Skip to main content
ISO/IEC 27001:2022 is the international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). ISOwl is built to help organisations document and demonstrate conformance with ISO 27001:2022.

What is an ISMS?

An Information Security Management System is a systematic approach to managing sensitive information so that it remains secure. It encompasses people, processes, and technology within a defined scope, and requires:
  • Identifying information security risks
  • Selecting and implementing controls to treat those risks
  • Monitoring and measuring the effectiveness of those controls
  • Continually improving the system based on performance data
An ISMS is not a single product or technology — it is a management framework.

The Plan-Do-Check-Act cycle

ISO 27001 is built around the Plan-Do-Check-Act (PDCA) continual improvement model:
PhaseISO 27001 activitiesISOwl support
PlanDefine scope, conduct risk assessment, select controlsClauses 4–6, Risk Management, Annex A
DoImplement controls, train staff, manage documentationClauses 7–8, Evidence, Asset Management
CheckInternal audits, performance measurement, management reviewClause 9, Audit, Dashboard
ActCorrect nonconformities, drive improvementClause 10, Findings

Standard structure

ISO 27001 consists of ten clauses. Clauses 1–3 are introductory. Clauses 4–10 are normative (mandatory) and contain all the shall requirements. Annex A is a normative reference to ISO 27002.
ClauseTitleNormative
1ScopeNo
2Normative referencesNo
3Terms and definitionsNo
4Context of the organisationYes
5LeadershipYes
6PlanningYes
7SupportYes
8OperationYes
9Performance evaluationYes
10ImprovementYes
Annex AInformation security controls referenceYes

ISOwl feature mapping

Every normative clause and Annex A maps to one or more ISOwl modules:
ClauseNameISOwl feature
4Context of the organisationClauses 4–10 — Clause 4 section
5LeadershipClauses 4–10 — Clause 5 section
6PlanningClauses 4–10 — Clause 6 section + Risk Management
7SupportClauses 4–10 — Clause 7 section + Evidence
8OperationClauses 4–10 — Clause 8 section
9Performance evaluationClauses 4–10 — Clause 9 section + Audit
10ImprovementClauses 4–10 — Clause 10 section + Findings
Annex AControls referenceAnnex A

Clauses 4–10: requirement tracking

ISOwl tracks conformance at the requirement level within each clause. The Clauses catalog defines the full three-level hierarchy (Clause → Subclause → Requirement). Each requirement can be assigned:
  • A conformance status (e.g. Not started, In Progress, Implemented, Not applicable)
  • A maturity level from 0 to 5
  • An owner and last review date
  • Free-text notes
The Executive Dashboard aggregates these states to produce the global compliance percentage shown on the dashboard.

Annex A

Annex A of ISO 27001 contains a normative list of 93 information security controls, organized into four themes. Organisations must reference these controls during their risk treatment process and produce a Statement of Applicability (SoA) that declares which controls are applicable and why. Annex A is a reference to ISO 27002:2022, which provides implementation guidance for each control.

Annex A controls

Evaluate and track all 93 ISO 27002:2022 controls within ISOwl’s Annex A module.

SoA export

Export your Statement of Applicability as a structured document.

Certification

ISO 27001 certification is granted by an accredited certification body (CB) after a two-stage audit:
  1. Stage 1 — Documentation review: the auditor reviews your ISMS documentation to confirm it meets the standard’s requirements.
  2. Stage 2 — Conformance audit: the auditor verifies that your ISMS is operating effectively in practice.
ISOwl does not manage the certification process itself, but it provides the documentation, evidence register, audit records, and findings tracking needed to prepare for both audit stages.
ISO 27001 certification requires an external audit by an accredited body. ISOwl supports your preparation and ongoing conformance — it does not replace the formal certification process.

ISO 27002

The companion implementation guidance standard that defines each of the 93 Annex A controls.

ISO 31000

The risk management standard that underpins ISOwl’s risk assessment methodology.

Clauses catalog

Technical reference for the ISO_27001_CLAUSES data structure.

ISO controls

Technical reference for the ISO_CONTROLS array and domain structure.

Build docs developers (and LLMs) love