Compliance Node Overview
ISO/IEC 27001:2022 (published October 2022, replacing ISO 27001:2013) is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It applies to any organization regardless of size or sector and is administered by ISO/IEC Joint Technical Committee 1, Subcommittee 27. The standard uses the Annex SL high-level structure shared with ISO 9001 and ISO 14001. Annex A contains 93 controls organized into four themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). The 2022 revision added 11 new controls including threat intelligence (A.5.7), ICT readiness for business continuity (A.5.30), web filtering (A.8.23), data masking (A.8.11), data leakage prevention (A.8.12), and secure coding (A.8.28). Certification is achieved through a Stage 1 documentation review and Stage 2 on-site audit by an IAF-accredited certification body, with 3-year recertification and annual surveillance audits. Non-compliance with contractual ISMS requirements can result in contract termination and regulatory liability under GDPR, NIS2, and DORA.
Pillar: Cybersecurity · Authority: ISO (International Organization for Standardization) · Version: 1.1.0 · Last updated:
Primary source: https://www.iso.org/standard/27001
SHA-256 integrity: c3e28e9d21c16a749ff8678760a649e01b1045f3c2bea0ea13a437d18d2f0ff5
Primary Citations — 6 traced to source
- {"jurisdiction":"EU","citation":"General Data Protection Regulation (GDPR) - Article 32: Security of processing","relevance":"Mandates appropriate technical and organizational measures to ensure a level of security appropriate to the risk. ISO 27001 certification is a primary method for demonstrating compliance."}
- {"jurisdiction":"EU","citation":"NIS2 Directive - Article 21: Cybersecurity risk-management measures","relevance":"Requires essential and important entities to adopt risk analysis policies and information system security policies, directly aligning with the core components of an ISO 27001 ISMS."}
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access