ISO/IEC 27001:2022 -- Information Security Management
Framework ID: ISO_27001 | Authority: International Organization for Standardization | Version: 2022
When to use
ISO 27001 is the globally recognised baseline for information security management systems (ISMS). Enable this framework if any of the following apply:
- Your organisation pursues ISO 27001 certification or maintains a certified ISMS
- Enterprise procurement requires ISO 27001 alignment from vendors
- You need broad security coverage as a foundation alongside sector-specific frameworks (DORA, NIS2, KRITIS-DE)
Typical profiles: enterprise SaaS, financial services, healthcare, government, technology vendors.
Controls summary
| Property | Value |
|---|---|
| Total controls | 93 |
| Themes | Organisational (A.5, 37), People (A.6, 8), Physical (A.7, 14), Technological (A.8, 34) |
| Assessment scope | app, aud |
| Scoring mode | Binary (compliant / non-compliant) |
| New in 2022 | 11 controls not present in ISO 27001:2013 |
The 14 Physical controls (A.7.x) are flagged csp_inherited: true -- datacentre-level controls that a cloud-hosted application inherits from its provider.
Cross-mapping
| Framework | Relationship |
|---|---|
| BSI IT-Grundschutz 2023 | Bidirectional cross-map via BSI Bausteinen |
| BSI C5 | C5:2020 aligned with ISO 27001 domains |
| GDPR | A.5.34 / A.8.11 / A.8.12 map to GDPR Art. 25/32 |
| SOC 2 | Overlapping Trust Services Criteria (CC6/CC7/CC8) |
| DORA | ICT risk management alignment (financial sector) |
| EUCS | EUCS Substantial/High baseline references ISO 27001 |
How to enable
Add the framework ID to your workspace .swao.yml:
frameworks:
- id: ISO_27001Redistribution note
ISO/IEC 27001:2022 and ISO/IEC 27002:2022 are copyright ISO. Control titles and descriptions in this framework paraphrase the requirement intent and do not reproduce verbatim standard text. The authoritative text is available from ISO and national standards bodies (e.g. BSI, DIN, AFNOR, BSI UK). No warranty is provided.