Glossary
ISO/IEC 27001
Also called: ISO 27001, ISMS standard
ISO/IEC 27001 is the international standard for information security management systems. It certifies a management system — the scope, risk assessment, selected controls and the evidence that they operate — rather than a product, which is the reason no piece of software can make an organisation compliant on its own.
ISO/IEC 27001 explained
What certification covers
Your scope statement, your risk assessment, the controls you selected and why, and the evidence that they operate over time. An auditor examines the management system; the tools are only relevant as the means by which controls are implemented and evidenced.
Where a document system contributes
Clauses 7.5.1 to 7.5.3 require documented information to be identified, approved, available and controlled — which is document control. Several Annex A controls then depend on evidence a document system generates as a byproduct: access control and access rights, logging, protection of records, information deletion and classification.
That is a meaningful reduction in effort rather than compliance itself.
The three documents that must agree
The statement of applicability lists which controls you adopted. The risk treatment plan justifies them. The policy set implements them. An inconsistency between the three is the most common major non-conformity in a first certification audit, and it arises because they are maintained separately by separate people.
Linking them by control reference is the practical fix.
Surveillance audits
A surveillance audit asks whether a control operated throughout the period since the last visit — not whether it operates today. Evidence therefore needs an audit-period field, or the question cannot be answered by filtering.
FAQ
ISO/IEC 27001: common questions
Can a product be ISO 27001 certified?
A vendor's own management system can be certified, which tells you something about the vendor. The product cannot be, and a vendor implying their software certifies you is misrepresenting the standard.
Which controls should we tag evidence with?
The Annex A reference, plus the audit period the evidence belongs to. Those two fields turn 'show me that this control operated during this period' into a two-clause filter.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
Última revisión: 28 de agosto de 2026. Browse the full glossary.