4 Guides
ISO 27001 Compliance Explained
The international information security standard, the certification path, Annex A controls, and how it compares to SOC 2.
ISO 27001 is the international standard for information security, and it is what enterprise buyers in Europe, the UK, and much of the world ask for the way US buyers ask for SOC 2. Where SOC 2 is an attestation report, ISO 27001 is a certification of your information security management system (ISMS).
ISO 27001 Guides
- 1What Is ISO 27001? A Guide to the StandardGuideThe international information-security-management standard, who requires it, and how it differs from a US-centric SOC 2 report.8 min read
- 2The ISO 27001 Certification Process: A Step-by-Step RoadmapGuideThe stages of ISO 27001 certification, from building your ISMS through the Stage 1 and Stage 2 audits and the three-year surveillance cycle.8 min read
- 3ISO 27001 Annex A Controls, Explained (93 Controls, Four Themes)GuideWhat Annex A is, how the 2022 revision reorganized the controls into four themes, and how to approach them without treating the list as a checklist.8 min read
- 4The Statement of Applicability: What It Is and How to Build OneGuideThe document at the center of ISO 27001, what the SoA must contain, and how to write one that holds up in a certification audit.7 min read