Standard
Advanced

ISO 27001 Quick-Start

A beginner-friendly walk of ISO 27001 — the Annex A control domains, the Plan-Do-Check-Act cycle that runs the ISMS, the Statement of Applicability that ties it together, and two real analyst briefs (gap assessment and audit prep) that show the certification clock firing in practice.

Last updated:

Pair this primer with the full course: Full /courses/iso-27001 walk →

The Annex A control domains

  • Organizational controls (A.5) — policies, roles, supplier relationships, and the information security governance the whole ISMS sits on.
  • People controls (A.6) — screening, awareness training, disciplinary process, and the post-offboarding duties that survive a contractor ending.
  • Physical controls (A.7) — perimeter security, equipment siting, clear-desk policy, and the disposal chain for storage media.
  • Technological controls (A.8) — the largest domain: identity and access, cryptography, system hardening, malware protection, backup, logging, and the SDLC.
  • Note: ISO 27001:2022 consolidated the legacy 114 controls across A.5 through A.18 into these four domains; if you are reading a 2013-vintage Annex A, the mapping is documented in Annex A itself.

The Plan-Do-Check-Act cycle

Plan — Establish the ISMS scope, the risk assessment methodology, and the risk treatment plan. The output is a Statement of Applicability (see next section) and a leadership-signed risk appetite. This is the part where the management system is actually defined, on paper, before any control is deployed.

Do — Implement the selected controls and the training and awareness program that keeps them in use. Day-to-day operations run here: access provisioning runs off the A.5/A.8 identity policy, the change ticket closes against the A.8 secure-development guidance, the backup schedule follows the A.8 backup control.

Check — Monitor, measure, and review the ISMS. Internal audits, control-effectiveness reviews, and the management review meeting all live in this phase. This is where the auditor will look first at certification audit: a missing internal-audit log is the most common major nonconformity.

Act — Address nonconformities and drive continual improvement. Corrective actions, treatment-of-risks updates, and the lessons-learned from incidents all get folded back into the Plan phase. ISO 27001 is explicit about this: an ISMS that does not improve over the audit cycle loses certification at surveillance.

The Statement of Applicability

The Statement of Applicability (SoA) is the single document that ties ISO 27001 together. It lists every Annex A control, marks each as applicable or not applicable, states the justification for any exclusion or inclusion, and names the control implementation status for the applicable ones.

An SoA that says "all 93 are applicable and implemented" with no justification is the second most common major nonconformity. The auditor expects each row to defend itself: why this control is in scope, where it is implemented (which document, which system), and how compliance with it is measured.

In practice the SoA is also the onboarding document for new analysts. Once you can locate the A.8.24 (data masking) row and trace it to the production pseudonymization pipeline, you can read every other control the same way. Treat it as the ISMS table of contents.

Two beginner briefs — gap assessment and audit prep

  • WovenCart (D2C apparel on Shopify Plus, PCI scope in marketing tooling, now being asked by a global enterprise customer for an ISO 27001 letter). Open as a gap assessment: walk all 93 Annex A controls, mark each applicable / not applicable with justification, score implementation status, and produce a SoA delta against the certification target. The Concrete artifact is the SoA itself plus a Plan-of-Action list sorted by audit-readiness impact.
  • Atlas Health Partners (regional integrated delivery network, post-merger HITRUST foundation that needs ISO 27001 cert for a cross-border data-processing contract). Open as audit prep: confirm the PDCA rhythm is real (signed internal-audit reports, dated management review minutes, a corrective-action log), rehearse the Stage 1 documentation review with the cert auditor, and walk the Stage 2 site audit on the A.8 technological controls first because that is where findings concentrate.

Next steps

Once you can name which PDCA phase a brief opens first — and which Annex A row the SoA delta is being scored against — you are no longer reading ISO 27001 as a 93-item checklist; you are using it as a management system with a certification clock. The next concrete move is to draft the actual control-language you would feed to a Policy Drafter. The Policy Drafter lab below turns a one-line intent into policy text that maps cleanly onto an Annex A row and justifies the SoA entry alongside it.

When you are ready to read the matching course, the full /courses/iso-27001 walk covers the Section 6 mandatory clauses and the Annex A control text clause by clause. Until then, the laminate for ISO 27001 is: name the Annex A row, name the PDCA phase, name the next concrete artifact.

Next
Next: try the Policy Drafter lab

Turn a one-line control intent into policy text mapped to an Annex A row — the editable draft, the SoA justification, and the evidence list an ISO 27001 cert auditor will ask for.

Open the Policy Drafter lab →