ISO 27001 and the ISMS
Building a management system.
ISO 27001 and the ISMS is a free Cyber Security Academy lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cyber Security Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
What ISO 27001 Is
ISO/IEC 27001 is the international standard for information security management. Unlike a flexible framework, it is a formal specification you can be certified against by an accredited body.
Its central concept is the ISMS, the Information Security Management System. ISO 27001 is less a list of technical controls and more a system for governing security as an ongoing, managed process.
The ISMS Concept
An ISMS is the set of policies, processes, roles, and controls an organization uses to manage information security risk systematically.
It is a management system, like a quality or environmental management system. The point is not a single audit pass but a living mechanism that:
- Assesses risk continuously.
- Applies and maintains controls.
- Measures effectiveness.
- Improves over time.
The Plan-Do-Check-Act Cycle
The ISMS runs on the PDCA continuous-improvement cycle:
- Plan — establish ISMS scope, policy, risk assessment, and treatment.
- Do — implement the chosen controls and processes.
- Check — monitor, audit, and measure performance.
- Act — correct nonconformities and improve.
This loop is why certification is not a one-time event; auditors expect evidence the cycle is genuinely turning.
Risk Assessment and Treatment
ISO 27001 is fundamentally risk-driven. You identify risks to confidentiality, integrity, and availability, then decide how to treat each one.
The four standard risk treatment options:
# Risk treatment options
# 1. Mitigate - apply a control to reduce the risk
# 2. Transfer - shift it (e.g. insurance, outsourcing)
# 3. Avoid - stop the activity that creates the risk
# 4. Accept - tolerate it (documented, signed off)The Statement of Applicability
A defining ISO 27001 artifact is the Statement of Applicability (SoA). It lists every control from the standard's reference set and records:
- Whether the control is applicable.
- Whether it is implemented.
- Justification for inclusion or exclusion.
The SoA links your risk assessment to your controls and is one of the first documents an auditor examines. Excluding a control is allowed, but you must justify why.
Annex A Controls
ISO 27001 references a catalog of controls in Annex A, detailed in the companion guide ISO 27002. The 2022 revision reorganized them into four themes:
- Organizational controls (policies, supplier management).
- People controls (screening, awareness).
- Physical controls (secure areas, equipment).
- Technological controls (access, cryptography, logging).
You select which apply based on your risk assessment, recorded in the SoA.
Scope and Context
Early in building an ISMS you define its scope: which parts of the organization, systems, and information the ISMS covers.
Scope matters enormously. A narrow scope (one product line) is faster to certify but limited; a broad scope (whole company) is more credible but more work. The certificate states the scope, and customers read it carefully, so scope it honestly to what you can sustain.
Leadership and Documentation
ISO 27001 mandates top-management commitment. Leadership must set the security policy, assign roles, provide resources, and review the ISMS.
It is also documentation-heavy by design: policies, the risk assessment, the SoA, procedures, and records of monitoring. Auditors live by the maxim if it is not documented, it did not happen. Evidence is the currency of certification.
Mandatory Clauses 4-10
Beyond Annex A controls, certification requires meeting the mandatory clauses 4 through 10, which describe the management system itself:
- 4 Context, 5 Leadership, 6 Planning, 7 Support.
- 8 Operation, 9 Performance evaluation, 10 Improvement.
These are not optional. You can tailor Annex A controls, but the management-system clauses must all be satisfied to be certified.
ISO 27001 vs NIST CSF
The two are complementary, not competing:
- ISO 27001 is certifiable, internationally recognized, and emphasizes the management system and governance.
- NIST CSF is voluntary, flexible, and emphasizes practical risk outcomes across functions.
Many organizations use CSF to structure operational capability and ISO 27001 to formalize and certify the program. Their control sets map onto each other extensively.
Internal Audit and Management Review
The ISMS contains two recurring checks that keep the PDCA loop honest:
- Internal audit — periodic, independent review of the ISMS against ISO 27001 and your own policies, to find nonconformities before the certification body does.
- Management review — leadership formally reviews ISMS performance, audit results, incidents, and risk changes, then decides on improvements and resources.
Both are mandatory. They are the mechanisms that prove the management system is alive rather than a static binder.
Quick Check
Test your grasp of a core ISO 27001 artifact.
Recap
ISO 27001 and the ISMS:
- ISO 27001 is a certifiable international standard centered on the ISMS, a managed system for handling information-security risk.
- The ISMS runs on the PDCA cycle (Plan, Do, Check, Act) for continuous improvement.
- It is risk-driven: assess risks, then mitigate, transfer, avoid, or accept each.
- The Statement of Applicability links risks to Annex A controls (organizational, people, physical, technological) with justifications.
- Mandatory clauses 4-10 govern the management system; leadership commitment and documentation are required. ISO 27001 complements NIST CSF.
Frequently asked questions
Is the “ISO 27001 and the ISMS” lesson free?
Yes — the full text of “ISO 27001 and the ISMS” is free to read here on the web, and the Cyber Security Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cyber Security Academy course, upgrade to CoddyKit PRO.
What will I learn in “ISO 27001 and the ISMS”?
Building a management system. You practise Cyber Security Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Cyber Security Academy?
No prior experience is required. Cyber Security Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “ISO 27001 and the ISMS” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Cyber Security Academy lesson?
Yes. Every Cyber Security Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.