ISO 27001: Information Security Management System
Explore ISO 27001, the international standard for information security management systems, and its significance for CISA exam preparation.
ISO/IEC 27001 is the international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). For CISA candidates, understanding ISO 27001 is important because it provides a structured approach to managing information security that is recognized globally.
What Is ISO 27001?
ISO 27001 specifies the requirements for an ISMS within the context of the organization's overall business risks. It adopts a risk-based approach, requiring organizations to identify information security risks and select appropriate controls to treat them. The standard is applicable to organizations of all sizes and sectors.
Key Components of ISO 27001
Context of the Organization
Organizations must understand their internal and external context, identify interested parties and their requirements, and determine the scope of the ISMS. This ensures the ISMS is relevant and appropriately bounded.
Leadership and Commitment
Top management must demonstrate leadership and commitment by establishing an information security policy, ensuring ISMS integration into business processes, and providing adequate resources. Management commitment is essential for ISMS success.
Planning
The planning phase requires organizations to:
- Perform a risk assessment to identify information security risks
- Evaluate the likelihood and impact of identified risks
- Determine risk treatment options (accept, mitigate, transfer, or avoid)
- Select controls from Annex A or other sources to address identified risks
- Produce a Statement of Applicability (SoA) documenting which controls are selected and why
Support
Organizations must ensure adequate resources, competence, awareness, communication, and documented information to support the ISMS.
Operation
This phase covers the implementation and operation of the risk treatment plan and the controls selected during planning.
Performance Evaluation
Organizations must monitor, measure, analyze, and evaluate the ISMS through internal audits, management reviews, and performance metrics.
Improvement
Continual improvement is achieved through corrective actions and ongoing refinement of the ISMS based on audit findings, incidents, and changing risk landscape.
Annex A Controls
ISO 27001:2022 includes 93 controls organized into four themes:
- Organizational controls (37): Policies, roles, asset management, access control, and supplier relationships
- People controls (8): Screening, terms of employment, awareness, and disciplinary processes
- Physical controls (14): Physical security perimeters, equipment security, and clear desk policies
- Technological controls (34): Endpoint security, access rights, cryptography, logging, and network security
Certification Process
Organizations can achieve ISO 27001 certification through a two-stage external audit process:
- Stage 1: Documentation review to assess ISMS readiness
- Stage 2: Implementation audit to verify controls are operating effectively
Certification is valid for three years, with annual surveillance audits.
ISO 27001 and CISA
IS auditors frequently encounter ISO 27001 during compliance and governance audits. Understanding the standard helps auditors evaluate whether an organization's ISMS meets international best practices and regulatory requirements.
CISA Exam Tips
Know the Plan-Do-Check-Act (PDCA) cycle that underpins ISO 27001. Understand the role of the Statement of Applicability and risk assessment in the ISMS. Exam questions may test your knowledge of the certification process and the relationship between ISO 27001 and other frameworks like COBIT.