ISO 27001

ISO 27001, reusing the work you already did

The international security standard, run from the same control set as your SOC 2. Your AI vCISO handles the ISMS documentation, the Annex A controls, and the evidence.

What is ISO 27001?

ISO 27001 is the leading international standard for information security management. Where SOC 2 results in an attestation report, ISO 27001 results in a certificate issued by an accredited certification body after a formal audit. Outside North America, and increasingly inside it, this certificate is what enterprise buyers ask for.

The standard has two parts. Clauses 4 through 10 define the management system itself: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A is the control catalog. The 2022 revision reorganized it into 93 controls across four themes: organizational, people, physical, and technological.

Certification runs on a three year cycle. An initial two stage audit earns the certificate, followed by annual surveillance audits and a recertification at the end of the cycle. The certification body checks both that your management system works and that the Annex A controls you declared applicable are operating.

Who needs ISO 27001?

Companies selling internationally

European and global enterprises ask for the certificate by name. It is often a hard requirement in procurement, not a nice to have.

Teams that already have SOC 2

Most of the control work overlaps. With cross mapping, the marginal effort to add ISO 27001 drops dramatically.

Regulated and security mature buyers' vendors

Finance, healthcare, and government adjacent buyers treat the certificate as the baseline for vendor trust.

How vCISO.AI gets you to ISO 27001

ISMS documentation, Annex A controls, and evidence, all from one program.

1.

Scope the ISMS

Define what the management system covers. Your onboarding answers seed the context, scope, and risk picture the standard requires.

2.

Risk and the Statement of Applicability

Work through risks and decide which Annex A controls apply. The platform tracks applicability and justification per control.

3.

Operate the controls

Policies, tasks, and evidence flow through the same control set as SOC 2, so work you did there counts here automatically.

4.

Certify and maintain

Walk into the stage 1 and stage 2 audits organized, then keep the program alive for surveillance audits without a scramble.

All 93 Annex A controls covered

The 2022 revision, organized the way the standard organizes it.

A.5

Organizational

37 controls for policies, roles, suppliers, and incidents

A.6

People

8 controls for screening, training, and offboarding

A.7

Physical

14 controls for facilities, equipment, and media

A.8

Technological

34 controls for access, crypto, logging, and development

Cl. 4 to 6

ISMS foundation

Context, leadership, and planning

Cl. 7 to 8

Support and operation

Resources, awareness, and execution

Cl. 9

Evaluation

Monitoring, internal audit, management review

Cl. 10

Improvement

Nonconformity and continual improvement

93

Annex A controls, cross mapped

Implement once, satisfy both. The controls behind your ISO 27001 certificate are the same ones behind your SOC 2 report.

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

ISO 27001 basics

Did not find what you were looking for? Talk to us.

See your gaps for free.

Run the gap analysis, get your roadmap, and know your real timeline before you spend a dollar.