Overview
ISO/IEC 27001 is the international requirements standard for an information security management system, or ISMS. ISO and the IEC publish it through their joint committee ISO/IEC JTC 1/SC 27. The current text is the third edition, published in October 2022, together with Amendment 1 from February 2024, which asks organizations to consider whether climate change is a relevant issue for their ISMS. The 2013 edition is no longer certifiable.
The standard doesn't tell an organization which products to buy. Clauses 4 to 10 require leadership commitment, a defined scope, a repeatable risk assessment, and a plan to treat the risks that it finds, followed by monitoring, internal audit, management review, and correction. Annex A then lists 93 controls. The organization compares its chosen controls with that list and records the result, including justified exclusions, in a Statement of Applicability.
In Canada, certification is voluntary but common in technology supply chains, and federal guidance from the Canadian Centre for Cyber Security names ISO/IEC 27001 as one form of independent assurance a cloud provider can offer. The Standards Council of Canada (SCC) accredits certification bodies for information security management systems against ISO/IEC 17021-1 and ISO/IEC 27006-1. Certificates from SCC-accredited bodies are recognized abroad through the multilateral arrangement once run by the International Accreditation Forum (IAF), which the Global Accreditation Cooperation Incorporated took over on January 1, 2026. Buyers can verify certificates in IAF CertSearch.
Who it applies to in Canada
Any organization, of any size or sector, that wants a managed and auditable way to protect the information it holds or processes. It's most common among software, cloud, managed service, and outsourcing providers.
Canadian suppliers usually pursue ISO 27001 because customers, foreign buyers, and public sector clients ask for a certificate in contracts and security questionnaires. The Standards Council of Canada accredits the certification bodies that issue ISO/IEC 27001 certificates in Canada.
Controls at a glance
Clauses 4 to 10 set the management system requirements, and Annex A lists 93 reference controls in 4 themes drawn from ISO/IEC 27002:2022.
Context of the organization (clause 4)
- Identify internal and external issues that affect security outcomes
- Decide whether climate change is a relevant issue
- Identify interested parties and their security requirements
- Define and document the ISMS scope and boundaries
- Establish, maintain, and keep improving the ISMS
Leadership (clause 5)
- Top management shows commitment and accountability
- Approve an information security policy
- Assign security roles, responsibilities, and authorities
- Build ISMS requirements into business processes
Planning (clause 6)
- Address risks and opportunities for the ISMS
- Define a repeatable information security risk assessment method
- Choose risk treatment options and the controls they need
- Compare controls with Annex A in a Statement of Applicability
- Set measurable security objectives and plans to reach them
- Plan changes to the ISMS in a controlled way
Support (clause 7)
- Provide people, budget, and tools for the ISMS
- Confirm staff are competent for their security roles
- Make staff aware of the policy and their part
- Plan internal and external security communication
- Create, control, and retain documented information
Operation (clause 8)
- Plan and control the processes that deliver security
- Control externally provided processes, products, and services
- Repeat risk assessments at planned intervals and after changes
- Carry out the risk treatment plan
- Keep records of assessment and treatment results
Performance evaluation (clause 9)
- Monitor, measure, and analyze security performance
- Run a planned internal audit program
- Hold management reviews with set inputs and outputs
- Keep evidence of monitoring, audit, and review results
Improvement (clause 10)
- Improve the ISMS on a continuing basis
- Correct nonconformities and deal with their effects
- Find root causes and prevent recurrence
- Check that corrective actions worked
Organizational controls (37)
- Security policies, roles, and segregation of duties
- Threat intelligence and an inventory of information assets
- Access control, identity management, and authentication information
- Supplier and cloud service security
- Incident planning, response, and evidence collection
- ICT readiness for business continuity
- Legal, privacy, and intellectual property requirements
Annex A controls 5.1 to 5.37.
People controls (8)
- Background screening before hiring
- Security terms in employment and a disciplinary process
- Awareness, education, and training
- Duties that continue after termination or role change
- Confidentiality or non-disclosure agreements
- Remote working and reporting of security events
Annex A controls 6.1 to 6.8.
Physical controls (14)
- Physical perimeters and entry controls
- Securing offices, rooms, and facilities
- Physical security monitoring
- Protection against physical and environmental threats
- Clear desk and clear screen rules
- Equipment siting, maintenance, and secure disposal
- Handling of storage media
Annex A controls 7.1 to 7.14.
Technological controls (34)
- Endpoint devices and privileged access rights
- Secure authentication and protection against malware
- Vulnerability and configuration management
- Information deletion, data masking, and leakage prevention
- Backups, redundancy, logging, and monitoring
- Network security, segregation, and web filtering
- Use of cryptography
- Secure development life cycle and secure coding
- Change management and protection of test information
Annex A controls 8.1 to 8.34.
Certification and assessment
A certification body first runs a stage 1 audit of the ISMS design and documents, then a stage 2 audit of how the ISMS works in practice. Once any nonconformities are resolved, it issues a certificate that names the scope and the Annex A version. Accredited certificates can be checked in IAF CertSearch.
Dates to know
- 2022-10-25
- ISO/IEC 27001:2022 published, starting a 3-year transition from the 2013 edition
- 2024-02
- Amendment 1 (climate action changes) published
- 2024-04-30
- Certification bodies may only issue new and renewed certificates to the 2022 edition
- 2025-10-31
- Transition ends; ISO/IEC 27001:2013 certificates expire or are withdrawn
- 2026-01-01
- Global Accreditation Cooperation Incorporated takes over the work of the IAF
In this hub
ISO 27001 Annex A controls explained
How the 93 Annex A controls are organized, what the 11 new controls cover, and how the list is used in an ISMS.
ISO 27001 ISMS requirements, clauses 4 to 10
What each management system clause of ISO/IEC 27001:2022 asks for, and the records auditors expect to see.
ISO 27001 certification process in Canada
How ISO/IEC 27001 certification works, from choosing an accredited certification body to stage 1 and stage 2 audits, surveillance, and renewal.
ISO 27001 transition from 2013 to 2022
The transition to ISO/IEC 27001:2022 closed on October 31, 2025, so certificates to the 2013 edition are no longer valid.
ISO 27001 vs SOC 2
How ISO/IEC 27001 certification and a SOC 2 examination differ in scope, method, output, and audience, and when Canadian organizations need both.
Resources
Official texts and free tools for ISO 27001. Links open the publisher’s site.
- ISO/IEC 27001:2022 Information security management systems, ISO
- Information security management systems accreditation, Standards Council of Canada
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
- IAF CertSearch, International Accreditation Forumtool
- ISO Online Browsing Platform, ISOtool
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- ISO/IEC 27001:2022 Information security management systems, ISO
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
- Information security management systems accreditation, Standards Council of Canada
- Global Accreditation Cooperation Incorporated, Global Accreditation Cooperation Incorporated
- Cloud security risk management (ITSM.50.062), Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.