ISO / IEC · International

ISO/IEC 27001:2022 Information Security Management compliance software

Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.

Overview

What ISO/IEC 27001 requires

ISO/IEC 27001 is the international standard for an Information Security Management System. The 2022 revision restructured Annex A into four themes — organisational, people, physical and technological — and introduced controls addressing threat intelligence, cloud services, data leakage prevention and secure coding.

Certification requires more than implemented controls. An auditor examines the management system itself: a defined scope, a risk assessment methodology applied consistently, a Statement of Applicability justifying every inclusion and exclusion, evidence of internal audit and management review, and demonstrated continual improvement.

The Statement of Applicability is where most first-time certifications stall. It must account for all Annex A controls with a documented justification for each decision, and it must stay synchronised with the risk register as risks change.

Who it applies to

  • Organisations seeking or maintaining ISO/IEC 27001 certification
  • Suppliers required to demonstrate certification under customer contracts
  • Organisations consolidating several security obligations under one management system
  • Teams transitioning from ISO/IEC 27001:2013 to the 2022 revision

At a glance

  • Current revision: ISO/IEC 27001:2022
  • Annex A themes: Organisational, People, Physical, Technological
  • Core artefact: Statement of Applicability
  • Cycle: Certification audit, surveillance, recertification
In the platform

How GRCLens supports ISO/IEC 27001

ISO/IEC 27001 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Statement of Applicability

Generate and maintain the SoA directly from control decisions, with justification recorded for every inclusion and exclusion.

Risk register and treatment

Link risks to Annex A controls and treatment plans so the SoA and risk assessment stay consistent with each other.

Evidence repository

Attach evidence to individual controls with ownership and review dates, so the audit pack assembles itself.

Multi-framework reuse

Annex A controls are mapped to SOC 2, NCA-ECC, PDPL and other frameworks, so a single control assessment serves several programmes.

Questions

ISO/IEC 27001 frequently asked questions

Does GRCLens issue ISO 27001 certification?

No. Certification can only be issued by an accredited certification body following a formal audit. GRCLens prepares and evidences your management system so that audit goes smoothly, and Security Solution Consultants provides the advisory support alongside it.

Does the platform cover the 2022 revision?

Yes. The Annex A control set reflects ISO/IEC 27001:2022, including the controls introduced in that revision.

Can the Statement of Applicability be exported for auditors?

Yes. The SoA is generated from live control decisions and can be exported for submission to your certification body.

Talk to us about ISO/IEC 27001

Security Solution Consultants provides ISO 27001 gap assessment and certification support alongside the platform, so you can combine tooling with hands-on expertise.

Contact us