Skip to content

ISO/IEC 27001:2022 -- Information Security Management ​

Framework ID: ISO_27001 | Authority: International Organization for Standardization | Version: 2022


When to use ​

ISO 27001 is the globally recognised baseline for information security management systems (ISMS). Enable this framework if any of the following apply:

  • Your organisation pursues ISO 27001 certification or maintains a certified ISMS
  • Enterprise procurement requires ISO 27001 alignment from vendors
  • You need broad security coverage as a foundation alongside sector-specific frameworks (DORA, NIS2, KRITIS-DE)

Typical profiles: enterprise SaaS, financial services, healthcare, government, technology vendors.


Controls summary ​

PropertyValue
Total controls93
ThemesOrganisational (A.5, 37), People (A.6, 8), Physical (A.7, 14), Technological (A.8, 34)
Assessment scopeapp, aud
Scoring modeBinary (compliant / non-compliant)
New in 202211 controls not present in ISO 27001:2013

The 14 Physical controls (A.7.x) are flagged csp_inherited: true -- datacentre-level controls that a cloud-hosted application inherits from its provider.


Cross-mapping ​

FrameworkRelationship
BSI IT-Grundschutz 2023Bidirectional cross-map via BSI Bausteinen
BSI C5C5:2020 aligned with ISO 27001 domains
GDPRA.5.34 / A.8.11 / A.8.12 map to GDPR Art. 25/32
SOC 2Overlapping Trust Services Criteria (CC6/CC7/CC8)
DORAICT risk management alignment (financial sector)
EUCSEUCS Substantial/High baseline references ISO 27001

How to enable ​

Add the framework ID to your workspace .swao.yml:

yaml
frameworks:
  - id: ISO_27001

Redistribution note ​

ISO/IEC 27001:2022 and ISO/IEC 27002:2022 are copyright ISO. Control titles and descriptions in this framework paraphrase the requirement intent and do not reproduce verbatim standard text. The authoritative text is available from ISO and national standards bodies (e.g. BSI, DIN, AFNOR, BSI UK). No warranty is provided.