What Is ISO 27001? A Guide to the Standard
The international information-security-management standard, who requires it, and how it differs from a US-centric SOC 2 report.
8 min read
ISO 27001 is the international standard for managing information security. Published by the International Organization for Standardization, it sets out the requirements for an information security management system, or ISMS: the policies, processes, and controls an organization uses to protect its information. Meeting the standard earns a certificate, recognized worldwide, that you run a real security program.
What an ISMS Is
The heart of ISO 27001 is the ISMS, and it is what makes the standard different from a checklist. An ISMS is a management system: you define the scope, assess your risks, choose controls to treat those risks, run them, and improve them over time. The standard cares not just that you have controls, but that you manage them, through leadership involvement, risk assessment, internal audits, and continual improvement.
Who Requires It
ISO 27001 is the more widely recognized standard outside the United States. If you sell into the EU, the UK, or to large global enterprises, it is often the security proof a buyer asks for by name. US-headquartered buyers more often ask for SOC 2, though many enterprises accept or request either. Which one unblocks your deals usually comes down to where your buyers are.
How It Differs From SOC 2
- Certification vs attestation. ISO 27001 is a certification against a fixed standard; SOC 2 is an attestation report describing what an auditor found. What you share is a certificate versus a report.
- A management system, not just controls. ISO 27001 requires a running ISMS with risk assessment and continual improvement. SOC 2 is organized around the Trust Services Criteria.
- Global vs US recognition. ISO 27001 travels internationally; SOC 2 is the US default.
The good news is that the two overlap heavily, so building one does most of the work for the other. For the decision in depth, see SOC 2 vs ISO 27001.
How Concord Fits
Concord Trust treats ISO 27001 as a framework pack mapped onto one control library, alongside SOC 2 and the others. You build and maintain your controls once, adopt the framework, and see coverage against its requirements, so pursuing ISO 27001 after SOC 2 is largely a mapping exercise rather than a second program.