ISO/IEC 27001 Information Security Management Systems

Confirms that an organisation knows what information it holds, what could go wrong with it, and has chosen and applied controls accordingly.

Accredited by UAF

What this certification proves

ISO/IEC 27001 does not certify that you will not be breached. It certifies that you know what information assets you hold, have assessed what could happen to them, and have chosen controls deliberately rather than by habit.

The document at the centre of it is the Statement of Applicability (SoA) — a line for every control in Annex A, saying whether you apply it, and if not, why not. That «why not» is the point: the standard does not demand every control, it demands that every exclusion is a decision someone made and can defend.

An audit therefore starts with the asset inventory and the SoA. A risk assessment that does not trace back to real assets is the most common finding.

Who this is for

  • IT, software and platform businesses holding customer data
  • Organisations processing client data under contract (SI, cloud, call centres)
  • Organisations asked by customers to complete security due-diligence questionnaires
  • Organisations with intellectual property or design data worth protecting

🌱 How this relates to ESG

S Social

Maps onto the S (Social) pillar. Data security and privacy are classified as social topics by the major ESG frameworks — not governance.

  • GRI 418 (Customer Privacy) — substantiated complaints concerning breaches of customer privacy are reported under Social
  • SASB and MSCI both place «Data Security» and «Customer Privacy» in the Social pillar
  • Korea's K-ESG guideline, S domain «information protection» — asks for an information security system and incident count
  • Customer due diligence — a certificate answers most of a security questionnaire in one document, which is often the immediate commercial reason to certify
  • Extends naturally to 27701 (privacy), 27017 (cloud) and 27018 (PII in cloud)

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 27001Information Security Management SystemsP · 조항 4 · 5 · 6PlanInventory assets,assess risk and…D · 조항 7 · 8DoApply the selectedAnnex A controls and…C · 조항 9CheckMeasure, auditinternally and hold…A · 조항 10ActRemove causes afterincidents and revise…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextIdentify interested parties and legal duties, and set the scope — which systems, sites and services.
5LeadershipTop management sets the information security policy and assigns roles.
6PlanningRisk assessment and treatment, and the Statement of Applicability. The heart of the standard.
7SupportCompetence, awareness, communication and documented information.
8OperationRun the risk treatment plan and the selected controls day to day.
9Performance evaluationMonitor and measure, audit internally, and review.
10ImprovementHandle nonconformities and incidents, and improve continually.
Annex A93 controlsFour themes — organisational, people, physical and technological. You select from these and justify what you exclude.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Is there an information asset inventory — systems, data, devices, suppliers?
  • Is there a risk assessment that traces back to those assets, with owners and treatment decisions?
  • 🔴 Is there a Statement of Applicability, with a reason for every excluded control? Auditors ask for this first
  • Is access management in place — who has what, and is it reviewed when people move or leave?
  • Are logs collected and retained?
  • Are backups taken, and have you actually restored from one?
  • Is there an incident response procedure, and has it been exercised?
  • Are suppliers and cloud services assessed for security?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 27001 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →