ISO/IEC 27001:2022 - Information Security Management Systems
ISO/IEC 27001:2022 establishes requirements for an Information Security Management System (ISMS) to manage information risks systematically, protecting confidentiality, integrity, and availability.
Overview
What ISO/IEC 27001:2022 is — and why it matters
ISO/IEC 27001:2022 establishes requirements for an Information Security Management System (ISMS) to manage information risks systematically, protecting confidentiality, integrity, and availability.
It uses a risk-based approach, with Annex A providing 93 controls across 4 themes: organizational, people, physical, technological.
The Standard
What the standard requires
Built on the common ISO “Annex SL” structure, the requirements map to these clauses:
Clause 4
Context – Internal/external issues, interested parties.
Clause 5
Leadership – Policy, roles.
Clause 6
Planning – Risks/opportunities, objectives.
Clause 7
Support – Resources, competence, communication.
Clause 8
Operation – Risk treatment, controls implementation.
Clause 9
Performance – Monitoring, audits, reviews.
Clause 10
Improvement – Nonconformity, continual improvement.
Annex A
Controls selection via Statement of Applicability (SoA).
Getting Ready
What you’ll need to get certified
- Information asset inventory and risk register; SoA justifying control selection/exclusions; evidence of control effectiveness (e.g., access logs, encryption policies).
- Incident management procedures with response times; supplier security agreements; awareness training metrics.
- Internal audits covering ISMS scope; management reviews with risk updates; simulated breach exercises.
The Audit
How ACS-GP certifies your management system
Our audits follow ISO/IEC 17021-1 (requirements for certification bodies) and ISO 19011 (guidelines for auditing management systems).
Compliant with ISO/IEC 17021-1 for ISMS certification and ISO 19011 for cybersecurity audit methods, emphasizing confidentiality.
Process: Stage 1 SoA/risk review; Stage 2 control testing via penetration simulations if applicable; surveillance on threat landscapes.
Auditors certified in CISA/CISM; findings per ISO 19011, with remote options for global teams.
Value Addition Auditing. We assess both efficiency and effectiveness — so your management system becomes a genuine business asset, not just a certificate on the wall — while upholding impartiality, competence and evidence-based findings.
The Payoff
The benefits of certification
What the standard delivers
- Reduces breach risks by 30-50%, minimizing financial losses (average breach cost $4.45M).
- Provides regulatory assurance (e.g., GDPR, HIPAA), building trust with clients and partners.
- Fosters a security-aware culture, improving incident response times by 40%.
- Enables competitive differentiation in digital markets, with certified firms winning 20% more contracts.
Why certify with ACS-GP
- IASCB-backed for universal acceptance, including cloud providers.
- Bundled with ISO 20000 for IT security synergy.
- ACSGP cyber threat intelligence briefings quarterly.
- Gap analysis tools tailored to Annex A updates.
Questions
ISO/IEC 27001:2022 certification — FAQs
Who should get ISO/IEC 27001:2022 certified?
How long does certification take?
How long is the certificate valid?
How much does ISO/IEC 27001:2022 certification cost?
Ready to certify to ISO/IEC 27001:2022?
Talk to ACS-GP about certifying your organisation — or explore the other standards we certify against.