Skip to main content

Evidence note

ISO/IEC 27001:2022

Technical Standard2022ISO / IEC

What does it cover?

An international requirements standard for establishing, implementing, maintaining and continually improving an Information Security Management System.

Key points

  1. 1ISO/IEC 27001 addresses organisational information-security management.
  2. 2Certification can provide evidence that an ISMS within a defined scope has been assessed.
  3. 3Certification scope matters when determining whether it supports a particular customer or service claim.

Why it matters. Lornets interpretation.

Certification is meaningful evidence, but it is not a universal technical verdict about every application property. Enterprise readiness depends on whether available evidence actually supports the claims relevant to the service and customer in scope.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 1ISO/IEC 27001 is an information-security management-system standard.
  2. 2Certification does not independently establish application scalability, architecture quality or every implementation-level security property.
  3. 3Lornets does not certify organisations against ISO/IEC 27001.

Source

Organisation
ISO / IEC
Evidence type
Technical Standard
Published
2022
Version
2022 edition, with Amendment 1:2024 applicable
Status
Current

View the standard

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Data & Privacy Engineering

Where this applies

Related evidence

Last verified 2026-08-11

2026

Government Guidance

Supplier Assurance Questions

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

UK National Cyber Security Centre

  • Enterprise Assurance
  • Security & Supply Chain

2026

Practitioner Reference

Cloud Controls Matrix and CAIQ v4.1

CCM v4.1 contains 207 controls across 17 domains.

Cloud Security Alliance, 4.1

  • Enterprise Assurance
  • Security & Supply Chain