01Introduction
ISO 27001 is the most widely recognized information security certification in the world. For companies selling to European or global enterprises, it's often the ticket to the procurement shortlist.
02What is ISO 27001?
ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and improving an information security management system (ISMS). Organizations are certified by an accredited body after an external audit.
The 2022 revision's Annex A lists 93 controls in four themes (organizational, people, physical and technological), including technical vulnerability management (A.8.8) and security testing in development and acceptance (A.8.29).
03How ISO 27001 works
Certification follows the ISMS lifecycle.
- 1.
Define the ISMS
Scope, context, leadership commitment and security policy.
- 2.
Assess risk
Identify risks and select Annex A controls in a Statement of Applicability.
- 3.
Operate and measure
Run controls, including vulnerability management and testing, then audit internally.
- 4.
Certify and maintain
Stage 1 and 2 external audits, then annual surveillance audits and recertification every three years.
04Threats and risks
An ISMS can be certified and still be weak.
Paper controls
Documented policies that aren't practiced.
Unverified technical controls
Claiming A.8.8 coverage without evidence that vulnerabilities are found and fixed.
Stale risk assessments
Risk registers that don't reflect the current product and cloud estate.
Audit-season scramble
Evidence gathered in a rush once a year instead of continuously.
05How Parameter helps
Parameter generates technical evidence for ISO 27001 as a byproduct of testing. See ISO 27001 penetration testing.
A.8.8 and A.8.29 evidence
The pentesting agents test and retest, and reports are ready for your auditor.
Development testing
Sentinel reviews every pull request for security flaws.
Cloud controls
Cloud Security shows configuration risk across providers.

