Focuses on systematic management of information-security risk.
ISO/IEC 27001 specifies requirements for an information security management system. This guide separates the management-system requirements, certification process and the technical preparation that hosting, SaaS and infrastructure teams usually need.

ISO publishes the standard but does not certify organizations. Certification is performed by independent certification bodies within the relevant conformity-assessment and accreditation arrangements.
Focuses on systematic management of information-security risk.
The 2022 edition is the current core reference.
Can be applied to technology and non-technology organizations.
A certificate can be issued for the defined scope after a successful audit.
It defines requirements to establish, implement, maintain and continually improve an ISMS. It is not a checklist of security products; governance, people, processes, technology and suppliers are managed together.
Risk management is central: the organization identifies information, threats, vulnerabilities, risk treatment decisions and evidence that controls operate effectively.
ISO states that organizations of any size and sector can use the standard. The scope can be designed around the real services, locations and supporting processes of the organization.
It is especially common where customers expect formal security assurance, including SaaS, hosting, cloud, finance, healthcare and outsourced service providers.
It is not automatically mandatory for every company worldwide. A contract, tender, regulator, customer security policy or supply-chain requirement can nevertheless make it a practical requirement for a particular organization.
Certification should not be confused with legal compliance such as privacy or sector regulation; each obligation needs its own assessment.
Typical preparation covers scope, assets, risk assessment, risk treatment, policies, operational evidence, internal audit and management review before the external certification audit.
The auditor evaluates both the design of the management system and whether controls operate in practice. Nonconformities may need remediation before a positive certification decision.
The management-system clauses are supported by Annex A control references. Organizational, people, physical and technological controls are considered according to risk and applicability.
Common technical themes include identity and access, privileged accounts, logging, vulnerability management, backup, cryptography, secure development, network security, cloud-service governance and incident response.
Auditors need evidence that controls are implemented, not merely written. A documented MFA policy without MFA on administrator access, or logs that nobody reviews, creates a gap between policy and operation.
Asset inventory, joiner-mover-leaver processes, restore tests, central logging, incident records, vulnerability cycles, change control and supplier access should produce repeatable evidence.
ISO/IEC 27001 is an international standard used through certification systems around the world. Organizations in Türkiye and other countries can pursue certification.
Acceptance by a customer can also depend on the certification body, accreditation, scope wording, covered locations and certificate validity.
There is no universal fixed price. Headcount, locations, scope complexity, IT estate, outsourcing, existing documentation and risk profile affect preparation effort and audit time.
Consulting, certification, staff time, security improvements and surveillance activities should be budgeted separately.
ISO 27001 is an organization-wide ISMS standard. SOC 2 is an attestation report about controls at a service organization; PCI DSS protects payment account data; CREST accredits cybersecurity service providers; FedRAMP addresses assurance for cloud services used by US federal agencies.
| Framework | Primary purpose | Typical audience |
|---|---|---|
| ISO 27001 | Information-security management system | Any sector |
| SOC 2 | Assurance over service controls | SaaS/B2B technology |
| PCI DSS | Payment-account data security | Merchants/payment ecosystem |
| CREST | Cybersecurity service capability | Pentest/SOC/IR providers |
| FedRAMP | US federal cloud assurance | Cloud/SaaS for federal use |
No. ISO publishes standards; independent certification bodies perform certification.
Yes. There is no minimum company size in the standard.
No. It can apply across sectors.
No. A penetration test is one technical activity and does not replace the management system.
No. Legal compliance remains a separate obligation.
Because the certificate applies to the scope and locations stated on it.
We do not claim to be a certification body or independent auditor. We can assist with technical readiness around servers, hosting, access, logging, backups and baseline security controls.