Skip to content

Compliance & frameworks

ISO 27001

ISO/IEC 27001:2022

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS) — a governed, risk-based way to run security that an accredited body can certify. For a cloud-native company, that certificate is often the credential that opens enterprise and international deals where a US-style attestation alone is not the expected proof. The 2022 revision reorganized Annex A into 93 controls across four themes, and a large share of them are squarely about how cloud identity, data, network, logging, and configuration are actually operated.

Who it applies to

ISO 27001 is voluntary — not a law — but it is frequently required by contract. Enterprises, government suppliers, and vendors selling into Europe, the UK, the Middle East, and Asia are often told a current certificate is a condition of doing business. Where US buyers tend to ask for SOC 2, international and enterprise buyers ask for ISO 27001, and many regulated organizations pursue both because the underlying controls overlap.

Cloud control themes

What ISO 27001 asks of your cloud

  • Access control and identity (A.5.15–A.5.18, A.8.2, A.8.5) — least privilege, identity management, authentication, and privileged access
  • Cryptography and data protection (A.8.24, A.8.10, A.8.12) — encryption in transit and at rest, secure deletion, and leakage prevention
  • Logging and monitoring (A.8.15, A.8.16) — event logging, retention, and monitoring of anomalous activity
  • Network security (A.8.20–A.8.23) — network controls, segregation of networks, and boundary protection
  • Configuration and secure operations (A.8.9) — hardened, managed configuration across cloud systems
  • Supplier and cloud service relationships (A.5.19–A.5.23) — governing security across your cloud providers

Domain × framework

Which assessment domains produce ISO 27001 evidence

Assessment domainHow it maps
Identity & accessIAM findings evidence the access-control and identity family — A.5.15–A.5.18 and A.8.2/A.8.5 — covering least privilege, MFA, privileged access, and joiner-mover-leaver deprovisioning.
Data securityEncryption and storage-exposure findings support A.8.24 use of cryptography, plus the data-protection controls A.8.10 information deletion and A.8.12 data leakage prevention.
Network exposureSegmentation and public-endpoint findings evidence A.8.20–A.8.22 network security and segregation of networks.
Logging & monitoringLog coverage, retention, and detection findings map to A.8.15 logging and A.8.16 monitoring activities.
Configuration & postureBaseline-drift findings support A.8.9 configuration management and the expectation of hardened, secure cloud operations.
Framework mappingThe crosswalk ties each cloud finding to specific Annex A controls, feeding the Statement of Applicability your certification body reviews.

What you get

A findings report organized so it drops into your ISO 27001 evidence: each cloud gap tied to the relevant Annex A control, ranked by risk, with a remediation order that supports your Statement of Applicability and stands up under a Stage 2 audit. It is readiness work your engineers and your certification body can both follow — not the certificate itself.

Most relevant to: FinTech, Healthcare, Commercial real estate

Questions

Does the health check certify us to ISO 27001?

No. Certification is issued only by an accredited certification body after a Stage 1 and Stage 2 audit of your ISMS. The health check is readiness work — it finds and prioritizes the cloud-technical gaps in your Annex A controls before the auditor does, so you go in prepared.

ISO 27001 or SOC 2 — which do we need?

They overlap heavily but serve different buyers: SOC 2 is the report US enterprises typically ask for, while ISO 27001 is the internationally recognized certificate. Many organizations pursue both, and the same cloud findings map to each — so one health check supports both efforts.

Do you build our ISMS or write the Statement of Applicability?

No. The ISMS, risk methodology, and Statement of Applicability are management-system work that stays with you. We cover the cloud-technical Annex A controls — identity, data, network, logging, and configuration — and hand you evidence that plugs into them.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check