Skip to main content
FRAMEWORK

The internationally recognized ISMS standard — operationalized.

ISO/IEC 27001 is two things joined together. Clauses 4 to 10 specify the management system: context, leadership, planning, support, operation, evaluation, improvement — the machinery that is supposed to keep security decisions being made after the project that started them ends. Annex A holds the control set, restructured in the 2022 revision into four themes: organizational, people, physical and technological. You are audited against the clauses. You are sampled against the controls.

Most of the pain lives in the joint between them. The Statement of Applicability declares which Annex A controls apply and why the rest do not, and it is the document that ages fastest — because it describes a control set that keeps changing while the document sits still. Generated from live control state, it is a readout. Maintained by hand, it is a liability with a version number.

Who it applies to

Any organization that wants a certificate, which almost always means someone else asked for one — an enterprise customer, a procurement gate, a regulator who accepts it as evidence of a managed control environment. The standard itself is sector-neutral and scope is yours to define, which is both the flexibility and the trap: a scope drawn narrowly enough to pass is also narrow enough for a customer to notice.

The certification cycle

Certification runs on a rhythm rather than a date. A Stage 1 audit reviews whether the management system is documented and ready; Stage 2 examines whether it actually operates. The certificate that follows runs on a three-year cycle with surveillance audits in between, so the question is never whether you were ready once — it is whether you have stayed ready through two surveillance visits and a recertification. Evidence produced as a by-product of operations survives that rhythm. Evidence assembled for Stage 2 does not survive the first surveillance audit. The certificate itself is issued by an accredited certification body: TruSecure prepares and maintains the evidence, and does not certify anyone.

What it asks, in operating terms

Read as an operating requirement rather than a standard document, 27001 reduces to a handful of standing asks — each answerable from live state, not reconstructed before an audit.

ISO 27001 requirements · how TruSecure answers them
What the standard asksWhere it is answered
Run a management system, not a projectGovernance workspace · policy, owners, review dates
Assess and treat risk, on a repeating cycleRisk register · treatment tracked to verified closure
Declare which Annex A controls apply, and why notStatement of Applicability · generated from live control state
Show the controls operated, not just existedEvidence automation · continuous, provenance-tracked
Show what changed and who approved itAudit trail · every change, approval and AI proposal logged
Give the auditor what they sample, quicklyAuditor export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an ISMS file is made of:

ISMS file · excerptSample data
Scope
defined · reviewed with the certification body
Annex A themes
organizational · people · physical · technological
Statement of Applicability
generated · current as of today
Open nonconformities
1 · owned, closes before surveillance
Auditor export
sealed · sha256:c052...7fa3

Where teams usually start

With a demo walked through by TruSecure — the Annex A themes mapped onto controls you already operate, a Statement of Applicability generated in front of you, the export your auditor samples from. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

Sovereignty

Annex A control evidence does not care where it is stored, but your Statement of Applicability and your supplier controls do. TruSecure holds your evidence with one EEA sub-processor, under EU and UK law. Note that certification is issued by an accredited external body — TruSecure prepares the evidence, it does not certify anyone, and holds no certification of its own yet.

See the whole chain

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

ISO 27001:2022 is a certifiable standard specifying requirements for an Information Security Management System, with an Annex A control set. TruSecure automates ISMS documentation, control evidence, and Statement of Applicability generation. Certification is issued by an accredited external body.