Skip to main content
  1. Index/

ISO/IEC 27001

Table of Contents

ISO/IEC 27001 is the world’s most widely recognized standard for Information Security Management Systems (ISMS). It is published jointly by ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission) — making it a truly international standard, not tied to any single country or jurisdiction. The current version is ISO/IEC 27001:2022, which replaced the 2013 edition and restructured its Annex A controls to align with the updated ISO/IEC 27002:2022 guidance (93 controls organized in 4 themes: Organizational, People, Physical, Technological). The standard specifies requirements (clauses 4–10) for establishing, implementing, maintaining, and continually improving an ISMS — covering context analysis, leadership commitment, risk assessment, treatment planning, operational controls, performance evaluation, and continuous improvement. Certification is voluntary but has become a global market expectation: ISO 27001 certification is required by countless procurement policies, regulatory frameworks (NIS2 references it, ENS aligns with it, E-ITS accepts it as equivalent, BSI IT-Grundschutz enables ISO 27001 certification), and customer contracts. Certification is issued by accredited certification bodies (accredited under ISO/IEC 17021) following a two-stage audit process, valid for 3 years with annual surveillance audits. Over 70,000 organizations worldwide hold ISO 27001 certification. Unlike prescriptive frameworks (DISA STIG, CIS Benchmarks), ISO 27001 is risk-based and outcome-oriented — it specifies what must be achieved but not how, allowing organizations to tailor implementations to their context.

Red Hat holds ISO/IEC 27001 certification for its global operations, covering the development, delivery, and support of its product portfolio — a certification renewed through regular surveillance audits. This means Red Hat’s internal security practices (secure development lifecycle, vulnerability management, access control, incident response, business continuity) are independently verified against the standard’s requirements. For customers pursuing their own ISO 27001 certification, Red Hat provides the technical controls that map to Annex A requirements across all four themes. For Organizational controls: Red Hat’s CSAF/VEX vulnerability feeds, Insights-driven risk analytics, and documented shared-responsibility models support the information security policies, threat intelligence, and supplier management controls (A.5.x). For Technological controls: RHEL and OpenShift deliver access control (A.8.3), cryptography (A.8.24), secure configuration (A.8.9), logging and monitoring (A.8.15–8.16), network security (A.8.20–8.22), and data protection controls (A.8.10–8.12). The OpenShift Compliance Operator can continuously validate configurations against ISO 27001-derived profiles, providing the ongoing conformity evidence that surveillance auditors examine. Ansible Automation Platform enables the “continual improvement” cycle (clause 10) by codifying security controls as repeatable, version-controlled playbooks that evolve as the ISMS matures. Red Hat’s alignment with ISO 27001 also creates a foundation for meeting other frameworks that reference or build upon it — including BSI IT-Grundschutz (which offers ISO 27001 certification based on IT-Grundschutz), ENS (which aligns its 73 measures with ISO 27001 Annex A), and E-ITS (which accepts ISO 27001 as equivalent compliance evidence).

Additional Information
#

Related

BSI IT-Grundschutz

BSI IT-Grundschutz is Germany’s national framework for establishing, implementing, and certifying an Information Security Management System (ISMS). It is developed and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) and stands out from generic standards like ISO/IEC 27001 by its extreme level of prescriptive detail — the IT-Grundschutz Compendium contains hundreds of specific security building blocks (“Bausteine”) covering technical, organizational, infrastructure, and personnel aspects. The framework is defined across four BSI Standards: 200-1 (ISMS requirements), 200-2 (methodology with three approaches: Basis-Absicherung, Standard-Absicherung, Kern-Absicherung), 200-3 (risk analysis), and 200-4 (business continuity management). Organizations can pursue ISO 27001 certification based on IT-Grundschutz, which is recognized as equivalent to standalone ISO 27001 but with the added rigor of the BSI’s detailed control catalog. Compliance is mandatory for German federal agencies (Bundesbehörden) under the UP Bund framework and is strongly recommended — often contractually required — for KRITIS operators and public-sector contractors. A major modernization is underway: Grundschutz++, introduced in 2025–2026, replaces the traditional PDF-based building blocks with OSCAL/JSON machine-readable catalogs, aligning with the NIS2 implementation requirement for a BSI-defined “state of the art.” The classic IT-Grundschutz remains valid for audits until end of 2028.

CIS Benchmarks

CIS Benchmarks are detailed, prescriptive security configuration guidelines published by the Center for Internet Security (CIS), a US-based non-profit organization. They are developed through a consensus process involving cybersecurity practitioners, vendors, and government agencies, and cover over 100 technology families — operating systems (Linux, Windows, macOS), cloud platforms (AWS, Azure, GCP), container orchestrators (Kubernetes, Docker), databases, web servers, and network devices. CIS Benchmarks are international in applicability — they are not tied to any single jurisdiction — and are referenced by regulatory frameworks worldwide (NIST, PCI-DSS, HIPAA, FedRAMP, NIS2 national implementations). Each benchmark provides two recommendation levels: Level 1 (practical hardening that does not significantly impact functionality) and Level 2 (defense-in-depth settings for high-security environments). CIS Benchmarks are voluntary — no law mandates CIS compliance directly — but they are frequently required by procurement contracts, industry standards, and as evidence of “reasonable security measures” in regulatory audits. The CIS also offers CIS Controls (formerly the SANS Top 20), a prioritized set of cybersecurity best practices, and the CIS Hardened Images program for pre-configured virtual machine images.

E-ITS / ISKE (Estonian Information Security Standard)

E-ITS (Eesti infoturbestandard — Estonian Information Security Standard) is Estonia’s national information security framework, developed and maintained by the RIA (Riigi Infosüsteemi Amet — Information System Authority). It replaced the previous ISKE (Infosüsteemide kolmeastmeline etalonturbe süsteem) system, which was in effect until 31 December 2022. E-ITS entered into force in December 2022 and is mandatory for all organizations performing public duties in Estonia — state agencies, local governments, and any entity operating information systems essential for the functioning of society. Private organizations may also voluntarily adopt E-ITS to achieve their information security goals. The standard is based on the German BSI IT-Grundschutz baseline protection methodology and is designed to be fully compatible with ISO/IEC 27001 — an audited E-ITS conformity allows organizations to demonstrate compliance equivalent to the international standard. E-ITS presents a baseline protection catalog containing security modules with specific measures, organized by asset type (IT systems, networks, applications, industrial automation, vehicles, etc.). Organizations must identify their assets, determine protection needs, apply the corresponding baseline measures, and undergo periodic audits. Alternatively, organizations may satisfy their obligation by holding a valid ISO/IEC 27001 certificate and submitting it to RIA. The standard is updated annually each autumn to reflect new threats and technological developments, and RIA provides a free support application (based on the 2024 version) to guide implementers through the process.