Skip to main content
ISO/IEC 27001:2022 · ISMS

Creating an ISMS It works after the audit.

ZebraByte helps prepare for ISO/IEC 27001 through risk management, controls, policies, evidence and ongoing processes.

Management system

ISO/IEC 27001 is not a universal list of technologies.

The standard defines requirements for an Information Security Management System based on risk.The scope, risk assessment, risk treatment, controls and evidence must reflect the actual organization.

This makes the difference between an operable ISMS and a set of documents prepared only for certification.

Clauses 4–10

The spine of the ISMS.

Annex A is only a part of the standard. Clauses 4–10 describe how the system is defined, operated, operated, verified and improved.

04

Context

Organization, stakeholders, needs, limits and scope of the ISMS.

05

Leadership

Policy, responsibilities and management involvement in the program.

06

Planning

Risks, opportunities, objectives and risk management methodology.

07

Support

Resources, skills, awareness, communication and documented information.

08

Operation

Implementation of the treatment plan and operation of the chosen controls.

09

Performance

Monitoring, measurement, internal audit and management review.

10

Improvement

Inconsistencies, corrective actions and continuous improvement.

Annex A

93 controls, patru teme.

Not all controls apply automatically to each organization. Risk assessment and risk treatment determine what is relevant, and Statement of Applicability documents the decision.

37

Organizational

Policy, roles, supplier relationships, threat intelligence, incident management and other governance controls.

8

People

Screening, terms of employment, awareness, responsibilities and processes that reduce human risk.

14

Physical

Secure areas, equipment, working environments and physical protection of information and infrastructure.

34

Technological

Identity, access control, logging, vulnerability management, cryptography, networks and secure development.

Risk loop

Risk management is at the heart of ISMS.

Controls are not selected in isolation. They must be traceable back to the risks, decisions and objectives of the organization.

01

Context and Activity

Systems, information, processes, suppliers and dependencies within the scope.

02

Evaluarea riscului

Threats, vulnerabilities, impact, probability and their own assessment criteria.

03

Tratamentul riscului

Reduce, avoid, transfer or accept risk through a documented decision.

04

Controls & SoA

Read relevant risk controls and document the applicability in the Statement of Applicability.

05

Evidence

Reviews, approvals, logs and results showing that the measures are operating in practice.

06

Continual improvement

Risk, scope and controls are updated as the business or infrastructure changes.

Technical evidence

Policies must be supported by the technical reality.

Where scope requires technical measures, security engineering must be able to demonstrate what is actually happening in the infrastructure.

Vezi Cyber Security
01 identity, MFA, SSO and access reviews
02 Vulnerability management, patching and hardening
03 Logging, monitoring and incident handling
04 Backup, Recovery and Business Continuity
05 Supplier and third-party security
06 Secure Development and Change Management

Certification journey

Readiness and certification are different roles.

ZebraByte prepares and can help with the operation of the program. Evaluation and certification remain independent.

Readiness

Build the ISMS

Scope, risk assessment, controls, policies, evidence and remediation before the independent assessment.

Internal assurance

Check before certification

Internal audit, management review, findings and corrective actions before the external auditor evaluates the system.

Stage 1

Documentation and preparation

The certification body shall verify the preparation of the ISMS and the basis required for the detailed assessment.

Stage 2

Deployment and Operation

Evaluators verify that the ISMS and the selected controls are deployed and operated within the declared scope.

Continuous

Keeping the system alive

Risk reviews, internal audits, management reviews and continuous improvement do not stop after certification.

Responsibility

Roluri clare.

ZebraByte

Readiness, ISMS design, risk management, controls, evidence, remediation and continuous operation within the agreed scope.

Your organization

It holds the decisions, risk, responsibilities and effective operation of the information security management system.

Certification body

It independently assesses the ISMS and, when the requirements are met, issues the certification.ZebraByte is not a certification body.

External assurance

After certification, you publish exactly what you can demonstrate.

The certificate and assurance materials can be distributed through the Trust Center within the scope of the certificate. The internal workspace, risk register and other sensitive information remain separate.

Vezi Trust Center
Trust Center ZebraByte pentru distribuirea documentelor ISO 27001

Case studies

Practical examples from the platform library about compliance and security programs built for growing organizations.

See all case studies.

Frequently asked questions

ZebraByte poate emite certificarea ISO/IEC 27001? +

No.ZebraByte can help with readiness, ISMS design, risk management, controls, evidence and remediation. Certification is issued by an independent certification body after scope and system evaluation.

Should all 93 controls in Annex A be implemented? +

The organization evaluates its risks and obligations, selects relevant controls and documents inclusion or exclusion in the Statement of Applicability.

Ce este Statement of Applicability? +

It is the document linking risk management to the relevant controls in Annex A and explaining their applicability. We treat it as a living part of the program, not as a table prepared solely for audit.

ISO27001 is just a documentation project? +

No. Policies and documents are required, but certification is based on a management system operated in practice. Access reviews, supplier management, incident handling and other processes must be supported by real evidence.

What happens after certification? +

ISMS continues: risk reviews, internal audits, management reviews, corrective actions and updating of controls. Certification does not turn the program into a static artefact.

The audit preparation begins with an ISMS that the team can use.

We can start with readiness and turn the result into a continuously followed program in the ZebraByte platform.

Talk about ISO27001
ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert