Skip to content
← Services

ISO/IEC 27001

ISO/IEC 27001:2022 — Information Security Management Systems

Industry StandardGlobalIn force: October 25, 2022

What it is

ISO/IEC 27001:2022 is the international standard for information security management systems. The 2022 revision restructured Annex A from 114 to 93 controls organised in four themes (organisational, people, physical, technological) and introduced 11 new controls reflecting modern threat realities.

What it requires

Any organisation establishing, implementing, maintaining, and continually improving an ISMS. Certification is voluntary but is increasingly required by enterprise customers, financial institutions, and public-sector procurement. Often used as evidence of NIS 2, DORA, and CRA compliance where overlap exists.

Key facts

Supervisor
Accredited certification bodies under national accreditation authorities (UKAS, DAkkS, Swedac, etc.)

DSI services for ISO/IEC 27001

DSI Advisory Services helps covered entities translate ISO/IEC 27001 obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.

See the service →

Related briefings

Security Doesn't Need Another Framework. It Needs an Operating Model.
Practitioner OperationsJune 21, 2026
Security Doesn't Need Another Framework. It Needs an Operating Model.

On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.

Free tier8 min read
The Wrong Posture
Chokepoint DoctrineJune 9, 2026
The Wrong Posture

Part II of the Governance Gap trilogy. The operational requirement that follows from the strategic finding: every security architecture is built against the threat model that the current architecture was already adequate to detect — which means the threat operating in the governance gap is, by definition, the one your architecture cannot see. The four wrong questions enterprise security is organised to answer (compliance, breach, supply chain, incident response) and the right ones (adversarial view, inference, shared infrastructure, intersection) that the full threat surface framework requires. France Titres, Snowflake, Trellix, the NIS2 / NiS2 chemical-plant scenario — each as evidence the gap is operational, not theoretical.

Free tier8 min read
The Wallet They Are Building Is Not for Your Convenience: Digital Sovereignty, the EUDI Wallet, and the Question Nobody in Brussels Is Answering
Digital IdentityMay 6, 2026
The Wallet They Are Building Is Not for Your Convenience: Digital Sovereignty, the EUDI Wallet, and the Question Nobody in Brussels Is Answering

ENISA has confirmed in writing that no security standard for the EU Digital Identity Wallet is available or foreseen to be available by the deployment deadline. The first generation of wallets will be certified against national schemes of varying robustness, not a unified European standard. The weakest wallet in the EU becomes the entry point for every service provider required to accept it.

Free tier11 min read

Read more on this

Other industry standard frameworks in the DSI registry: