AuditBird

ISO/IEC 27001:2022

ISO 27001 for SaaS Teams

A practical guide to building an information security management system, managing risk, preparing evidence and working toward ISO 27001 certification.

Explore ISO 27001 requirements →

AuditBird is expanding beyond SOC 2 to help small teams manage multiple compliance frameworks without building a large compliance department. ISO 27001 support is coming — Join Early Access for updates.

AuditBird

What are you preparing for?

Select one or more requirements.

✓ SOC 2
✓ ISO 27001
✓ GDPR
HIPAA
PCI DSS
NIST
Other

AuditBird will map your compliance work across your selected requirements.

What is ISO 27001?

ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It is risk-based. Certification is performed by an independent certification body — not AuditBird, not ISO, and not a software product.

ISMS

The management system: scope, roles, risk decisions, policies, operation and improvement.

Controls

Security practices selected through risk treatment — often informed by Annex A.

Documentation & evidence

Written rules plus records that show the system actually operates.

Certification audit

An independent certification body examines the ISMS. AuditBird does not issue certificates.

ISO 27001 is not simply a checklist of security tools. Buying a scanner or writing a generic policy pack does not create an ISMS.

How ISO 27001 works

Implementations differ by scope and risk. The sequence below is a practical orientation for SaaS teams — not a claim that every organization follows identical steps.

01

Define scope

Decide which products, locations, systems and people sit inside the ISMS boundary.

02

Establish the ISMS

Set the management system: policies, roles, objectives and how the work will run.

03

Assess risks

Identify information security risks that matter to the scoped environment.

04

Treat risks

Mitigate, transfer, avoid or accept — with owners and residual risk where applicable.

05

Select controls

Choose relevant controls through risk treatment, not as a blind checklist.

06

Document

Write policies and processes that match how the company actually operates.

07

Operate

Run the controls in day-to-day work: access, incidents, vendors, changes, recovery.

08

Collect evidence

Keep records that show recurring activities actually happened.

09

Internal audit

Check whether the ISMS conforms to requirements and is effectively maintained.

10

Management review

Leadership reviews ISMS performance at planned intervals.

11

Corrective action

Address nonconformities and improve the system.

12

Certification audit

An independent certification body examines Stage 1 and Stage 2.

ISO 27001 requirements

ISO/IEC 27001 contains management system requirements in Clauses 4–10. Annex A provides a reference set of information security controls. Annex A is not a universal checklist where every control must automatically be implemented — applicability follows risk treatment.

Clause 4

Context of the organization

Understand internal/external issues, interested parties and the ISMS scope.

Clause 5

Leadership

Top management commitment, policy and assigned roles and responsibilities.

Clause 6

Planning

Risks, opportunities, information security objectives and planning to achieve them.

Clause 7

Support

Resources, competence, awareness, communication and documented information.

Clause 8

Operation

Operational planning, risk assessment and risk treatment in practice.

Clause 9

Performance evaluation

Monitoring, measurement, internal audit and management review.

Clause 10

Improvement

Continual improvement and corrective action when things go wrong.

Clauses 4–10 contain the certifiable management system requirements. This page paraphrases concepts for education — it does not reproduce copyrighted ISO standard text. Detailed requirements guide — coming soon as a dedicated page.

Annex A controls

ISO/IEC 27001:2022 Annex A lists 93 reference controls in four themes. Organizations consider these controls through risk treatment and document applicability and exclusions in the Statement of Applicability.

Organizational

37 controls

Policies, roles, asset handling, supplier relationships, incident management and more.

People

8 controls

Screening, terms of employment, awareness, disciplinary process and remote working expectations.

Physical

14 controls

Physical security perimeters, entry controls, equipment and environmental protections.

Technological

34 controls

Access control, cryptography, logging, network security, secure development and related controls.

Not every Annex A control automatically applies identically to every organization. ISO 27001 controls guide — coming soon.

Statement of Applicability

The Statement of Applicability (SoA) is a core ISMS document. At a high level it helps record which controls apply, their implementation status, and the justification for inclusion — and for exclusions where relevant.

Connects risk to controls

The SoA shows how risk treatment decisions map onto the Annex A reference set.

Explains exclusions

If a control does not apply, the justification should be clear — not silent.

Not a template stamp

A simplistic SoA that ignores real risk treatment will not hold up in a certification audit.

Living document

As scope, systems and risks change, the SoA should stay aligned.

Statement of Applicability guide — dedicated page coming soon.

Risk assessment

Risk assessment sits at the center of ISO 27001. Methodologies can differ. AuditBird does not dictate a mandatory risk methodology — the important part is a repeatable process your team can operate and explain.

01

Identify what matters

Relevant assets, processes, data flows and scenarios in scope.

02

Assess risk

Threats, vulnerabilities or risk scenarios — with likelihood and impact or an equivalent scale.

03

Assign owners

Someone accountable for each tracked risk.

04

Treat and track

Select controls, record residual risk or acceptance, and revisit on a cadence.

ISO 27001 risk assessment guide — coming soon.

Policies and documentation

ISO 27001 documentation should reflect how the organization actually operates. There is no single mandatory policy pack that every company must adopt verbatim.

Information Security Policy
Access Control
Risk Management
Incident Management
Supplier / Vendor Security
Business Continuity
Change Management
Acceptable Use
Asset Management
HR / security procedures

Documentation should describe real practices, not merely exist for the audit. Many security policy concepts overlap across frameworks, but templates must be adapted to your organization and ISO 27001 ISMS — they are not “ISO 27001-certified templates.” Browse free SOC 2 policy templates as a starting point for overlapping topics, then rewrite them for your ISMS. ISO 27001 policies guide — coming soon.

Evidence

Having a documented process is not the same as demonstrating that it operates. Certification bodies sample records — not intentions.

Access reviews
Security training records
Risk assessments
Risk treatment records
Vendor reviews
Policy approvals
Internal audit records
Management review records
Incident records
Vulnerability / remediation records
Change records
Backup / recovery testing
Corrective actions

Long term, AuditBird is designed to help teams keep evidence, owners and recurring work in one place — across frameworks, not only for a single report.

Internal audit and management review

ISO 27001 expects the organization to evaluate its own ISMS before relying on a certification body. This is a meaningful difference from a simplified “write policies and wait for an auditor” story.

Internal audit

Evaluates whether the ISMS conforms to the organization's requirements and applicable ISO 27001 requirements, and whether it is effectively implemented and maintained.

Management review

Leadership reviews the ISMS at planned intervals — performance, issues, resources and improvement.

Corrective action

Nonconformities are addressed with owners, actions and follow-up — not buried in a slide deck.

What AuditBird is not

AuditBird does not replace a qualified internal auditor, certification body or accredited certification decision.

Internal audit guide — coming soon.

Certification process

Timelines vary. The outline below is a high-level orientation — not a guarantee of duration or outcome.

01

Prepare and operate

Build the ISMS, run controls, collect evidence, fix gaps.

02

Internal audit & management review

Confirm the system is ready before Stage 1.

03

Certification body

Select an independent certification body appropriate for your needs.

04

Stage 1 & Stage 2

Documentation and readiness, then detailed examination of implementation.

05

Findings & decision

Address issues where required; the body issues a certification decision.

06

Surveillance & recertification

Maintain the ISMS through ongoing surveillance and the recertification cycle.

AuditBird does not issue ISO 27001 certificates. Certification guide — coming soon.

ISO 27001 without building an enterprise compliance department

Startups should avoid bureaucracy that does not match how they ship. A proportionate ISMS still needs ownership, evidence and honesty — not a 200-page binder nobody opens.

Realistic scope

One product and one cloud account often beat an impressive multi-entity boundary you cannot operate.

Named owners

Someone coordinates risk, policies, evidence and auditor questions — often a founder or CTO at first.

Repeatable work

Access reviews, training, vendor checks and restore tests that fit the calendar you actually keep.

Evidence from operations

Tickets, exports and logs from real work beat screenshots invented the week before Stage 2.

SOC 2 vs ISO 27001

Neither framework is universally “better.” Many growing SaaS companies eventually need both. Do not rebuild the same compliance program twice.

SOC 2ISO 27001
What it isAttestation / examination and reportCertifiable ISMS standard
Who examinesIndependent CPA firmIndependent certification body
BasisTrust Services CriteriaISO/IEC 27001 requirements + risk-based controls
Common inUS B2B SaaS buyer ecosystemsInternational recognition across markets
OutcomeSOC 2 report (not a certification)ISO 27001 certificate (if successful)

A control such as access review, incident management or vendor review may support requirements across frameworks. Underlying work and evidence can often be reused or mapped where appropriate — without inventing exact overlap percentages. Read more on SOC 2 for small SaaS teams.

One compliance program. Multiple frameworks.

Security work shouldn't restart every time a customer asks for another framework. AuditBird is being built around reusable controls, evidence, policies and ownership so growing teams can expand their compliance program without duplicating the same work.

Control

Periodic access review

Maps conceptually to requirements under SOC 2, ISO 27001 and future frameworks where access governance is expected.

Evidence

Q3 access review export

Can support mapped requirements where appropriate — one artifact, multiple frameworks — when the mapping is designed that way.

Multi-framework support is being developed. SOC 2 currently has the deepest product and resource cluster. ISO 27001 support is coming to AuditBird. See planned pricing — start with one framework, expand as your program grows. Do not assume ISO 27001 is already included in paid plans until product support ships.

ISO 27001 resources

Dedicated guides will land here as the cluster grows. Only live pages are clickable.

ISO 27001 Checklist

Coming soon

A practical preparation list for scope, risk, controls, evidence and certification readiness.

ISO 27001 Controls

Coming soon

How Annex A themes relate to risk treatment and the Statement of Applicability.

Statement of Applicability

Coming soon

What an SoA documents and why exclusions need justification.

ISO 27001 Risk Assessment

Coming soon

A practical view of identifying, treating and tracking information security risks.

ISO 27001 Certification

Coming soon

Stage 1, Stage 2 and what happens after the certificate decision.

ISO 27001 for Startups

Coming soon

How small teams keep the ISMS proportionate without enterprise bureaucracy.

Working on SOC 2 too?

SOC 2 remains a strong acquisition path for many SaaS teams. These free tools are SOC 2-oriented — they are not ISO-specific — but the underlying security work often overlaps.

Questions

ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It is risk-based. Certification is issued by an independent certification body — not by AuditBird.

Build an ISMS without an enterprise GRC department.

Join early access for updates on ISO 27001 support — and for the multi-framework program AuditBird is building around reusable controls and evidence.

Explore SOC 2 resources

SOC 2 · ISO 27001 · GDPR · and more