Standards & legislation

ISO 27001

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Certifiable, risk-driven and the most widely used anchor for security frameworks worldwide.

ISO 27001 in brief

ISO 27001 describes how an organisation structures information security: from risk assessment and policy to the concrete controls in Annex A. The 2022 revision counts 93 controls, divided over organisational, people, physical and technological measures.

In the Audirium framework library, ISO 27001 is the anchor: the shared control set that other frameworks map onto references ISO 27001. If you already run ISO 27001, you immediately see how much of BIO, NEN 7510 or DORA is covered.

Verified counts

Framework

93 controls

ISO/IEC 27001:2022 — Information security management systems (version 2022).

Library

41 frameworks

This standard does not stand alone: the library counts 1,807 controls and 2,224 cross-references.

Domains in ISO 27001:2022

  • Organizational controls (37) (37)
  • Technological controls (34) (34)
  • Physical controls (14) (14)
  • People controls (8) (8)

Get started with ISO 27001

Request a demo or see how CRAFT supports this standard.

Frequently asked questions

How many controls does ISO 27001:2022 have?

Annex A of ISO 27001:2022 contains 93 controls, divided over four themes: organisational, people, physical and technological. The Audirium framework library includes all 93 and links them to the shared control set that BIO, NEN 7510 and DORA also map onto.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard for the management system (ISMS); ISO 27002 is the accompanying code of practice that details how to implement each control. You certify against 27001 and implement with 27002.

How does Audirium help with ISO 27001?

The CRAFT framework library contains ISO 27001 in full and shows through cross-references how much of other frameworks you already cover with an existing ISMS. Around it, the platform offers the audit app and Risk Heat Map for the audit and assessment cycle.