What is ISO 27001? A practical guide for SaaS teams
ISO/IEC 27001:2022 is the international requirements standard for an information security management system (ISMS). It gives organisations a risk-based way to establish, operate, review and continually improve how they protect information; certification is performed by an independent certification body.
Who this is for: For teams learning what ISO 27001 requires or preparing their ISMS before formal auditor review.
What ISO 27001 covers
The standard covers the management system around information security: organisational context, leadership, planning, support, operation, performance evaluation and continual improvement. Its goal is to manage risks to the confidentiality, integrity and availability of information.
- ISMS scope and context
- Risk assessment and treatment
- Internal audit and management review
What evidence teams usually prepare
A reviewable ISMS normally includes a defined scope, risk methodology and register, treatment decisions, a Statement of Applicability, approved policies, control evidence, internal-audit records, management-review outputs and corrective actions.
- Risk register and treatment plan
- Statement of Applicability
- Control evidence and review history
How certification works
An independent certification body evaluates whether the ISMS conforms to ISO/IEC 27001. Trustega helps organise preparation records and evidence; it is not a certification body and does not issue certificates.
Where Trustega helps
Trustega connects scope, controls, owners, risks, policies, vendors and evidence so the team can maintain the ISMS as an operating process instead of a paper-only policy folder.
Common questions
What is ISO/IEC 27001 in simple terms?
ISO/IEC 27001 is an international standard that specifies requirements for an information security management system. It helps an organisation identify information risks, choose treatments, operate controls and continually improve the management system.
What is the current version of ISO 27001?
The current full edition is ISO/IEC 27001:2022. Organisations should confirm applicable amendments and transition expectations with their certification body.
Is ISO 27001 a certification?
ISO/IEC 27001 is the requirements standard. An accredited or otherwise qualified independent certification body can audit an organisation's ISMS and issue a certificate within a defined scope.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 contains requirements against which an ISMS can be certified. ISO/IEC 27002 provides implementation guidance for information security controls and is not itself the certification requirements standard.
Does ISO 27001 require an auditor?
Independent certification requires an external certification audit. The management system also includes internal audit and management review activities. Trustega prepares records but does not replace the auditor or certification body.
Primary sources
Related practical guides
- ISO 27001 checklist: scope, risk and evidence — A practical ISO 27001 checklist covering scope, assets, risk assessment, SoA decisions, policies, evidence and audit preparation.
- ISO 27001 risk assessment: make decisions reviewable — A practical ISO 27001 risk assessment guide covering criteria, owners, likelihood, impact, treatment and residual risk.
- Audit preparation checklist: what to review first — A review-week preparation checklist for evidence freshness, owners, policies, vendors, access reviews and audit packs.