Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Compliance

ISO/IEC 27001

ISO/IEC 27001 is the international standard that specifies the requirements for an information security management system (ISMS): a governed, risk-based process by which an organization defines its security scope, assesses its risks, selects controls, operates them and improves them. Certification is granted by an accredited body after audit and maintained over a three-year cycle with surveillance audits. The 2022 edition lists 93 reference controls in Annex A, grouped as organizational, people, physical and technological.

A management system, not a checklist

The standard’s core clauses ask for context and scope, leadership commitment, a risk assessment and treatment process, resources and competence, operational planning, performance evaluation and continual improvement. Annex A is the catalog the risk treatment draws from, and the Statement of Applicability records which controls apply and why. An organization can be certified with controls excluded, provided the exclusion is justified by the risk assessment. That is why two certificates can cover very different realities.

What auditors actually look at

Evidence that the process runs: risk assessments with dates and owners, management reviews with decisions, internal audit results, corrective actions closed, and for each applicable control the records that it operates (access reviews, change records, supplier evaluations, awareness sessions). Certification audits sample; the risk for the certified organization is evidence that exists for the audit week and nowhere else in the year.

Where it meets the European texts

ISO 27001 does not make an organization NIS2 or DORA compliant, but its control set overlaps heavily with the NIS2 risk-management measures and the DORA ICT risk framework, and a mapped control set lets one program serve all three. The value of the certificate in a supply chain is precisely that: a supplier’s ISO 27001 scope and Statement of Applicability tell a buyer which controls are claimed, and a buyer’s own assessment tells it whether to believe them.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.