first thing to read, not the logo.

What an ISO 27001 Auditor Will Not Look At

  • Whether your industrial protocols carry any authentication at all
  • PLC firmware integrity and change control on the control network
  • Whether a patch will disturb a running process
  • Safety instrumented systems
  • Real-time constraints that rule out standard IT controls
  • Serial links, engineering workstations, and vendor remote access into the process

None of this is a flaw in the standard. It is simply outside what the standard was written to address.

What to Use Instead — or Alongside

IEC 62443 was written for industrial automation and control systems. It adds concepts ISO 27001 does not have: security zones and conduits, security levels SL 1 to SL 4, and defined roles for asset owner, system integrator, and product supplier.

Most industrial organizations end up running both. ISO 27001 at the corporate level for governance and information assets. IEC 62443 at the plant level for the control system itself. They are complementary, not alternatives.

Before choosing a framework, read IEC 62443 vs ISO 27001. If you are moving between the two worlds, our IT to OT guide covers the mindset shift.

Certification: Time, Cost, and What Happens

The Process

Stage 1 audit — a documentation review. The auditor checks that the ISMS exists on paper, that the scope makes sense, and that the SoA is coherent. Gaps found here are usually fixable.

Stage 2 audit — the real one. The auditor tests whether the ISMS operates as documented. Interviews, records, evidence.

Certificate — valid for three years.

Surveillance audits — typically annual, smaller in scope.

Recertification — a full audit in year three.

How Long It Takes

For a first certification, most organizations need 6 to 12 months from decision to certificate. A small, well-organized company with an existing security program can do it faster. An organization starting from nothing takes longer.

The time is rarely spent on the audit. It is spent building evidence that the system has been running long enough to have results — audits performed, incidents handled, a management review completed.

What Drives the Cost

Published price ranges vary so widely that quoting one number is misleading. What is consistent is what drives it:

  • Scope size — number of sites, employees, and systems inside the boundary
  • Starting point — an existing security program versus starting from zero
  • Consulting — often the largest line item, and optional
  • Tooling — compliance platforms, or spreadsheets and discipline
  • Certification body fees — audit days, which scale with scope
  • Internal time — usually underestimated, and often the biggest real cost

The single most effective way to reduce cost is to define a tight, defensible scope. A narrow scope that you can genuinely control beats a broad one you cannot.

The full path is covered in our ISO 27001 certification process guide.

Benefits Beyond the Certificate

A stronger security posture. The structured risk process finds weaknesses before attackers do. This is the point; the certificate is the byproduct.

Regulatory alignment. ISO 27001 maps onto GDPR, NIS2, and most sector regulations. It is not a substitute for any of them, but it reduces duplicated work.

Commercial access. In many tenders, certification is a filter. No certificate, no bid.

Fewer customer audits. A recognized certificate replaces a portion of the security questionnaires and client-driven audits that otherwise consume the security team.

Internal clarity. Implementation forces organizations to answer questions they had been avoiding: who owns which system, what happens when someone leaves, which supplier can reach what.

ISO 27001 and Its Neighbors

ISO 27001 belongs to the ISO 27000 family:

StandardRole
ISO/IEC 27000Vocabulary and overview
ISO/IEC 27001What the ISMS must achieve — certifiable requirements
ISO/IEC 27002How to implement the Annex A controls — guidance only
ISO/IEC 27005Information security risk management

Only 27001 is certifiable. The others support it.

Frequently Asked Questions

Is ISO 27001 mandatory? No. It is voluntary. It becomes effectively mandatory when customers, tenders, or contracts require it — which is common in cloud services, financial services, and public procurement.

How long does ISO 27001 certification take? Typically 6 to 12 months for a first certification. Most of that time goes into running the ISMS long enough to produce evidence, not into the audit itself.

How long is an ISO 27001 certificate valid? Three years, with surveillance audits in between — usually annual — and a full recertification audit at the end of the cycle.

Can an individual be ISO 27001 certified? No. Organizations are certified, not people. Individuals earn qualifications such as Lead Auditor or Lead Implementer, which are different things.

What is the difference between ISO 27001 and ISO 27002? ISO 27001 states the requirements and is certifiable. ISO 27002 gives implementation guidance for the Annex A controls and is not certifiable. You are audited against 27001 and you read 27002 to do the work.

Do I have to implement all 93 Annex A controls? No. You select controls based on your risk assessment and justify both inclusions and exclusions in the Statement of Applicability. Excluding a control is acceptable when the justification holds.

Is ISO 27001 enough for SCADA and industrial systems? Usually not on its own. It was written for information assets, and most certified scopes exclude the control network. IEC 62443 addresses the industrial layer. Many organizations run both.

What is the difference between ISO 27001 and SOC 2? ISO 27001 is an international standard with a certificate issued by an accredited certification body. SOC 2 is a report — an attestation issued by a CPA firm, mainly recognized in the United States. One proves a management system exists; the other reports on how controls operated over a period.

Is ISO 27001:2013 still valid? No. The transition period ended on 31 October 2025. Certificates against the 2013 version are no longer valid, and current certification is against ISO/IEC 27001:2022.

Author: Zakaria El Intissar

I've spent 13 years in power system automation, electrical protection, and SCADA communication, as an automation and industrial computing engineer. ScadaProtocols.com is where I turn what I've learned on site into plain guides and working tools — so other engineers can decode, analyze, and troubleshoot industrial communication protocols without the guesswork.

Leave a Reply

Your email address will not be published. Required fields are marked *