What is ISO/IEC 27001? Core architecture of information security management system

Quick answer

Understand the management scope, information assets, risk assessment, control measures, applicability statement and continuous improvement of ISO/IEC 27001, and establish cross-department information security governance.

Author: StartrustPublished: Updated:

An information security incident does not necessarily start with a hacker. Sending to the wrong recipient, unreclaimed permissions, incorrect cloud settings, supplier interruption, equipment damage, or failure to restore the backup may cause information to be leaked, tampered with, or unusable. The core value of ISO/IEC 27001 is to use risk management to integrate these scattered issues into a sustainable operational information security management system, rather than just purchasing more information security products.

ISO/IEC 27001 manages information, not just IT

ISO/IEC 27001:2022 is the current information security management system requirements standard, applicable to different sizes and industries. It requires organizations to establish, implement, maintain and continuously improve ISMS within their own operational context, and assess and handle information security risks as needed.

Information may exist on servers, in the cloud, on paper, on mobile devices, in email, in conversations or in employee experiences, so the responsibility does not fall solely on the information department. Human Resources masters employee information and the resignation process, business processes customer information, R&D retains designs and source codes, purchases management service providers, and legal identifies contracts and legal requirements. If only the IT organization is involved, many real sources of risk will be missed.

Three basic goals: confidentiality, integrity and availability

Confidentiality means that information can only be accessed by authorized persons; integrity means that information and processing methods remain correct, complete and have not been modified without authorization; availability means that information and related services can be obtained when needed. Companies cannot focus solely on preventing leaks. If order data is tampered with, or key systems are down for several days, it will also have a significant impact.

When assessing risks, you should consider the three objectives at the same time and judge the impact based on the business situation. For example, the confidentiality of public website content may not be high, but integrity and availability are very important; undisclosed merger and acquisition information has extremely high confidentiality requirements.

Step 1: Confirm ISMS scope and governance responsibilities

The enterprise must first explain which organizations, locations, processes, systems and services the ISMS covers, as well as the interfaces with other units and external suppliers. A scope that is too large can create a first-time import burden, and one that is too small can exclude truly critical dependencies. A more pragmatic approach is to center on important services or customer commitments and draw the relationship between information, systems, personnel and suppliers.

Senior managers need to approve policies, objectives, risk acceptance criteria and resources, and review performance regularly. The information security window can coordinate the system, but each information asset and business process should still have clear owners.

Step 2: Inventory of information assets and requirements

Asset inventories do not have to list only hardware numbers. Enterprises should identify the information, software, equipment, services, personnel capabilities and external dependencies that need to be protected from business processes, and record the asset owner, location, classification, retention period and applicable requirements. If the list is complete but it is impossible to see which asset supports which important process, subsequent risk analysis will still be out of focus.

Also sort out customer contracts, regulations, privacy, intellectual property and operational needs. For example, certain data needs to be encrypted, restricted from cross-border transfer, or deleted within a specific period, which will affect the control design.

Step 3: Use a consistent approach to assess and address risks

Risk assessment should identify threats, weaknesses, existing controls, likelihood of occurrence and impact, and then determine the risk level based on enterprise-approved criteria. Rating is not the purpose, the point is to be able to sort out the order of processing and explain the reasons for the judgment. For high-risk projects, enterprises can choose to reduce, avoid, transfer or accept them subject to approval conditions.

The risk treatment plan must specify the measures, responsible persons, deadlines, required resources and verification methods. It is also important to assess the remaining risk after completion, rather than just closing the case once you see the equipment has been purchased.

Step 4: Control Measures and Applicability Statement

ISO/IEC 27001:2022 Appendix A provides a set of reference controls covering organizational, personnel, physical and technical aspects. Companies will decide what controls are needed based on risk, regulatory and contractual requirements, and may also use measures other than those in Appendix A. The applicability statement is used to document necessary controls, rationale for selection, implementation status, and reasons for excluding referenced controls.

This document is not a tick list. If all controls are checked “applicable”, but the risk cannot be connected to the actual process, it will show that the system has not been judged. Controls not only include firewalls and anti-virus, but may also include permission approval, job separation, supplier contracts, incident notifications, backup and restore, physical access control, education and training, and security development.

Step 5: Put information security into daily operations

An effective ISMS will embed controls into personnel to offboarding, system development, change, procurement, outsourcing, backup, incident handling and operations continuity processes. When employees leave, accounts and access control should be recycled according to the list; before using cloud services, data location, access, backup, and incident responsibilities should be evaluated; system changes should retain testing and approval records.

After a security incident occurs, in addition to restoring services, it is also necessary to retain evidence, analyze the causes, evaluate reporting obligations, and track corrective measures. Drills should test actual connections, decision-making and resilience, not just reading procedures.

Step 6: Monitoring, auditing and continuous improvement

Enterprises can track risk treatment progress, vulnerability patching, permission review, incident response, backup and restore testing, supplier deficiencies, and education and training results. Indicators should be able to assist decision-making, rather than just showing “how many classes were held.” For example, the number of days past due for high-risk vulnerabilities is usually more meaningful to manage than the total number of scans.

Internal audits check whether systems are consistent with plans and implemented effectively, while management reviews allow senior managers to assess changes in risks, resources and improvement needs. When organizations introduce AI, move to the cloud, merge and acquire, or launch new services, they should also re-examine the scope and risks.

What practical benefits can be brought after importing?

Traditionally, information security issues were often tracked by different people through emails and spreadsheets, and risks, weaknesses, incidents and audit deficiencies were managed independently. After establishing an ISMS, common criteria can be used to prioritize, allowing managers to see risk acceptance and resource selection; process owners will know clearly what evidence needs to be retained and when to review.

For external clients, validation can provide evidence that a system has been independently assessed, but certificates do not represent zero risk, nor do they replace the client’s own due diligence. The real benefit still lies in the company’s daily ability to detect and deal with risks early.

Common misunderstandings

  • Treat ISO/IEC 27001 as a technical checklist for the information department.
  • Believe that purchasing information security equipment is equivalent to completing risk management.
  • The asset list only lists hardware, ignoring information, services and suppliers.
  • The risk assessment is replicated annually and does not reflect new systems and operational changes.
  • It is believed that no more security incidents will occur after passing the verification.

Which companies are suitable for import?

  • Manage large amounts of customer, employee, financial or R&D information.
  • Provide cloud, software, platform or outsourced information services.
  • When faced with customer information security questionnaires and audits, the answers were inconsistent.
  • Multiple locations or suppliers jointly process important information.
  • Hope to transform fragmented information security measures into a risk-oriented system.

Frequently asked questions when importing ISMS

After using cloud services, will the responsibility for information security be handed over to the supplier?

Cloud service providers will assume some infrastructure and platform control, but users still need to manage accounts, permissions, data classification, settings, backups, connections and contracts. Different service models also have different divisions of responsibilities. Enterprises should confirm the service scope, data location, secondary processors, event notification, termination transfer and deletion mechanisms before purchasing, and incorporate shared responsibilities into risk assessments.

Can the verification scope be limited to the information department?

The scope can be reasonably defined based on the organizational purpose, but important processes and interfaces that support the target service cannot be ignored. If customer information is collected by business, human resources management privileged accounts, and procurement management cloud providers, these activities may affect the ISMS even if they are not in the information department. The scope statement should be truthful and transparent and assess the dependent risks posed by excluded units.

How can information security risk assessment be carried out practically?

Enterprises can start from important services, identify the information, systems, personnel, locations and suppliers that support them, and then consider the scenarios one by one in which information is accessed without authorization, incorrectly modified, lost or interrupted. Existing controls need to be documented during the assessment, otherwise the same risk may receive completely different scores depending on how it is understood by different people. In addition to financial impact, the impact can also include regulations, customers, operations, reputation and personal safety.

Risk criteria should be approved by management, including risk acceptance thresholds and who has the authority to accept them. If a high risk cannot be reduced for the time being, the acceptance decision needs to describe the time limit, alternative control and monitoring methods. Re-evaluation should occur when major changes, events, weaknesses or supplier changes occur and do not have to wait for the annual routine.

How to write the applicability statement in a way that has management value?

At a minimum, the applicability statement should answer: why a certain control is necessary, whether it is currently implemented, where the relevant systems or evidence are, and the reasons why the referenced control is excluded. The selection of controls should link back to risks, regulations and covenants rather than just ticking them all off just to look complete. If the organization uses controls other than those in Appendix A, they must also be included in disposition and tracking.

The implementation status can be distinguished between operational, partially operational and planning, and linked to the person responsible and the deadline. When risks or technical circumstances change, the suitability statement is updated. This document can become a management index if it can be linked to the risk register, policies, procedures, audits and improvements; if it is compiled only before verification, it usually loses accuracy quickly.

How to manage suppliers and cloud services?

Before purchasing, suppliers should be evaluated based on service importance, data sensitivity, system authority, substitutability and concentration. Reviews may include security systems, incident logging, operational continuity, secondary processors, data location, vulnerability management and termination migration. The contract must clearly stipulate access, encryption, backup, event notification, audit rights, data return and deletion.

After the service is launched, performance, verification or reporting effectiveness, and major changes should still be regularly reviewed. If supplier service interruption affects critical operations, companies need to test backup and exit plans and cannot rely solely on contractual compensation. For cloud services, it is also necessary to clearly define the settings and controls that the provider and user are responsible for, to avoid both parties assuming that the other party will handle it.

Security incident management is more than just reporting after an incident

Enterprises must first define incident classification, reporting channels, roles, external contacts, evidence preservation and decision-making rights. When employees discover suspicious emails, account anomalies, or lost equipment, they should be able to report it quickly instead of first judging whether it is serious. Incident handling needs to include detection, analysis, control, elimination, recovery and follow-up review, and the notification time limit must be determined based on personal information, industry or contract requirements.

After the restoration is completed, the technical and institutional reasons should be analyzed to confirm whether similar assets are affected, and then follow up on corrective measures. Exercises can use ransomware, cloud outage, data breach or vendor incident scenarios to test the collaboration between IT, legal, business, PR and management. Merely testing whether the technical team can restore the backup is still not enough to verify the overall resilience.

How to measure ISMS performance so that it is not just about the number of pieces?

Indicators can be selected based on risk and control purposes, such as high-risk vulnerability patching overdue, privileged account review, backup and restore success rate, incident discovery and control time, supplier missing case closure, risk treatment progress, and employee simulation drill improvement. Indicators must have data sources, responsibilities, frequencies, goals and exception handling methods.

A single indicator can lead to misinterpretation. For example, an increase in the number of incidents may indicate an increase in risks or that employees are more willing to report; a decrease in the number of vulnerabilities may indicate a reduction in the scope of the scan. Management reviews should look at trends, scope, causes and residual risk simultaneously and make resource and prioritization decisions, rather than just requiring all numbers to turn green.

Self-check before establishing ISMS

  • Does the scope cover critical services and their people, systems, locations and suppliers?
  • Have risk criteria, acceptance thresholds and approval authorities been confirmed by management?
  • Can information assets be linked to processes, owners, classifications and applicable requirements?
  • Can the controls in the suitability statement be traced back to risks, regulations or covenants?
  • Are the shared responsibilities, events and exit methods of cloud and outsourced services clear?
  • Are backups, incidents and operational continuity tested in real-life situations, rather than just looking at documents?

If your organization currently relies primarily on individual security tools, you can start by mapping out the data flows and dependencies on one important service. This can help teams identify people, processes and third-party risks that are not covered by tools, and then decide on the order of control investments.

After completing the review, an improvement list should be formed based on the level of risk, and management should confirm the priority, resources, and acceptable completion deadlines.

Conclusion

ISO/IEC 27001 does not guarantee that enterprises will never have trouble, but requires enterprises to use a consistent method to understand information, judge risks, select controls, and continuously make corrections. When information security shifts from IT equipment management to cross-departmental governance, the system will have the ability to evolve along with the business and threats.

##Official reference material

Data access date: July 20, 2026.

Related resources

Browse all articles

Related knowledge articles

ICTHow do information and communications companies integrate sustainable disclosure and information security governance?

During every customer questionnaire, annual inventory or audit period, information and communications industry personnel often need to reorganize computer room power consumption, equipment procurement, software and hardware products, cloud resources and supplier information. The real difficulty is usually not filling in the last number, but the scattered information, different calibers, and confirming who provided it, who reviewed it, and why the previous version was modified. In the past, when the information and communications industry dealt with sustainable information disclosure, each unit often collected data on computer room electricity consumption and equipment procurement based on their own forms and understandings.

Management topicHow to conduct information security risk assessment? From information assets to risk management

Describe assets, threats, weaknesses, impacts, possibilities, risk acceptance and disposal plans, provide implementable operating procedures, and organize the company's actual preparation, division of labor and management priorities.

ICTHow does the information and communications supply chain manage ESG and information security risks simultaneously?

During every customer questionnaire, annual inventory or audit period, information and communications industry personnel often need to reorganize computer room power consumption, equipment procurement, software and hardware products, cloud resources and supplier information. The real difficulty is usually not filling in the last number, but the scattered information, different calibers, and confirming who provided it, who reviewed it, and why the previous version was modified. In the past, when the information and communications industry dealt with supply chain and information security, each unit often collected data on computer room power consumption and equipment according to their own forms and understandings.

Related system modules

Sustainability Performance ManagementView system moduleSupplier ManagementView system module