TrustPoint

ISO/IEC 27001:2022

The international standard for an information security management system, and a framework many Gulf organizations run alongside their regulator’s control set.

Publisher
ISO/IEC
Version
2022
Country
International
Availability
Included in the platform

What the standard is

ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system. It is the standard organizations certify against, and the certificate is issued by an accredited certification body rather than by ISO itself.

Two things distinguish it from a control checklist. First, it is a management-system standard: the clauses covering context, leadership, planning, support, operation, performance evaluation and improvement are as auditable as the controls. Second, the control set in Annex A is applied through a risk-driven statement of applicability, so which controls apply to you is an output of your risk assessment rather than a given.

The 2022 revision reorganised the Annex A controls into four themes and introduced controls addressing areas that had grown in importance since the previous edition, including threat intelligence, cloud services and secure development.

What certification actually requires

A certification audit looks for a working system, not a folder of documents. The recurring points of failure are the same across most first attempts: a risk assessment that was done once and never revisited, a statement of applicability that does not match what is actually deployed, internal audits that were scheduled but never followed up to closure, and management review that happened without a record.

The evidential burden is continuous rather than annual. Access reviews, supplier reviews, corrective actions, competence records and improvement actions all need to exist across the period, with dates. An auditor sampling a control will ask for the record from eight months ago, not the one produced last week.

How TrustPoint supports it

ISO/IEC 27001:2022 and ISO/IEC 27002:2022 both ship in the core library. You attach the framework to a perimeter, work the assessment requirement by requirement, and hold the evidence in the managed store where one artefact can serve many requirements.

The risk side is where the integration pays. Applied controls link both to requirements and to risks, so rating a control effective moves the residual score on every risk it mitigates, and letting its review lapse shows up in both places. That is the join a spreadsheet-based ISMS never has.

Internal audit runs in the platform rather than beside it: engagements, scoped assessments, findings raised against the same records everyone else uses, and follow-up tracked to closure. External auditors get their own role, assigned to the folders their engagement covers, so they see the evidence in that scope and nothing beyond it.

Policies are authored with versioning, review cycles and approval routing, and attestations record who read and accepted each published version, which is the evidence the competence and awareness clauses ask for.

Version transitions

When a standard revises, the usual outcome is a reassessment from zero, because the answers live in a spreadsheet keyed to the old control numbers.

Frameworks in TrustPoint are versioned, and a guided upgrade carries existing assessments forward when a new version of a framework is added to the library, showing what was renamed, merged, split, introduced or retired. The library includes the 2022 edition of ISO/IEC 27001, not the 2013 edition, so a programme built on 2013 is assessed directly against 2022.

What it maps to, and what that saves

ISO 27001 is often the common reference other frameworks are compared with. The core library includes the NCA ECC to ISO 27001 mapping set; mapping sets to other frameworks are not yet included.

Because each relationship is recorded (equal, subset, superset, intersecting or related) and suggestions require a person to accept them, the saving survives contact with a certification auditor. A mapping applied silently is a mapping nobody can defend.

Common questions

Does TrustPoint certify us to ISO 27001?

No. Certification is issued by an accredited certification body after an audit. TrustPoint is where you run the management system and hold the evidence that audit will sample.

Is TrustPoint itself ISO 27001 certified?

We do not claim any certification for the product on this site. Ask us directly and we will tell you the current position. What we will describe in detail is the architecture and the controls, on the security page.

Can we manage the statement of applicability here?

Applied controls carry their applicability, effectiveness rating and review schedule, and they link to both the requirements they satisfy and the risks they mitigate. That linkage is what keeps the picture consistent with the risk assessment it is supposed to follow from.

What if our programme is built on the 2013 edition?

The library includes ISO/IEC 27001:2022, not the 2013 edition, so assessments are carried out against 2022 directly. The guided upgrade applies when a newer version of a framework already in the library is added.

Commonly mapped to

See TrustPoint running your ISMS.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.