Arama Yap Mesaj Submit
Request a Callback
+90
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro

Contact Us

Location Halkali merkez neighborhood fatih st ozgur apt no 46 , Kucukcekmece , Istanbul , 34303 , TR
ISO/IEC 27001:2022 · ISMS

What Is ISO 27001? ISO/IEC 27001:2022 Certification and Technical Readiness

ISO/IEC 27001 specifies requirements for an information security management system. This guide separates the management-system requirements, certification process and the technical preparation that hosting, SaaS and infrastructure teams usually need.

Official ISO page for ISO IEC 27001 2022 information security management systems
Official-source view · Open source
Important distinction

ISO publishes the standard but does not certify organizations. Certification is performed by independent certification bodies within the relevant conformity-assessment and accreditation arrangements.

TypeInternational management-system standard

Focuses on systematic management of information-security risk.

Current editionISO/IEC 27001:2022

The 2022 edition is the current core reference.

ApplicabilityAny size and sector

Can be applied to technology and non-technology organizations.

OutcomeIndependent certification

A certificate can be issued for the defined scope after a successful audit.

Contents

  1. What exactly is ISO/IEC 27001?
  2. Who can use or certify to ISO 27001?
  3. Is ISO 27001 mandatory?
  4. How does certification usually work?
  5. Which control areas matter in the 2022 structure?
  6. Technical readiness for hosting and SaaS providers
  7. Is it globally recognized?
  8. What drives cost and timeline?
  9. How is ISO 27001 different from SOC 2, PCI DSS, CREST and FedRAMP?
01

What exactly is ISO/IEC 27001?

It defines requirements to establish, implement, maintain and continually improve an ISMS. It is not a checklist of security products; governance, people, processes, technology and suppliers are managed together.

Risk management is central: the organization identifies information, threats, vulnerabilities, risk treatment decisions and evidence that controls operate effectively.

02

Who can use or certify to ISO 27001?

ISO states that organizations of any size and sector can use the standard. The scope can be designed around the real services, locations and supporting processes of the organization.

It is especially common where customers expect formal security assurance, including SaaS, hosting, cloud, finance, healthcare and outsourced service providers.

03

Is ISO 27001 mandatory?

It is not automatically mandatory for every company worldwide. A contract, tender, regulator, customer security policy or supply-chain requirement can nevertheless make it a practical requirement for a particular organization.

Certification should not be confused with legal compliance such as privacy or sector regulation; each obligation needs its own assessment.

04

How does certification usually work?

Typical preparation covers scope, assets, risk assessment, risk treatment, policies, operational evidence, internal audit and management review before the external certification audit.

The auditor evaluates both the design of the management system and whether controls operate in practice. Nonconformities may need remediation before a positive certification decision.

  • Define scope and boundaries
  • Inventory information assets and owners
  • Assess and treat risks
  • Document applicable controls and rationale
  • Generate operational evidence
  • Complete internal audit and management review
  • Proceed to independent certification audit
05

Which control areas matter in the 2022 structure?

The management-system clauses are supported by Annex A control references. Organizational, people, physical and technological controls are considered according to risk and applicability.

Common technical themes include identity and access, privileged accounts, logging, vulnerability management, backup, cryptography, secure development, network security, cloud-service governance and incident response.

06

Technical readiness for hosting and SaaS providers

Auditors need evidence that controls are implemented, not merely written. A documented MFA policy without MFA on administrator access, or logs that nobody reviews, creates a gap between policy and operation.

Asset inventory, joiner-mover-leaver processes, restore tests, central logging, incident records, vulnerability cycles, change control and supplier access should produce repeatable evidence.

07

Is it globally recognized?

ISO/IEC 27001 is an international standard used through certification systems around the world. Organizations in Türkiye and other countries can pursue certification.

Acceptance by a customer can also depend on the certification body, accreditation, scope wording, covered locations and certificate validity.

08

What drives cost and timeline?

There is no universal fixed price. Headcount, locations, scope complexity, IT estate, outsourcing, existing documentation and risk profile affect preparation effort and audit time.

Consulting, certification, staff time, security improvements and surveillance activities should be budgeted separately.

09

How is ISO 27001 different from SOC 2, PCI DSS, CREST and FedRAMP?

ISO 27001 is an organization-wide ISMS standard. SOC 2 is an attestation report about controls at a service organization; PCI DSS protects payment account data; CREST accredits cybersecurity service providers; FedRAMP addresses assurance for cloud services used by US federal agencies.

FrameworkPrimary purposeTypical audience
ISO 27001Information-security management systemAny sector
SOC 2Assurance over service controlsSaaS/B2B technology
PCI DSSPayment-account data securityMerchants/payment ecosystem
CRESTCybersecurity service capabilityPentest/SOC/IR providers
FedRAMPUS federal cloud assuranceCloud/SaaS for federal use

Official and primary sources

ISO/IEC 27001:2022www.iso.orgISO conformity assessmentwww.iso.orgISO/IEC 27000 familywww.iso.org

Frequently asked questions

Does ISO issue ISO 27001 certificates?

No. ISO publishes standards; independent certification bodies perform certification.

Can a small company certify?

Yes. There is no minimum company size in the standard.

Is it only for IT companies?

No. It can apply across sectors.

Does a penetration test equal ISO 27001 certification?

No. A penetration test is one technical activity and does not replace the management system.

Does ISO 27001 automatically mean privacy-law compliance?

No. Legal compliance remains a separate obligation.

Why does certificate scope matter?

Because the certificate applies to the scope and locations stated on it.

EKA Infrastructure & Security

Review your technical readiness before compliance work

We do not claim to be a certification body or independent auditor. We can assist with technical readiness around servers, hosting, access, logging, backups and baseline security controls.

Top