Parameter

What is ISO 27001?

ISO/IEC 27001

What ISO 27001 is, how an ISMS and Annex A controls work, the certification process, and where technical testing fits in.

01Introduction

ISO 27001 is the most widely recognized information security certification in the world. For companies selling to European or global enterprises, it's often the ticket to the procurement shortlist.

02What is ISO 27001?

ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and improving an information security management system (ISMS). Organizations are certified by an accredited body after an external audit.

The 2022 revision's Annex A lists 93 controls in four themes (organizational, people, physical and technological), including technical vulnerability management (A.8.8) and security testing in development and acceptance (A.8.29).

03How ISO 27001 works

Certification follows the ISMS lifecycle.

  1. 1.

    Define the ISMS

    Scope, context, leadership commitment and security policy.

  2. 2.

    Assess risk

    Identify risks and select Annex A controls in a Statement of Applicability.

  3. 3.

    Operate and measure

    Run controls, including vulnerability management and testing, then audit internally.

  4. 4.

    Certify and maintain

    Stage 1 and 2 external audits, then annual surveillance audits and recertification every three years.

04Threats and risks

An ISMS can be certified and still be weak.

  • Paper controls

    Documented policies that aren't practiced.

  • Unverified technical controls

    Claiming A.8.8 coverage without evidence that vulnerabilities are found and fixed.

  • Stale risk assessments

    Risk registers that don't reflect the current product and cloud estate.

  • Audit-season scramble

    Evidence gathered in a rush once a year instead of continuously.

05How Parameter helps

Parameter generates technical evidence for ISO 27001 as a byproduct of testing. See ISO 27001 penetration testing.

  • A.8.8 and A.8.29 evidence

    The pentesting agents test and retest, and reports are ready for your auditor.

  • Development testing

    Sentinel reviews every pull request for security flaws.

  • Cloud controls

    Cloud Security shows configuration risk across providers.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your ISO 27001 program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.