{"id":636,"date":"2026-08-12T07:15:04","date_gmt":"2026-08-12T07:15:04","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=636"},"modified":"2026-08-12T07:15:04","modified_gmt":"2026-08-12T07:15:04","slug":"iso-27001","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/","title":{"rendered":"ISO 27001: Clauses, Annex A and Certification"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: ISO 27001\n     Same design system as the VAPT, MFA and Penetration Testing pages.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">ISO 27001 is the international standard for information security management. It sets out how a company should identify risks to the information it holds, put controls in place, and prove to an independent auditor that the system works.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>ISO 27001 asks an organisation to work out what could go wrong with the information it holds, decide which controls reduce that risk, and show the whole arrangement is reviewed regularly. An independent certification body then audits the organisation and issues the certificate. The current version is ISO\/IEC 27001:2022.<\/p>\n<\/div>\n\n<p>The arrangement the standard describes is called an <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a>, an information security management system. The name is heavier than the idea: it means written rules, a named owner for each one, and records showing the rules are followed. The standard is less interested in which tools you buy than in whether someone is accountable for security and can demonstrate it.<\/p>\n\n<p>Most companies pursue certification because a customer asked for it. It is the security credential enterprise buyers recognise across Europe and Asia, so it usually surfaces during procurement or due diligence.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#contains\">The two parts of ISO 27001<\/a><\/li>\n    <li><a href=\"#documents\">The six documents you must have<\/a><\/li>\n    <li><a href=\"#certification\">How certification actually works<\/a><\/li>\n    <li><a href=\"#soc2\">ISO 27001 or SOC 2?<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports ISO 27001<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"contains\">The two parts of ISO 27001<\/h2>\n\n<p>The standard has two parts, and they carry different weight. Clauses 4 to 10 are compulsory: no organisation is certified without meeting all of them. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> is a list of controls to choose from, selected according to the risks you identified.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 396\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"ISO 27001 structure: mandatory clauses 4 to 10, and Annex A containing 93 controls across four themes.\">\n  <text x=\"18\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#4a52a8\">Clauses 4 to 10<\/text>\n  <text x=\"18\" y=\"46\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">Mandatory. All must be met to certify.<\/text>\n  <rect x=\"8\" y=\"58\" width=\"356\" height=\"322\" rx=\"18\" fill=\"#f4f5fd\"\/>\n\n  <rect x=\"30\" y=\"78\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"101\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">4<\/tspan>  Context of the organisation<\/text>\n  <rect x=\"30\" y=\"120\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"143\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">5<\/tspan>  Leadership<\/text>\n  <rect x=\"30\" y=\"162\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"185\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">6<\/tspan>  Planning and risk assessment<\/text>\n  <rect x=\"30\" y=\"204\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"227\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">7<\/tspan>  Support and competence<\/text>\n  <rect x=\"30\" y=\"246\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"269\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">8<\/tspan>  Operation<\/text>\n  <rect x=\"30\" y=\"288\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"311\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">9<\/tspan>  Performance evaluation<\/text>\n  <rect x=\"30\" y=\"330\" width=\"312\" height=\"36\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"46\" y=\"353\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#3d4590\"><tspan font-weight=\"700\">10<\/tspan>  Improvement<\/text>\n\n  <text x=\"406\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#1c267a\">Annex A<\/text>\n  <text x=\"406\" y=\"46\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">93 controls, selected by risk, in four themes.<\/text>\n  <rect x=\"396\" y=\"58\" width=\"356\" height=\"322\" rx=\"18\" fill=\"#f1f7fb\"\/>\n\n  <rect x=\"418\" y=\"78\" width=\"312\" height=\"118\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"436\" y=\"126\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Organisational<\/text>\n  <text x=\"436\" y=\"148\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#b9c1e6\">Policies, suppliers, incident management<\/text>\n  <text x=\"712\" y=\"130\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"26\" font-weight=\"700\" fill=\"#ffffff\">37<\/text>\n\n  <rect x=\"418\" y=\"204\" width=\"312\" height=\"34\" rx=\"10\" fill=\"#7b9dc9\"\/>\n  <text x=\"436\" y=\"226\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">People<\/text>\n  <text x=\"712\" y=\"228\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"20\" font-weight=\"700\" fill=\"#ffffff\">8<\/text>\n\n  <rect x=\"418\" y=\"246\" width=\"312\" height=\"52\" rx=\"10\" fill=\"#c2d9ec\"\/>\n  <text x=\"436\" y=\"269\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">Physical<\/text>\n  <text x=\"436\" y=\"288\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Facilities, equipment, clear desk<\/text>\n  <text x=\"712\" y=\"278\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"22\" font-weight=\"700\" fill=\"#25547a\">14<\/text>\n\n  <rect x=\"418\" y=\"306\" width=\"312\" height=\"60\" rx=\"10\" fill=\"#dfe3f5\"\/>\n  <text x=\"436\" y=\"331\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3d4590\">Technological<\/text>\n  <text x=\"436\" y=\"350\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Access control, cryptography, logging<\/text>\n  <text x=\"712\" y=\"342\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"22\" font-weight=\"700\" fill=\"#3d4590\">34<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Block height reflects the number of controls in each theme. Organisational controls account for the largest share by some distance.<\/figcaption>\n<\/figure>\n\n<p>A common misunderstanding is that all 93 controls are compulsory. They are not. Controls are selected by risk assessment, and every exclusion is justified in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a>.<\/p>\n\n<div class=\"callout\">\n  <p class=\"k\">Which version applies<\/p>\n  <p>The 2022 edition replaced the 2013 one, reorganising Annex A from 114 controls into 93 and adding 11 new ones, including cloud services security and secure coding. The transition period closed on 31 October 2025, so all certification now runs against the 2022 edition.<\/p>\n<\/div>\n\n<h2 id=\"documents\" class=\"c-apri\">The six documents you must have<\/h2>\n\n<p>An auditor assesses evidence, not intent. These six records are required whatever the size of the organisation.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">ISMS scope<\/p>\n    <p>Which parts of the business, systems and locations are covered.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Information security policy<\/p>\n    <p>The approved statement of objectives, signed off by leadership.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Risk assessment and treatment<\/p>\n    <p>The risks identified and the decision taken on each one.<\/p>\n  <\/div>\n  <div class=\"tcard a\">\n    <p class=\"n\">Statement of Applicability<\/p>\n    <p>Every Annex A control, whether it applies, and why any were excluded.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Internal audit results<\/p>\n    <p>Proof you audited yourself before the certification body arrived.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Management review records<\/p>\n    <p>Minutes showing leadership reviewed performance and acted on it.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"certification\" class=\"c-plum\">How certification actually works<\/h2>\n\n<p>An accredited certification body runs a two-stage audit. The certificate then lasts three years, subject to annual surveillance audits.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 268\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"ISO 27001 certification path: gap analysis, implementation, internal audit, stage 1 audit, stage 2 audit, certificate, then annual surveillance and recertification.\">\n  <defs>\n    <marker id=\"is1\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker>\n    <marker id=\"is2\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#6b4576\"\/><\/marker>\n  <\/defs>\n\n  <text x=\"14\" y=\"24\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">GETTING CERTIFIED<\/text>\n\n  <rect x=\"8\" y=\"38\" width=\"112\" height=\"62\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"64\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Gap analysis<\/text>\n  <text x=\"64\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Current vs required<\/text>\n  <line x1=\"124\" y1=\"69\" x2=\"140\" y2=\"69\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n\n  <rect x=\"148\" y=\"38\" width=\"112\" height=\"62\" rx=\"12\" fill=\"#dfe3f5\"\/>\n  <text x=\"204\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3d4590\">Implement<\/text>\n  <text x=\"204\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Controls and ISMS<\/text>\n  <line x1=\"264\" y1=\"69\" x2=\"280\" y2=\"69\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n\n  <rect x=\"288\" y=\"38\" width=\"112\" height=\"62\" rx=\"12\" fill=\"#c2d9ec\"\/>\n  <text x=\"344\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#25547a\">Internal audit<\/text>\n  <text x=\"344\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Management review<\/text>\n  <line x1=\"404\" y1=\"69\" x2=\"420\" y2=\"69\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n\n  <rect x=\"428\" y=\"38\" width=\"112\" height=\"62\" rx=\"12\" fill=\"#7b9dc9\"\/>\n  <text x=\"484\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Stage 1 audit<\/text>\n  <text x=\"484\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#eaf1f8\">Documentation<\/text>\n  <line x1=\"544\" y1=\"69\" x2=\"560\" y2=\"69\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n\n  <rect x=\"568\" y=\"38\" width=\"112\" height=\"62\" rx=\"12\" fill=\"#1c267a\"\/>\n  <text x=\"624\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Stage 2 audit<\/text>\n  <text x=\"624\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Controls in use<\/text>\n\n  <path d=\"M624,104 L624,124 L380,124 L380,144\" fill=\"none\" stroke=\"#6b4576\" stroke-width=\"2\" marker-end=\"url(#is2)\"\/>\n  <rect x=\"268\" y=\"150\" width=\"224\" height=\"42\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"176\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">Certificate issued, valid 3 years<\/text>\n\n  <text x=\"14\" y=\"222\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">STAYING CERTIFIED<\/text>\n  <rect x=\"148\" y=\"230\" width=\"150\" height=\"32\" rx=\"10\" fill=\"#f0e6f3\"\/>\n  <text x=\"223\" y=\"251\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"600\" fill=\"#6b4576\">Surveillance, year 1<\/text>\n  <line x1=\"302\" y1=\"246\" x2=\"318\" y2=\"246\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n  <rect x=\"326\" y=\"230\" width=\"150\" height=\"32\" rx=\"10\" fill=\"#f0e6f3\"\/>\n  <text x=\"401\" y=\"251\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"600\" fill=\"#6b4576\">Surveillance, year 2<\/text>\n  <line x1=\"480\" y1=\"246\" x2=\"496\" y2=\"246\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#is1)\"\/>\n  <rect x=\"504\" y=\"230\" width=\"150\" height=\"32\" rx=\"10\" fill=\"#dcc6e2\"\/>\n  <text x=\"579\" y=\"251\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"600\" fill=\"#4d2f57\">Recertification, year 3<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Stage 1 examines whether the documentation exists. Stage 2 examines whether the controls are actually operating.<\/figcaption>\n<\/figure>\n\n<h2 id=\"soc2\" class=\"c-sky\">ISO 27001 or SOC 2?<\/h2>\n\n<p>Buyers ask for one or the other. They are different instruments.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th><\/th><th>ISO 27001<\/th><th>SOC 2<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Outcome<\/strong><\/td><td>A certificate against a published standard<\/td><td>An <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-type-1-vs-type-2\/\">attestation report on controls<\/a><\/td><\/tr>\n    <tr><td><strong>Issued by<\/strong><\/td><td>An accredited certification body<\/td><td>A licensed CPA firm<\/td><\/tr>\n    <tr><td><strong>Recognition<\/strong><\/td><td>International, strongest in Europe and Asia<\/td><td>Mainly North America<\/td><\/tr>\n    <tr><td><strong>Cycle<\/strong><\/td><td>Three years, with annual surveillance audits<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-for-startups\/\">Repeated annually<\/a><\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto supports ISO 27001<\/h2>\n\n<p>Osto maps controls across 200+ frameworks, ISO 27001 among them, and collects evidence directly from the modules that implement those controls: access management, logging, endpoint protection, vulnerability testing and cloud posture. Osto prepares you to be audit-ready and supplies the evidence. The audit itself, and the certificate, come from an accredited certification body.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Build the controls, then collect the evidence<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto deploys the security controls ISO 27001 expects and maps the evidence automatically. Tell us your scope and we will tailor a plan.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">200+ frameworks &middot; Evidence from your own controls &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is ISO 27001?<\/summary>\n  <p>ISO\/IEC 27001 is the international standard for an information security management system. It sets out how an organisation identifies information security risks and selects, implements and reviews the controls that address them. Organisations are certified against it by an accredited certification body.<\/p>\n<\/details>\n\n<details>\n  <summary>How many controls does ISO 27001 have?<\/summary>\n  <p>The 2022 edition lists 93 controls in Annex A, arranged in four themes: organisational (37), people (8), physical (14) and technological (34). Not all of them apply to every organisation. Controls are selected on the basis of a risk assessment, and exclusions are justified in the Statement of Applicability.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between ISO 27001 and ISO 27002?<\/summary>\n  <p>ISO 27001 is the certifiable standard, containing the requirements an organisation must meet. ISO 27002 is a guidance document that explains how to implement the Annex A controls in practice. Organisations are certified against 27001; they are not certified against 27002.<\/p>\n<\/details>\n\n<details>\n  <summary>How long does ISO 27001 certification take?<\/summary>\n  <p>It depends on the scope and on how much already exists. The time goes into implementing controls, producing the mandatory documentation, and completing an internal audit and management review before the certification body runs its two-stage audit. Certification bodies also have their own scheduling lead times.<\/p>\n<\/details>\n\n<details>\n  <summary>Is ISO 27001 mandatory?<\/summary>\n  <p>No. Certification is voluntary and no law requires it. In practice it becomes a commercial requirement, since enterprise customers, particularly in Europe and Asia, frequently require it in contracts or vendor due diligence.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> &middot; SOC 2 &middot; ISO 27017 &middot; ISO 27701 &middot; Risk Assessment<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ISO 27001 is the international standard for information security management. It sets out how a company should identify risks to\u2026<\/p>\n","protected":false},"author":8,"featured_media":637,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[],"class_list":["post-636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=636"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/636\/revisions"}],"predecessor-version":[{"id":638,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/636\/revisions\/638"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/637"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}