ISO/IEC 27001
ISO/IEC 27001:2022 — Information Security Management Systems
What it is
ISO/IEC 27001:2022 is the international standard for information security management systems. The 2022 revision restructured Annex A from 114 to 93 controls organised in four themes (organisational, people, physical, technological) and introduced 11 new controls reflecting modern threat realities.
What it requires
Any organisation establishing, implementing, maintaining, and continually improving an ISMS. Certification is voluntary but is increasingly required by enterprise customers, financial institutions, and public-sector procurement. Often used as evidence of NIS 2, DORA, and CRA compliance where overlap exists.
Key facts
- Supervisor
- Accredited certification bodies under national accreditation authorities (UKAS, DAkkS, Swedac, etc.)
- Official text
- https://www.iso.org/standard/27001
DSI services for ISO/IEC 27001
DSI Advisory Services helps covered entities translate ISO/IEC 27001 obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Related briefings
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
Part II of the Governance Gap trilogy. The operational requirement that follows from the strategic finding: every security architecture is built against the threat model that the current architecture was already adequate to detect — which means the threat operating in the governance gap is, by definition, the one your architecture cannot see. The four wrong questions enterprise security is organised to answer (compliance, breach, supply chain, incident response) and the right ones (adversarial view, inference, shared infrastructure, intersection) that the full threat surface framework requires. France Titres, Snowflake, Trellix, the NIS2 / NiS2 chemical-plant scenario — each as evidence the gap is operational, not theoretical.
ENISA has confirmed in writing that no security standard for the EU Digital Identity Wallet is available or foreseen to be available by the deployment deadline. The first generation of wallets will be certified against national schemes of varying robustness, not a unified European standard. The weakest wallet in the EU becomes the entry point for every service provider required to accept it.
Read more on this
Other industry standard frameworks in the DSI registry: