Frameworks
ISO 27001, explained
The international standard for information security management.
ISO/IEC 27001 is the international standard for an information security management system, an ISMS. A growing number of Australian tenders, enterprise contracts and insurers now ask for it by name.
This page covers what the standard actually requires, who tends to need certification, and where ORCA Opti helps you build and hold the evidence behind it.
What ISO 27001 is
ISO/IEC 27001 is a management-system standard, not a checklist of technical settings. Its subject is how your organisation decides what to protect, chooses controls based on risk, and keeps that decision current as things change. The 2022 revision is the version certification bodies now audit against.
The heart of it is a documented risk assessment and a Statement of Applicability: for every control you consider, you record whether it applies, why, and how it is implemented. Annex A lists 93 controls across four themes, organisational, people, physical and technological. You are not required to adopt all 93, but you are required to justify each decision.
Certification is issued by an accredited certification body after a two-stage audit, then maintained through annual surveillance audits on a three-year cycle. The standard itself is copyright ISO and is purchased from ISO or Standards Australia.
Who needs ISO 27001
It is voluntary, but increasingly the price of entry. You are most likely to need it if:
- You sell software or services to enterprise or government buyers who ask for it in procurement and security questionnaires.
- You handle other organisations' data as a processor, and your customers are accountable for your controls.
- You want one recognised framework to anchor a security programme that auditors, insurers and boards already understand.
- You are weighing it against SOC 2. ISO 27001 is the more common ask outside the United States, and the two share a great deal of underlying control work.
Scoping ISO 27001, or answering a tender that asks for it? See it against your own controls on a walkthrough, or start building the evidence today.
What the standard asks for
The clauses that most often decide whether an audit goes smoothly:
A risk-based ISMS
A defined scope, a risk assessment methodology, and a treatment plan that connects each risk to the controls you have chosen. This is the spine of the standard.
Statement of Applicability
A living document recording, for all 93 Annex A controls, whether each applies, the justification, and its implementation status. Auditors read this first.
Documented policies and controls
Access control, cryptography, supplier security, incident management and more, written down, owned, and reviewed on a cycle rather than at audit time.
Evidence controls are operating
Not that a control exists on paper, but that it is working now. Configuration, access reviews and monitoring results, captured with dates against them.
Internal audit and management review
The organisation has to check its own system and have leadership review it, on a schedule, and record what came of it. Continual improvement is part of the standard.
Two minutes, no sign-up
Check your ISO 27001 readiness
Answer a few questions and see where you stand against what an audit assesses. Your score is free and instant. The personalised snapshot is yours by email, no account needed.
1. Management system
3 pointsDo you have a defined scope and a documented information security management system, rather than a set of separate policies?
2. Risk assessment
3 pointsHave you run a documented information security risk assessment, with a treatment plan linking each risk to the controls that address it?
3. Statement of Applicability
2 pointsDo you have a Statement of Applicability recording a justified decision for each of the Annex A controls?
4. Evidence controls operate
3 pointsCould you show an auditor that your key controls are operating now, with dated evidence, rather than only that they exist on paper?
5. Audit and review
2 pointsDo you run internal audits and management reviews on a schedule, with records of what came out of them?
0 of 5 answered
Where ORCA Opti helps
ORCA does not certify you, and no platform can. Certification is issued by an accredited body assessing your organisation. What ORCA does is hold the management system and produce the evidence an auditor asks to see, so the audit is a matter of showing a record rather than assembling one.
Your ISMS as a living system of record: the risk register, the Statement of Applicability, policies with owners and version history, and review cycles that raise their own tasks and escalate when they fall overdue. The management system stops being a folder of documents that goes stale between audits.
Continuous, dated evidence for the technological controls in your Microsoft 365, Azure, AWS and Google Cloud environments, access, multi-factor authentication, administrator counts, configuration drift, checked on a schedule and written back against the control it tests. This is what turns an Annex A control from asserted to evidenced.
Where AI now touches information in scope, AI Guardian inspects each interaction and records it, so the AI your team uses sits inside the ISMS rather than outside it.
What stays yours. Writing your scope, choosing your controls and engaging an accredited certification body stay with you and your assessors. ORCA is where the record of it lives.
Common questions
See where you stand
Book a walkthrough and we will show you ORCA Opti against the framework you are working to, or start free with the Microsoft 365 or Google Workspace account you already have.
Join our mailing list
News and updates from ORCA Opti.