Skip to main content
DocumentMS

Glossary

ISO/IEC 27001

Also called: ISO 27001, ISMS standard

ISO/IEC 27001 is the international standard for information security management systems. It certifies a management system — the scope, risk assessment, selected controls and the evidence that they operate — rather than a product, which is the reason no piece of software can make an organisation compliant on its own.

ISO/IEC 27001 explained

What certification covers

Your scope statement, your risk assessment, the controls you selected and why, and the evidence that they operate over time. An auditor examines the management system; the tools are only relevant as the means by which controls are implemented and evidenced.

Where a document system contributes

Clauses 7.5.1 to 7.5.3 require documented information to be identified, approved, available and controlled — which is document control. Several Annex A controls then depend on evidence a document system generates as a byproduct: access control and access rights, logging, protection of records, information deletion and classification.

That is a meaningful reduction in effort rather than compliance itself.

The three documents that must agree

The statement of applicability lists which controls you adopted. The risk treatment plan justifies them. The policy set implements them. An inconsistency between the three is the most common major non-conformity in a first certification audit, and it arises because they are maintained separately by separate people.

Linking them by control reference is the practical fix.

Surveillance audits

A surveillance audit asks whether a control operated throughout the period since the last visit — not whether it operates today. Evidence therefore needs an audit-period field, or the question cannot be answered by filtering.

FAQ

ISO/IEC 27001: common questions

Can a product be ISO 27001 certified?

A vendor's own management system can be certified, which tells you something about the vendor. The product cannot be, and a vendor implying their software certifies you is misrepresenting the standard.

Which controls should we tag evidence with?

The Annex A reference, plus the audit period the evidence belongs to. Those two fields turn 'show me that this control operated during this period' into a two-clause filter.

A 30-minute session with a solutions engineer, using a folder structure and approval chain that resemble yours — not a generic demo tenant.