ISO 27001 Defined in Plain Terms
ISO 27001 is the international standard for an information security management system or ISMS. Published jointly by ISO and the IEC, it sets out how an organisation should assess the risks to its information, choose controls to treat them and keep improving the system over time. The current edition is ISO/IEC 27001:2022.
For most organisations the push to certify comes from outside. Customers ask for it in security questionnaires, public tenders name it as a requirement and regulators expect evidence that security is actively managed. A certificate is a short way to show that an independently audited system stands behind your security claims.
How ISO 27001 Works
ISO 27001 is built around a management system. The idea is that security is an ongoing process you plan, run, check and improve so ISO 27001 asks you to build a repeatable system for it. Clauses 4 to 10 of the standard hold the mandatory requirements for that system.

The clauses run from understanding your context and setting leadership responsibilities through planning and providing resources, to running, measuring and improving the system. Leadership matters most here. Clause 5 requires top management to own the system so ISO 27001 has to be driven from board level and cannot be delegated wholesale to IT.
The engine of the system is risk. You assess the risks to your information, decide how to treat each one and then choose controls to match. Most controls come from Annex A of the standard, a reference set of 93 safeguards.
You do not apply all 93. You apply the controls your risk assessment justifies and record the rest as excluded in the Statement of Applicability with a reason for each decision. That document is what an auditor reads first.
Once the system runs, it does not stop. The standard requires internal audits, a management review and continual improvement so the ISMS keeps pace with new risks and changes in the business. That ongoing cycle is what keeps a certificate meaningful over its three-year life.
The Annex A Controls in Four Themes
Annex A groups its 93 controls into four themes sorted by who or what puts each control into practice. The 2022 revision cut the count from 114 and reorganised the old 14 domains into these four which makes it easier to give each control an owner.
- Organizational (37 controls): Policies, roles, supplier and cloud security, threat intelligence, incident management and business continuity.
- People (8 controls): Screening, terms of employment, security awareness training and the handover when someone joins, moves role or leaves.
- Physical (14 controls): Secure areas, equipment, clear-desk practice and protection against physical and environmental threats.
- Technological (34 controls): Access control, cryptography, secure configuration, monitoring, backup and secure development.
These are a reference set, not a mandate. You pick what your risks call for and justify the rest. The 2022 revision also added 11 new controls that reflect how work has changed among them threat intelligence, information security for cloud services and ICT readiness for business continuity.
The ISO 27000 Family Explained
ISO 27001 sits in a wider family of standards each with a different job. Knowing which is which saves confusion because people often name the wrong one. You certify against ISO 27001 alone. The others support it.
- ISO/IEC 27000: The overview and vocabulary. It defines the terms used across the family and is free to download from ISO.
- ISO/IEC 27001: The requirements for the management system. The only standard in the family you are certified against.
- ISO/IEC 27002: Implementation guidance for the Annex A controls with a page of detail on each. You use it to build controls but you do not certify against it.
- ISO/IEC 27005: Guidance on managing information security risk which supports the risk work at the heart of ISO 27001.
- ISO/IEC 27017 and 27018: Extra controls for cloud services and for protecting personal data in public clouds.
- ISO/IEC 27701: The privacy information management standard. Its 2025 edition became a standalone certifiable standard that maps closely to GDPR. Earlier versions were an extension to ISO 27001.
For a Swedish organisation the two that matter most alongside 27001 are usually 27002 for building the controls and 27701 for privacy.
Real-World Cases
ISO 27001 is easier to grasp through the failures it exists to reduce. Two recent Swedish incidents show the kind of risk its controls address and the honest limit of what any standard can promise.

The Miljödata Supply-Chain Attack
In August 2025 a ransomware attack hit Miljödata, a supplier of HR and sick-leave software used by roughly 80 percent of Sweden’s municipalities. By the supplier’s own estimate the disruption reached around 200 of Sweden’s 290 municipalities and regions. Attackers demanded a ransom of 1.5 bitcoin and data on about 1.5 million people was later published on the dark web.
The damage spread through one shared supplier. That is exactly what Annex A’s supplier and supply-chain controls exist to manage including the duty to assess supplier risk and set security expectations in contracts.
Certification of Miljödata would not have prevented the attack. What the standard changes is the customer’s side. It forces you to ask how much of your operation depends on a single vendor and what happens when that vendor goes dark.
The Tietoevry Ransomware Outage
In January 2024 the Akira ransomware group hit one of Tietoevry’s datacentres in Sweden. The attack took down services for many Swedish customers including the Primula payroll system used by most Swedish universities and more than 30 government authorities along with retail and a regional health-record system. Tietoevry warned that recovery could take days or weeks.
Two ISO 27001 lessons stand out. Akira commonly breaks in through remote-access appliances at organisations without multi-factor authentication, per CISA, which is why access control and strong authentication are core technological controls. And when systems do go down, tested backups and a continuity plan decide whether an outage is an inconvenience or a crisis.
Neither case argues that certification prevents attacks. Both show that a structured, risk-based system changes how badly an attack lands.
ISO 27001 and Swedish Regulation
ISO 27001 is voluntary. No Swedish or EU law requires the certificate itself. What the law increasingly requires is that you manage information security to a demonstrable standard and this is where certification earns its place because it is independent evidence that you do.
Under NIS2, brought into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) in force since 15 January 2026, in-scope organisations must take specific security measures. Article 21 covers risk management, incident handling, business continuity, supply-chain security and staff awareness all of which an ISO 27001 ISMS is built to deliver. Article 20 makes the management body accountable and a certificate gives boards evidence they can point to.
NIS2 also adds duties ISO 27001 does not cover on its own such as strict incident-reporting timelines so certification takes you a long way towards compliance without finishing the job.
For personal data, ISO 27001 supports the security-of-processing duty under GDPR Article 32. The privacy-specific standard is ISO/IEC 27701 whose 2025 edition is a standalone certifiable standard that maps to GDPR requirements. Many organisations run the two together, one for security and one for privacy.
Financial entities have a further regime in DORA which sets ICT risk-management rules that overlap with much of ISO 27001. Whichever rules apply to you, a certified ISMS is a practical way to show an auditor that the measures behind your policies are real. For how these obligations apply to a Swedish organisation, see our ISO 27001 compliance overview.
How ISO 27001 Certification Works
Certification is a defined process, run by an external certification body. Before it starts, most organisations do a gap analysis against the standard, build the missing parts of the ISMS, then run at least one internal audit and a management review so there is evidence the system actually operates.
The audit itself has two stages. Stage 1 is a documentation and readiness review where the auditor checks your scope, policies, risk assessment and Statement of Applicability. Stage 2 is the main audit, where the auditor samples evidence, interviews staff and confirms the controls you selected are working. A clean Stage 1 does not certify you. Only a passed Stage 2 does.
A certificate is then valid for three years. The certification body runs a lighter surveillance audit in each of the first two years, then a fuller recertification audit in the third year that starts the cycle again. Miss the audits and the certificate lapses.
One detail decides whether a certificate means anything. The certification body should itself be accredited by a recognised national accreditation body which in Sweden is Swedac. This whole audit structure is set by ISO/IEC 17021-1, the standard certification bodies work to. An unaccredited certificate can look identical and carry far less weight.
Adoption is wide and growing. The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, up from 48,671 the year before, though the 2024 figures also draw on a broader data source. Since the 2013 version’s transition window closed on 31 October 2025, every valid certificate is now to the 2022 revision.
How to Get Started with ISO 27001
You do not need to solve everything at once. ISO 27001 is designed to be scoped so a first project can be tightly bounded and grown later. A sensible order of first steps looks like this.
- Define the scope: Decide which parts of the business, systems and locations the ISMS will cover and keep it realistic.
- Get leadership behind it: The standard needs top management to own the system, set direction and provide resources.
- Run a gap analysis: Compare what you do today against the standard’s requirements to see the real distance to certification.
- Assess your risks: Identify the risks to your information, then decide how to treat each one.
- Select controls and write the Statement of Applicability: Choose the Annex A controls your risks call for and record what you include and exclude.
- Operate, then audit yourself: Run the system, then complete an internal audit and a management review before inviting an external auditor.
- Choose an accredited certification body: Check it is accredited by Swedac or another recognised body before you book Stage 1.
If the internal skills or time are not there, many organisations bring in outside help such as a CISO advisory service to run the gap analysis and risk assessment.
Done well, ISO 27001 leaves you with more than a certificate. You get a clear picture of your risks, a set of controls that match them and a routine for keeping both current as the business and its threats change.


