ISO/IEC 27001:2022 — Information Security Management

The international standard for managing information security risk. The certificate enterprise buyers, banks and government panels ask for by name.

International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). Certification is issued by accredited certification bodies — in Australia, typically accredited by JAS-ANZ.

What it is

ISO/IEC 27001 is the international standard for an Information Security Management System — an ISMS. It is published jointly by the International Organization for Standardization and the International Electrotechnical Commission, and it is the most widely recognised security certification in the world.

Cloud providers and SaaS teams can use ISO/IEC 27017 and 27018 to address cloud security controls and the handling of personal information in public cloud services alongside their ISO 27001 work.

It is worth being clear about what it is not. ISO 27001 is not a technical checklist, and it does not tell you which firewall to buy or how to configure your cloud. It requires something harder: that the organisation identifies its own information security risks, decides deliberately how to treat each one, assigns an owner, and then proves through records that the resulting controls actually operate.

The standard has two parts. Clauses 4 to 10 set the management system requirements — organisational context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 controls across four themes: organisational, people, physical and technological. You select the controls that address your risks and record every inclusion and exclusion, with justification, in a Statement of Applicability.

The current edition is ISO/IEC 27001:2022. Amendment 1:2024 added a requirement to consider whether climate change is relevant to the organisation's context — a small change, but one auditors do ask about.

Certification is granted by an accredited certification body, not by ISO and not by a consultancy. In Australia those bodies are typically accredited by JAS-ANZ. The certificate runs on a three-year cycle: a two-stage initial audit, surveillance audits in years one and two, and full recertification in year three.

Who it's for

Nothing in Australian law requires ISO 27001. In practice the obligation arrives commercially, and it arrives with a deadline attached.

Organisations whose deals stall in security review

This is the most common reason Australian organisations start. A software or services vendor reaches the security assessment stage of an enterprise sale and the process stops for months. The certificate answers most of the questionnaire before it is sent.

When a buyer asks for assurance over a service organisation's controls, SOC 2 readiness may be part of the evidence plan alongside ISO 27001, depending on the customer's requirements.

Suppliers to APRA-regulated entities

Banks, insurers and superannuation funds must manage the risks of their material service providers under APRA's CPS 230 and CPS 234. They discharge that by requiring evidence from suppliers, and ISO 27001 is the evidence most readily accepted.

Government suppliers

ISO 27001 appears as a baseline eligibility requirement on federal and state ICT panels. Its governance requirements also map closely onto the ASD Information Security Manual and the Victorian Protective Data Security Standards, so the work is rarely wasted even where a different framework is the formal obligation.

Organisations holding significant personal information

Under the Notifiable Data Breaches scheme, a breach involving personal information can require notification to the OAIC and to affected individuals. A documented and tested security posture is what makes that survivable.

Choosing the right starting point

The right starting point depends on the commercial need. Where a customer, regulator or tender already requires certification, the programme can be scoped around that deadline. Where the requirement is still emerging, a gap assessment establishes the baseline, identifies the work ahead and gives the organisation a practical route to certification when the timing is right.

Why implement it

  • It unblocks revenue. The certificate converts a months-long security review into a document exchange. For organisations selling upmarket, this is usually the entire business case.
  • It is a gate on procurement. On many government and large corporate tenders, ISO 27001 is an eligibility requirement. Without it the submission is not scored on merit — it is not scored.
  • It satisfies flow-down obligations from clients bound by CPS 230, CPS 234 or the SOCI Act, who must evidence the security of their supply chain.
  • It shortens incidents. The controls the standard insists on — access review, logging, backup, patching, supplier assessment — are the ones that decide whether an incident lasts days or weeks.
  • It makes the next certificate cheap. Clauses 4 to 10 are shared across modern ISO standards under the Annex SL structure. Once the governance layer, risk methodology and audit programme exist, adding ISO 27701 for privacy or ISO 42001 for AI is a fraction of the original effort.

What it does not do is make you secure by itself. A management system built to pass an audit rather than to run the business will pass the audit and then decay. That is a real failure mode and worth naming.

How implementation works

A first-time ISMS usually takes six to nine months. The sequence matters, and most failed or expensive attempts get it out of order.

1. Define the scope

Decide which parts of the organisation, which systems and which locations the ISMS covers. This single decision drives cost, audit duration and how useful the certificate will be to your customers. Scoping too broadly is the most common way to make the programme harder than it needed to be.

2. Agree the risk methodology

Set how risk will be assessed and what level of risk the organisation is prepared to accept, before assessing anything. Auditors examine how ratings were arrived at, not just the ratings themselves.

3. Assess risk and produce the Statement of Applicability

Identify information assets and risks, decide treatments, and derive the SoA from those decisions. The SoA records which of the 93 Annex A controls apply and justifies every inclusion and exclusion. It should follow the risk work, never be written first and back-justified.

4. Build the controls and the evidence trail

Policies and procedures, and the routines that produce records: access reviews, supplier assessments, incident logging, change control, awareness training. A control that produces no record cannot be audited.

5. Operate the system

Two to three months minimum. The auditor tests whether controls work in practice, which requires a history. This is the stage most commonly underestimated, and it cannot be compressed by effort.

6. Internal audit and management review

Both are mandatory (Clauses 9.2 and 9.3) and both must be complete before Stage 2. The internal audit must be impartial — whoever built a control cannot be the person who audits it.

7. Stage 1 and Stage 2 certification audit

Stage 1 reviews documentation and readiness. Stage 2, usually a few weeks later, tests operating effectiveness against evidence. Findings are raised as minor or major nonconformities with a window to respond.

How Soveriq helps

Soveriq builds the management system inside the environment you already run rather than moving your compliance into a third-party subscription platform. The result is a system your team owns and can maintain, and there is no annual licence attached to keeping your certificate.

Engagements are scoped against published price floors, so you know the basis of the number before the conversation starts.

On internal audit. ISO 27001 requires internal audit to be impartial. Where Soveriq has built your management system, we do not then audit it and call that an independent internal audit. What we provide in that situation is readiness validation — useful, honestly labelled, and not a substitute for the impartial audit the standard requires. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build, and the arrangement is disclosed to you in writing. The same position applies to any retainer that includes an audit component.

Clear roles through certification. Soveriq prepares the management system, evidence and organisation for certification. The certificate and final certification decision come from an independent certification body, keeping implementation and certification roles clear. Soveriq supports your team through Stage 1 and Stage 2 without pre-empting that independent decision.

What the engagement looks like

Soveriq works in five modules, and you can take one or all of them. Most ISO 27001 programmes use Module 01 to establish the baseline, Module 02 to build the system, and Module 04 to sit with you through the certification audit.

  • Module 01 — Gap analysis. Clause and control review, current-state report, prioritised roadmap.
  • Module 02 — Build. Scope, risk assessment, Statement of Applicability, policy set and the evidence workflows, constructed inside your own environment.
  • Module 03 — Internal audit. The mandatory Clause 9.2 audit, subject to the impartiality position below.
  • Module 04 — Audit representation. Present with you through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance. Surveillance readiness, register upkeep, management review.

Price floors for every module are published on the pricing page. Certification body fees are separate and paid directly to the certification body — Soveriq does not mark them up or receive any part of them.

Common questions

Is ISO 27001 mandatory in Australia?

No. There is no Australian law requiring ISO 27001. It becomes effectively mandatory through contracts — when a customer, a tender or a prime contractor requires it. That is a commercial obligation rather than a regulatory one, but it is no less binding on the deal.

How long is the certificate valid?

Three years, with surveillance audits in years one and two and a full recertification audit in year three. It is a cycle rather than a one-off event, which is why systems that were built purely to pass tend to fail the first surveillance.

Can we scope it to just one product or team?

Yes, and this is one of the most useful cost levers available. The scope must be defensible and clearly stated on the certificate, and your customer has to accept it — there is no point certifying a scope that excludes the system they actually care about.

Do we need to buy Vanta, Drata or a similar platform?

No. Those platforms can work well, but nothing in the standard requires one. Soveriq builds the management system inside the tools you already own and pay for, which avoids adding a recurring subscription to the cost of compliance.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope