An ISO 27001 programme takes its shape from two decisions: which Annex A controls apply to you, and what evidence will show they operate. The 2022 revision reorganised the 93 controls into four themes, and the Statement of Applicability records, control by control, what you selected and why. That document depends on a risk assessment done first, so the wider order is risk register, then control selection, then evidence, then audit. This hub covers the control selection step in depth and ends with how to judge software. The risk register and evidence guides, which serve every framework, sit under Also relevant, alongside how the standard overlaps NIS2.
4 pages on ISO 27001, in the order the work happens. Jump to the stage you are at, or read straight through.
Read the 93 controls as four themes, and record in a Statement of Applicability which ones you selected and why.
Judge platforms on Annex A control depth and on whether evidence collected once also counts for SOC 2.
These sit under another subject but bear directly on ISO 27001.
The free compliance check runs the ISO 27001 gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users