ISMS
The management system: scope, roles, risk decisions, policies, operation and improvement.
ISO/IEC 27001:2022
A practical guide to building an information security management system, managing risk, preparing evidence and working toward ISO 27001 certification.
AuditBird is expanding beyond SOC 2 to help small teams manage multiple compliance frameworks without building a large compliance department. ISO 27001 support is coming — Join Early Access for updates.
AuditBird
Select one or more requirements.
AuditBird will map your compliance work across your selected requirements.
ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It is risk-based. Certification is performed by an independent certification body — not AuditBird, not ISO, and not a software product.
The management system: scope, roles, risk decisions, policies, operation and improvement.
Security practices selected through risk treatment — often informed by Annex A.
Written rules plus records that show the system actually operates.
An independent certification body examines the ISMS. AuditBird does not issue certificates.
ISO 27001 is not simply a checklist of security tools. Buying a scanner or writing a generic policy pack does not create an ISMS.
Implementations differ by scope and risk. The sequence below is a practical orientation for SaaS teams — not a claim that every organization follows identical steps.
01
Decide which products, locations, systems and people sit inside the ISMS boundary.
02
Set the management system: policies, roles, objectives and how the work will run.
03
Identify information security risks that matter to the scoped environment.
04
Mitigate, transfer, avoid or accept — with owners and residual risk where applicable.
05
Choose relevant controls through risk treatment, not as a blind checklist.
06
Write policies and processes that match how the company actually operates.
07
Run the controls in day-to-day work: access, incidents, vendors, changes, recovery.
08
Keep records that show recurring activities actually happened.
09
Check whether the ISMS conforms to requirements and is effectively maintained.
10
Leadership reviews ISMS performance at planned intervals.
11
Address nonconformities and improve the system.
12
An independent certification body examines Stage 1 and Stage 2.
ISO/IEC 27001 contains management system requirements in Clauses 4–10. Annex A provides a reference set of information security controls. Annex A is not a universal checklist where every control must automatically be implemented — applicability follows risk treatment.
Clause 4
Understand internal/external issues, interested parties and the ISMS scope.
Clause 5
Top management commitment, policy and assigned roles and responsibilities.
Clause 6
Risks, opportunities, information security objectives and planning to achieve them.
Clause 7
Resources, competence, awareness, communication and documented information.
Clause 8
Operational planning, risk assessment and risk treatment in practice.
Clause 9
Monitoring, measurement, internal audit and management review.
Clause 10
Continual improvement and corrective action when things go wrong.
Clauses 4–10 contain the certifiable management system requirements. This page paraphrases concepts for education — it does not reproduce copyrighted ISO standard text. Detailed requirements guide — coming soon as a dedicated page.
ISO/IEC 27001:2022 Annex A lists 93 reference controls in four themes. Organizations consider these controls through risk treatment and document applicability and exclusions in the Statement of Applicability.
37 controls
Policies, roles, asset handling, supplier relationships, incident management and more.
8 controls
Screening, terms of employment, awareness, disciplinary process and remote working expectations.
14 controls
Physical security perimeters, entry controls, equipment and environmental protections.
34 controls
Access control, cryptography, logging, network security, secure development and related controls.
Not every Annex A control automatically applies identically to every organization. ISO 27001 controls guide — coming soon.
The Statement of Applicability (SoA) is a core ISMS document. At a high level it helps record which controls apply, their implementation status, and the justification for inclusion — and for exclusions where relevant.
The SoA shows how risk treatment decisions map onto the Annex A reference set.
If a control does not apply, the justification should be clear — not silent.
A simplistic SoA that ignores real risk treatment will not hold up in a certification audit.
As scope, systems and risks change, the SoA should stay aligned.
Statement of Applicability guide — dedicated page coming soon.
Risk assessment sits at the center of ISO 27001. Methodologies can differ. AuditBird does not dictate a mandatory risk methodology — the important part is a repeatable process your team can operate and explain.
01
Relevant assets, processes, data flows and scenarios in scope.
02
Threats, vulnerabilities or risk scenarios — with likelihood and impact or an equivalent scale.
03
Someone accountable for each tracked risk.
04
Select controls, record residual risk or acceptance, and revisit on a cadence.
ISO 27001 risk assessment guide — coming soon.
ISO 27001 documentation should reflect how the organization actually operates. There is no single mandatory policy pack that every company must adopt verbatim.
Documentation should describe real practices, not merely exist for the audit. Many security policy concepts overlap across frameworks, but templates must be adapted to your organization and ISO 27001 ISMS — they are not “ISO 27001-certified templates.” Browse free SOC 2 policy templates as a starting point for overlapping topics, then rewrite them for your ISMS. ISO 27001 policies guide — coming soon.
Having a documented process is not the same as demonstrating that it operates. Certification bodies sample records — not intentions.
Long term, AuditBird is designed to help teams keep evidence, owners and recurring work in one place — across frameworks, not only for a single report.
ISO 27001 expects the organization to evaluate its own ISMS before relying on a certification body. This is a meaningful difference from a simplified “write policies and wait for an auditor” story.
Evaluates whether the ISMS conforms to the organization's requirements and applicable ISO 27001 requirements, and whether it is effectively implemented and maintained.
Leadership reviews the ISMS at planned intervals — performance, issues, resources and improvement.
Nonconformities are addressed with owners, actions and follow-up — not buried in a slide deck.
AuditBird does not replace a qualified internal auditor, certification body or accredited certification decision.
Internal audit guide — coming soon.
Timelines vary. The outline below is a high-level orientation — not a guarantee of duration or outcome.
01
Build the ISMS, run controls, collect evidence, fix gaps.
02
Confirm the system is ready before Stage 1.
03
Select an independent certification body appropriate for your needs.
04
Documentation and readiness, then detailed examination of implementation.
05
Address issues where required; the body issues a certification decision.
06
Maintain the ISMS through ongoing surveillance and the recertification cycle.
AuditBird does not issue ISO 27001 certificates. Certification guide — coming soon.
Startups should avoid bureaucracy that does not match how they ship. A proportionate ISMS still needs ownership, evidence and honesty — not a 200-page binder nobody opens.
One product and one cloud account often beat an impressive multi-entity boundary you cannot operate.
Someone coordinates risk, policies, evidence and auditor questions — often a founder or CTO at first.
Access reviews, training, vendor checks and restore tests that fit the calendar you actually keep.
Tickets, exports and logs from real work beat screenshots invented the week before Stage 2.
Neither framework is universally “better.” Many growing SaaS companies eventually need both. Do not rebuild the same compliance program twice.
| SOC 2 | ISO 27001 | |
|---|---|---|
| What it is | Attestation / examination and report | Certifiable ISMS standard |
| Who examines | Independent CPA firm | Independent certification body |
| Basis | Trust Services Criteria | ISO/IEC 27001 requirements + risk-based controls |
| Common in | US B2B SaaS buyer ecosystems | International recognition across markets |
| Outcome | SOC 2 report (not a certification) | ISO 27001 certificate (if successful) |
A control such as access review, incident management or vendor review may support requirements across frameworks. Underlying work and evidence can often be reused or mapped where appropriate — without inventing exact overlap percentages. Read more on SOC 2 for small SaaS teams.
Security work shouldn't restart every time a customer asks for another framework. AuditBird is being built around reusable controls, evidence, policies and ownership so growing teams can expand their compliance program without duplicating the same work.
Control
Maps conceptually to requirements under SOC 2, ISO 27001 and future frameworks where access governance is expected.
Evidence
Can support mapped requirements where appropriate — one artifact, multiple frameworks — when the mapping is designed that way.
Multi-framework support is being developed. SOC 2 currently has the deepest product and resource cluster. ISO 27001 support is coming to AuditBird. See planned pricing — start with one framework, expand as your program grows. Do not assume ISO 27001 is already included in paid plans until product support ships.
Dedicated guides will land here as the cluster grows. Only live pages are clickable.
A practical preparation list for scope, risk, controls, evidence and certification readiness.
How Annex A themes relate to risk treatment and the Statement of Applicability.
What an SoA documents and why exclusions need justification.
A practical view of identifying, treating and tracking information security risks.
Stage 1, Stage 2 and what happens after the certificate decision.
How small teams keep the ISMS proportionate without enterprise bureaucracy.
SOC 2 remains a strong acquisition path for many SaaS teams. These free tools are SOC 2-oriented — they are not ISO-specific — but the underlying security work often overlaps.
ISO/IEC 27001 is an international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It is risk-based. Certification is issued by an independent certification body — not by AuditBird.
Join early access for updates on ISO 27001 support — and for the multi-framework program AuditBird is building around reusable controls and evidence.
SOC 2 · ISO 27001 · GDPR · and more