ISO 27001 · 7 min read · Updated 2026-06-05

What Is ISO 27001? A Plain-English Guide

ISO/IEC 27001 is the world’s leading standard for an Information Security Management System, or ISMS. In plain terms, it is a framework for managing the security of your information through people, processes, and technology.

Certification to ISO 27001 is independent proof that an organisation runs a structured, risk-based approach to protecting data. It is increasingly a requirement to win enterprise and government contracts.

What an ISMS actually is

An ISMS is not a product you install. It is a set of policies, procedures, and controls, backed by management commitment, that together manage information security risk.

ISO 27001 defines what a compliant ISMS must include: leadership, a risk assessment and treatment process, defined objectives, competence and awareness, monitoring, internal audit, and continual improvement.

The structure of the standard

The standard has two parts. Clauses 4 to 10 are the mandatory management-system requirements (context, leadership, planning, support, operation, performance evaluation, improvement).

Annex A is a catalogue of security controls you select from based on your risk assessment. The 2022 version lists 93 controls grouped into four themes: organisational, people, physical, and technological.

Who needs ISO 27001

Any organisation that handles sensitive information can benefit, but it is most common among SaaS and technology companies, managed service providers, and any business selling to large enterprises that demand it in procurement.

It is voluntary, but in practice it often becomes mandatory: large customers frequently will not sign without it.

ISO 27001 vs ISO 27002

ISO 27001 is the certifiable standard. ISO 27002 is a companion guidance document that explains how to implement each Annex A control in detail. You certify against 27001 and use 27002 as the how-to.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate ISO 27001 with Drata

Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.

FAQ

Is ISO 27001 mandatory?
No, it is voluntary, but enterprise and government customers increasingly require it before they will do business with you.
How long is an ISO 27001 certificate valid?
Three years, with annual surveillance audits to confirm you are maintaining the ISMS.
What is the current version?
ISO/IEC 27001:2022. Organisations certified to the older 2013 version had to transition by 31 October 2025.