Cybersecurity Compliance Guide for Businesses
ISO 27001 Cybersecurity Checklist: Controls & Implementation
ISO 27001 requires implementing an Information Security Management System (ISMS) with 93 controls across four themes: organizational (37 controls), people (8 controls), physical (14 controls), and technological (34 controls) — covering access management, encryption, incident response, business continuity, and supplier security.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
What Is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic framework for managing sensitive information through risk assessment, control implementation, and continuous improvement. ISO 27001 alignment demonstrates to customers, partners, and regulators that your organization takes information security seriously.
The 2022 revision (ISO 27001:2022) restructured the Annex A controls from 14 categories into 4 themes with 93 controls, making the standard more practical and aligned with modern security practices.
Building an ISMS
An ISMS is not a product — it's a management system that encompasses policies, procedures, people, and technology:
- Context and scope. Define the boundaries of your ISMS: which business units, systems, locations, and data types are included. Consider interested parties (customers, regulators, employees) and their security expectations.
- Leadership commitment. Top management must demonstrate commitment through an information security policy, allocated resources, defined roles, and regular management reviews.
- Risk assessment. Identify information security risks, assess their likelihood and impact, and determine treatment options (mitigate, accept, transfer, avoid). Risk assessment drives which controls you implement.
- Statement of Applicability (SoA). Document which of the 93 Annex A controls apply to your organization and justify exclusions. The SoA is a key audit document.
Annex A Controls Checklist (ISO/IEC 27001:2022)
Organizational Controls (A.5)
- A.5.1 Information security policies — Documented, approved, communicated
- A.5.2 Information security roles and responsibilities — Clearly defined
- A.5.3 Segregation of duties — Prevent fraud and error
- A.5.7 Threat intelligence — Monitor for emerging threats
- A.5.8 Information security in project management — Integrate security into projects
- A.5.23 Information security for cloud services — Cloud-specific controls
- A.5.24 Incident management planning — Documented response procedures
- A.5.29 Information security during disruption — Business continuity planning
- A.5.31 Legal and regulatory requirements — Identify applicable requirements
People Controls (A.6)
- A.6.1 Screening — Background checks for personnel
- A.6.3 Information security awareness and training — Regular security training
- A.6.4 Disciplinary process — Consequences for policy violations
- A.6.5 Responsibilities after termination — Access removal, asset return
Physical Controls (A.7)
- A.7.1 Physical security perimeters — Controlled access to facilities
- A.7.4 Physical security monitoring — Surveillance and detection
- A.7.10 Storage media — Secure handling and disposal
Technological Controls (A.8)
- A.8.1 User endpoint devices — Endpoint security policies
- A.8.2 Privileged access rights — Restricted and monitored
- A.8.3 Information access restriction — Least-privilege enforcement
- A.8.5 Secure authentication — MFA, strong passwords
- A.8.7 Protection against malware — Anti-malware controls
- A.8.8 Management of technical vulnerabilities — Vulnerability scanning and patching
- A.8.9 Configuration management — Secure baseline configurations
- A.8.12 Data leakage prevention — DLP controls
- A.8.15 Logging — Comprehensive security logging
- A.8.16 Monitoring activities — Security event monitoring
- A.8.24 Use of cryptography — Encryption at rest and in transit
- A.8.25 Secure development lifecycle — Security in SDLC
- A.8.28 Secure coding — Secure development practices
Implementation Approach
- Phase 1: Establish the ISMS (2–3 months). Define scope, conduct risk assessment, create the Statement of Applicability, develop core policies (information security policy, acceptable use, access control, incident response).
- Phase 2: Implement controls (3–6 months). Address gaps identified in risk assessment. Implement technical controls (encryption, monitoring, access management), process controls (change management, incident response), and organizational controls (training, governance).
- Phase 3: Operate and monitor (3–6 months). Run the ISMS, collect evidence of control operation, conduct internal audits, perform management reviews. This period builds the track record needed for external assessment.
- Phase 4: External assessment. Stage 1 audit reviews documentation and ISMS design. Stage 2 audit evaluates operating effectiveness through evidence review, interviews, and testing.
ISO 27001 vs SOC 2
Both are widely respected, but serve different purposes:
- ISO 27001 is a management system standard — it's about having a systematic approach to security. SOC 2 is an audit report — it's about specific control effectiveness.
- ISO 27001 is globally recognized, particularly in Europe. SOC 2 is most common in North America.
- ISO 27001 results in a certificate (valid 3 years with annual surveillance audits). SOC 2 results in a report (typically renewed annually).
- Many organizations pursue both, leveraging shared controls to minimize duplicate effort.
How SeqOps fits
SeqOps checks your cloud and server configuration against many compliance frameworks, shows which controls pass or fail, and sends scheduled reports you can share with management and auditors. It supports your compliance work; it doesn't certify you.