ISO/IEC 27001:2022 — the certifiable information security management system standard
ISO/IEC 27001 specifies what an information security management system (ISMS) must contain — context, leadership, risk assessment and treatment, controls, monitoring and improvement — and is the standard organisations certify against. For privacy work it is the security foundation most processor contracts, supplier questionnaires and UK GDPR Article 32 conversations end up referring to.
- Published by
- ISO and IEC, through Joint Technical Committee 1, Subcommittee 27 (Information security, cybersecurity and privacy protection).
- Type
- Management system standard; certifiable.
- Versions and language
- Edition 3, published 25 October 2022 (19 pages), English and French. Amendment 1:2024 (“Climate action changes”) is issued free of charge. The 2013 edition and its two corrigenda are withdrawn.
- Jurisdiction
- International.
- Primary audience
- CISOs, security and compliance leads, DPOs, internal and external auditors.
- Topic tags
- information security · ISMS · risk management · certification · UK GDPR Art. 32
- Availability
- Paid (CHF 155 from ISO at the time of verification); a read-only preview is available on the ISO Online Browsing Platform.
Why it matters
Two things about the 2022 edition are worth knowing before it is cited. First, the structure: the 2022 text follows the harmonised ISO management-system structure, and its Annex A controls were reorganised and renumbered in line with ISO/IEC 27002:2022 — so a control reference written against the 2013 edition will not map one-to-one, and a statement of applicability or a supplier questionnaire that still quotes 2013 control numbers needs the correspondence table before it is carried forward. Second, the amendment: ISO lists Amendment 1:2024 as “climate action changes”; it does not alter the controls.
The UK position. UK GDPR Article 32 does not require ISO/IEC 27001, and certification is not treated by the ICO as proof of compliance. It is, however, the reference most UK processor agreements and supplier due-diligence questionnaires reach for when they ask about “appropriate technical and organisational measures”, which makes the edition and scope of a certificate a practical thing to check rather than a formality. The privacy-specific companion is ISO/IEC 27701:2025, which since its 2025 edition can stand alone as a management system standard but is still written to sit alongside an ISMS.
For UK organisations that held BS 10012, note that BSI’s product record now shows that standard as withdrawn; we are confirming the position with BSI before changing its entry on this list.
