4 Guides

ISO 27001 Compliance Explained

The international information security standard, the certification path, Annex A controls, and how it compares to SOC 2.

ISO 27001 is the international standard for information security, and it is what enterprise buyers in Europe, the UK, and much of the world ask for the way US buyers ask for SOC 2. Where SOC 2 is an attestation report, ISO 27001 is a certification of your information security management system (ISMS).

ISO 27001 Guides

  1. 1What Is ISO 27001? A Guide to the Standard
    Guide
    The international information-security-management standard, who requires it, and how it differs from a US-centric SOC 2 report.
  2. 2The ISO 27001 Certification Process: A Step-by-Step Roadmap
    Guide
    The stages of ISO 27001 certification, from building your ISMS through the Stage 1 and Stage 2 audits and the three-year surveillance cycle.
  3. 3ISO 27001 Annex A Controls, Explained (93 Controls, Four Themes)
    Guide
    What Annex A is, how the 2022 revision reorganized the controls into four themes, and how to approach them without treating the list as a checklist.
  4. 4The Statement of Applicability: What It Is and How to Build One
    Guide
    The document at the center of ISO 27001, what the SoA must contain, and how to write one that holds up in a certification audit.
Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.