ISO/IEC 27001 · 2022
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It covers both the management system (clauses 4–10) and the Annex A control set, the framework of choice when you sell globally.
Who needs ISO/IEC 27001?
- Companies selling into Europe and beyond, where ISO 27001 is the common language
- Teams that want a certifiable, audited standard rather than an attestation
- Organizations building a durable security program, not a one-off checklist
How Keel helps with ISO/IEC 27001
- The full ISMS clauses plus the Annex A controls, crosswalked to your other frameworks
- Statement of Applicability and evidence tracking built in
- Readiness scoring across the whole standard so nothing slips before the audit
Collect once, comply everywhere
ISO/IEC 27001 shares its DNA with SOC 2, ISO 27001, and the other frameworks Keel supports. Implement a control once and it counts toward every framework it satisfies, so adding ISO/IEC 27001 rarely means starting from scratch.
Features that help with ISO/IEC 27001: Risk register · Policy management · Vendor risk management · Controls & crosswalk · Evidence management
Other frameworks: CIS Critical Security Controls · PCI DSS · SOC 2 · NIST Cybersecurity Framework · NIST SP 800-53 · HIPAA · All frameworks →