The internationally recognized ISMS standard — operationalized.
ISO/IEC 27001 is two things joined together. Clauses 4 to 10 specify the management system: context, leadership, planning, support, operation, evaluation, improvement — the machinery that is supposed to keep security decisions being made after the project that started them ends. Annex A holds the control set, restructured in the 2022 revision into four themes: organizational, people, physical and technological. You are audited against the clauses. You are sampled against the controls.
Most of the pain lives in the joint between them. The Statement of Applicability declares which Annex A controls apply and why the rest do not, and it is the document that ages fastest — because it describes a control set that keeps changing while the document sits still. Generated from live control state, it is a readout. Maintained by hand, it is a liability with a version number.
Who it applies to
Any organization that wants a certificate, which almost always means someone else asked for one — an enterprise customer, a procurement gate, a regulator who accepts it as evidence of a managed control environment. The standard itself is sector-neutral and scope is yours to define, which is both the flexibility and the trap: a scope drawn narrowly enough to pass is also narrow enough for a customer to notice.
The certification cycle
Certification runs on a rhythm rather than a date. A Stage 1 audit reviews whether the management system is documented and ready; Stage 2 examines whether it actually operates. The certificate that follows runs on a three-year cycle with surveillance audits in between, so the question is never whether you were ready once — it is whether you have stayed ready through two surveillance visits and a recertification. Evidence produced as a by-product of operations survives that rhythm. Evidence assembled for Stage 2 does not survive the first surveillance audit. The certificate itself is issued by an accredited certification body: TruSecure prepares and maintains the evidence, and does not certify anyone.
What it asks, in operating terms
Read as an operating requirement rather than a standard document, 27001 reduces to a handful of standing asks — each answerable from live state, not reconstructed before an audit.
| What the standard asks | Where it is answered |
|---|---|
| Run a management system, not a project | Governance workspace · policy, owners, review dates |
| Assess and treat risk, on a repeating cycle | Risk register · treatment tracked to verified closure |
| Declare which Annex A controls apply, and why not | Statement of Applicability · generated from live control state |
| Show the controls operated, not just existed | Evidence automation · continuous, provenance-tracked |
| Show what changed and who approved it | Audit trail · every change, approval and AI proposal logged |
| Give the auditor what they sample, quickly | Auditor export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an ISMS file is made of:
- Scope
- defined · reviewed with the certification body
- Annex A themes
- organizational · people · physical · technological
- Statement of Applicability
- generated · current as of today
- Open nonconformities
- 1 · owned, closes before surveillance
- Auditor export
- sealed · sha256:c052...7fa3
Where teams usually start
With a demo walked through by TruSecure — the Annex A themes mapped onto controls you already operate, a Statement of Applicability generated in front of you, the export your auditor samples from. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Annex A control evidence does not care where it is stored, but your Statement of Applicability and your supplier controls do. TruSecure holds your evidence with one EEA sub-processor, under EU and UK law. Note that certification is issued by an accredited external body — TruSecure prepares the evidence, it does not certify anyone, and holds no certification of its own yet.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
ISO 27001:2022 is a certifiable standard specifying requirements for an Information Security Management System, with an Annex A control set. TruSecure automates ISMS documentation, control evidence, and Statement of Applicability generation. Certification is issued by an accredited external body.