ISO/IEC 27001 Information Security Management Systems
Confirms that an organisation knows what information it holds, what could go wrong with it, and has chosen and applied controls accordingly.
What this certification proves
ISO/IEC 27001 does not certify that you will not be breached. It certifies that you know what information assets you hold, have assessed what could happen to them, and have chosen controls deliberately rather than by habit.
The document at the centre of it is the Statement of Applicability (SoA) — a line for every control in Annex A, saying whether you apply it, and if not, why not. That «why not» is the point: the standard does not demand every control, it demands that every exclusion is a decision someone made and can defend.
An audit therefore starts with the asset inventory and the SoA. A risk assessment that does not trace back to real assets is the most common finding.
Who this is for
- IT, software and platform businesses holding customer data
- Organisations processing client data under contract (SI, cloud, call centres)
- Organisations asked by customers to complete security due-diligence questionnaires
- Organisations with intellectual property or design data worth protecting
🌱 How this relates to ESG
S SocialMaps onto the S (Social) pillar. Data security and privacy are classified as social topics by the major ESG frameworks — not governance.
- GRI 418 (Customer Privacy) — substantiated complaints concerning breaches of customer privacy are reported under Social
- SASB and MSCI both place «Data Security» and «Customer Privacy» in the Social pillar
- Korea's K-ESG guideline, S domain «information protection» — asks for an information security system and incident count
- Customer due diligence — a certificate answers most of a security questionnaire in one document, which is often the immediate commercial reason to certify
- Extends naturally to 27701 (privacy), 27017 (cloud) and 27018 (PII in cloud)
What certification gives you
- You find out what information you actually hold — most organisations discover assets they had forgottenSee the 8-step process →
- Answers most of a customer security due-diligence questionnaire in one documentRequest audit duration and fees →
- Controls are chosen and justified, not copied from a templateCheck a certified organisation →
- Extends to privacy (27701) and cloud (27017 · 27018) on the same foundationSee ISO/IEC 27701 →
- Recognised worldwide through IAF mutual recognitionSee our accreditations →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| 4 | Context | Identify interested parties and legal duties, and set the scope — which systems, sites and services. |
| 5 | Leadership | Top management sets the information security policy and assigns roles. |
| 6 | Planning | Risk assessment and treatment, and the Statement of Applicability. The heart of the standard. |
| 7 | Support | Competence, awareness, communication and documented information. |
| 8 | Operation | Run the risk treatment plan and the selected controls day to day. |
| 9 | Performance evaluation | Monitor and measure, audit internally, and review. |
| 10 | Improvement | Handle nonconformities and incidents, and improve continually. |
| Annex A | 93 controls | Four themes — organisational, people, physical and technological. You select from these and justify what you exclude. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- Is there an information asset inventory — systems, data, devices, suppliers?
- Is there a risk assessment that traces back to those assets, with owners and treatment decisions?
- 🔴 Is there a Statement of Applicability, with a reason for every excluded control? Auditors ask for this first
- Is access management in place — who has what, and is it reviewed when people move or leave?
- Are logs collected and retained?
- Are backups taken, and have you actually restored from one?
- Is there an incident response procedure, and has it been exercised?
- Are suppliers and cloud services assessed for security?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO/IEC 27001 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →
