Our own servers in Europe · GDPR · Support in your language

Learning path

ISO 27001 — Information security

The seven auditable clauses of the information security standard, with risk analysis and the statement of applicability explained clause by clause.

7 modules ~30 min total Content reviewed on

Every clause of ISO 27001, explained

ISO 27001 shares the same high-level structure (Annex SL) as ISO 9001, with a planning clause centered on risk analysis and the statement of applicability of Annex A controls.

This path explains each clause with the asset inventory, incident management and the evidence an information security auditor usually asks for.

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024