> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ISO 27001:2022

> Implement and certify your Information Security Management System (ISMS) with DSALTA.

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It provides a systematic approach to managing sensitive information through people, processes, and technology controls.

<Note>
  ISO 27001:2022 is the latest revision. Organizations certified under the 2013 version must transition by October 2025.
</Note>

## Who needs ISO 27001?

<CardGroup cols={2}>
  <Card title="Global businesses" icon="globe">
    Organizations operating internationally, especially in European and APAC markets where ISO 27001 is the standard security expectation.
  </Card>

  <Card title="Enterprise vendors" icon="building">
    Companies whose customers require formal certification as part of procurement or vendor assessment.
  </Card>
</CardGroup>

## ISO 27001:2022 Annex A themes

The 2022 revision restructured 93 controls into 4 themes:

| Theme              | Controls | Examples                                                       |
| ------------------ | -------- | -------------------------------------------------------------- |
| **Organizational** | 37       | Security policies, roles, asset management, supplier relations |
| **People**         | 8        | Screening, awareness training, disciplinary processes          |
| **Physical**       | 14       | Physical entry controls, equipment security, clear desk policy |
| **Technological**  | 34       | Access rights, authentication, encryption, logging, monitoring |

## Certification process

<Steps>
  <Step title="Define ISMS scope">
    Determine which processes, locations, and systems are in scope for certification.
  </Step>

  <Step title="Conduct risk assessment">
    Identify information security risks and define treatment plans using DSALTA's risk register.
  </Step>

  <Step title="Implement controls">
    DSALTA maps all 93 Annex A controls. Implement policies, configure technical controls, and collect evidence.
  </Step>

  <Step title="Stage 1 audit">
    The certification body reviews your ISMS documentation and readiness.
  </Step>

  <Step title="Stage 2 audit">
    The auditor evaluates whether controls are implemented and operating effectively.
  </Step>

  <Step title="Certification">
    Receive ISO 27001 certification valid for 3 years, with annual surveillance audits.
  </Step>
</Steps>

## How DSALTA helps

* **Pre-built ISMS policies** — AI-generated policies covering all Annex A requirements
* **Risk register** — likelihood × impact scoring with treatment plans (Mitigate, Accept, Transfer, Avoid)
* **93 Annex A controls** mapped to evidence requirements
* **Statement of Applicability** — auto-generated based on your control selections
* **Cross-framework mapping** — \~70% overlap with SOC 2, significant overlap with GDPR and NIS 2

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How long does certification take?" icon="clock">
    Typically 3–6 months for implementation plus the two-stage audit. DSALTA's pre-built controls and policies accelerate this significantly.
  </Accordion>

  <Accordion title="What changed in the 2022 version?" icon="arrows-rotate">
    Restructured from 14 domains to 4 themes, added 11 new controls (threat intelligence, cloud security, data masking, etc.), and updated existing controls.
  </Accordion>

  <Accordion title="Do I need to certify, or just be compliant?" icon="certificate">
    You can implement ISO 27001 without certification, but many customers specifically require the formal certificate from an accredited body.
  </Accordion>

  <Accordion title="How does it overlap with SOC 2?" icon="diagram-project">
    Approximately 60–70% of controls overlap. DSALTA maps these automatically, so completing one framework accelerates the other.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**339** of DSALTA's automated checks contribute evidence to this framework, drawn from **73** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Risk Register](/guides/data-library/risk-register)
* [Policies](/guides/data-library/policies)
