ISO 27001, as a living system.
ISO/IEC 27001 asks for an information security management system that keeps working, not a binder that passed once. TruOps keeps the evidence behind it current.
Mappings are typed exact, partial, or inferred, each with a citation.
ISO/IEC 27001 is the international standard for an information security management system (ISMS). The 2022 edition sets management-system requirements in clauses 4 to 10 and lists 93 reference controls in Annex A, grouped into organizational, people, physical, and technological themes. Organizations are certified by an accredited certification body on a three-year cycle with annual surveillance audits.
- Surveillance is coming and the Statement of Applicability does not match how you actually run
- ISO was a certification project; it is not an ISMS yet
- You need ISO for international buyers and already run SOC 2 or NIST
- Published by
- ISO and IEC
- Current edition
- ISO/IEC 27001:2022
- Annex A
- 93 controls in 4 themes
- Certification
- 3-year cycle with surveillance audits
What ISO 27001 requires
The standard has two parts. Clauses 4 to 10 define the management system: context, leadership, planning (including risk assessment and treatment), support, operation, performance evaluation, and improvement. Annex A lists reference controls you select based on your risk assessment and justify in a Statement of Applicability.
| Annex A theme | Controls |
|---|---|
| Organizational | 37 |
| People | 8 |
| Physical | 14 |
| Technological | 34 |
The actual challenge
ISO 27001 is a management system that has to keep working. Most organizations have a binder that passed once and a SoA that was true the week of stage 2.
- Annex A was mapped in a spreadsheet that no longer matches the controls you operate.
- Internal audit and management review are calendar events, not a live view of status.
- A new framework (SOC 2, NIS2, 42001) means rebuilding the same evidence in a different template.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts ISO 27001 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
2013 to 2022
The 2022 revision reorganized the 114 controls of the 2013 edition into 93, merging many and adding new ones such as threat intelligence, cloud services security, data masking, and secure coding. The transition period for certificates issued under ISO/IEC 27001:2013 ended on 31 October 2025.
How TruOps helps with ISO 27001
Pick ISO 27001 as your anchor, or map it to the framework you already run. TruOps keeps ISO 27001's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your ISO 27001 assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
Each Annex A control is its own record with status, owner, and evidence, so your Statement of Applicability reflects reality rather than a spreadsheet.
If this is your situation
Bring your SoA, last audit report, and policy set. TruOps will turn them into a living control set, show honest overlap with SOC 2 and NIST, and list what is still open.
How TruOps helps
- Anchor or map
- Run ISO 27001 as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your ISO 27001 assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
How many controls are in ISO 27001:2022?
Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: organizational (37), people (8), physical (14), and technological (34).
Is ISO 27001 certification mandatory?
No. It is voluntary, but it is widely required by customers and partners, especially outside the United States.
What is a Statement of Applicability?
A document listing which Annex A controls you apply, which you exclude, and why. It is a required ISO 27001 artifact.
Can TruOps map ISO 27001 to SOC 2?
Yes. Run ISO 27001 as your anchor or map it to SOC 2 and others; TruOps shows coverage requirement by requirement, including partial overlaps.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
Related
Do the work once; count it everywhere it honestly applies.
→FrameworksSOC 2AICPA Trust Services Criteria: Type I and Type II readiness.
→FrameworksISO/IEC 42001The certifiable AI management system standard.
→LearnFramework crosswalkMapping one framework's requirements to another's.
→Use casesAudit preparationWalk into fieldwork with dated, cited evidence.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.