Operations & SecurityLast reviewed: 2026-07-30

ISO 27001

ISO 27001 is the leading international standard for information security. It describes how an organization builds, operates and continuously improves an information security management system (ISMS) to systematically protect the confidentiality, integrity and availability of data – verifiable through independent certification.

ISO 27001 is the globally authoritative standard for managing information security. It defines how an organization sets up, operates, monitors and continuously improves what is known as an information security management system (ISMS). The goal is the deliberate protection of the three classic security objectives: confidentiality (data is only visible to authorized parties), integrity (data is unaltered and correct) and availability (data and systems are accessible when needed). The standard is published by the International Organization for Standardization together with the IEC; the current valid version is ISO/IEC 27001:2022.

Crucially, ISO 27001 is not a technical checklist along the lines of "install this firewall." It describes a management-driven process: an organization identifies its own risks to information, decides on suitable protective measures on a risk basis, implements them and demonstrates in day-to-day operations that they work. It is precisely this verifiable, repeatable methodology that sets ISO 27001 apart from isolated security precautions – and makes it a widespread proof of trust toward customers, partners and regulators.

At a glance

  • International standard (ISO/IEC 27001) for information security
  • At its core is an ISMS – a managed, risk-based security process
  • Protects the confidentiality, integrity and availability of information
  • Certification by accredited bodies, valid for 3 years with annual surveillance audits
  • A common requirement for cloud and SaaS providers, including ERP systems

How ISO 27001 works: the ISMS

The heart of the standard is the information security management system. This is not a single IT product, but the interplay of policies, processes, responsibilities and technical measures with which an organization steers information security on a lasting basis. It begins with defining the scope: which sites, systems, data and processes fall under the ISMS? Next comes the core of every ISO 27001 implementation – the risk assessment: for the information assets worth protecting, threats and vulnerabilities are evaluated and the resulting risks are ranked by likelihood of occurrence and potential impact.

Based on this risk analysis, the organization selects measures for risk treatment and documents the rationale in a Statement of Applicability (SoA). Ongoing operation is essential: responsible owners are appointed, staff are made aware, security incidents are recorded and internal audits are carried out. The ISMS is therefore a living system that evolves along with new threats, new systems and changed business processes.

The PDCA cycle: continuous improvement

ISO 27001 follows the principle of continuous improvement based on the PDCA cycle (Plan–Do–Check–Act). In the Plan phase, risks are assessed and measures are planned; in the Do phase, they are implemented. The Check phase uses internal audits and metrics to verify whether the measures are working, and the Act phase corrects weaknesses and adjusts the ISMS. Security is thus not a one-off project, but a loop that adapts protective measures to a shifting threat landscape.

Structure of the standard and the Annex A controls

The binding text of the standard (clauses 4 to 10) describes the management requirements: context of the organization, leadership and top-management commitment, planning including risk treatment, provision of resources, operational running, performance evaluation and improvement. Every certified organization must fulfill these clauses – they form the framework of the ISMS.

The standard text is supplemented by Annex A, a reference catalog of concrete security measures (controls). In the 2022 version, this catalog was streamlined from 114 to 93 measures and organized into four themes: organizational, people, physical and technological measures. Examples range from access control and encryption through supplier security to business continuity and secure software development. Which of these controls are actually relevant follows from the risk assessment – the organization need not implement all of them blindly, but must justify every selection or omission in the Statement of Applicability.

Certification: process and validity

Unlike a mere self-commitment, ISO 27001 can be audited and certified by an accredited certification body. This creates robust proof toward third parties, because an independent auditor confirms the effectiveness of the ISMS. A certificate is valid for three years; during this time annual surveillance audits take place, before a full re-certification audit becomes due at the end.

The two audit stages

The certification audit takes place in two stages. In Stage 1, the auditor reviews the documentation – policies, risk assessment, Statement of Applicability – for completeness and ISMS maturity. Stage 2 is the actual audit, on-site or remote: using samples and evidence, the auditor checks whether the documented processes are genuinely lived out in practice. If nonconformities are identified, the organization must demonstrate corrective actions before the certificate is issued.

ISO 27001 in the ERP context

An ERP system bundles a company's most sensitive data: customer and supplier master data, prices and terms, open orders, inventory as well as posting and document data. If this data falls into the wrong hands or is manipulated, immediate commercial and legal damage results. That is why information security plays a central role precisely in ERP – from authorization through encrypted transmission to audit-proof logging.

For user organizations, ISO 27001 is relevant from two directions. First as a selection criterion: anyone choosing a cloud ERP or SaaS provider should check whether its data center and operations are certified to ISO 27001 – the certificate proves a structured handling of security risks at the provider. Second as an obligation of one's own: if a company introduces an ISMS itself, the ERP system becomes part of the scope. Access rights, provisioning processes, data backup and disaster recovery must then comply with the ISMS requirements and be documented in a verifiable way.

Delimitation: ISO 27001, BSI IT-Grundschutz, SOC 2 and TISAX

ISO 27001 is often confused with related frameworks. The German BSI IT-Grundschutz is a more detailed, more measure-oriented method and can be certified in a way compatible with ISO 27001 ("ISO 27001 based on IT-Grundschutz"). SOC 2 is an assurance report (not a certificate) from an audit firm, common above all in the US. TISAX is the industry-specific standard of the automotive sector, built on top of ISO 27001. Among these, ISO 27001 is the internationally broadest, generic standard and often serves as the common denominator.

Benefits and DACH specifics

The practical benefit of ISO 27001 extends beyond the certificate itself. A functioning ISMS lowers the risk of data breaches and business interruptions, creates clear responsibilities and eases cooperation with security-conscious customers – in tenders the certification is often mandatory. At the same time it is a sales and trust argument, because independent proof carries more weight than a self-declaration.

In the DACH region, ISO 27001 interlocks with further requirements. The GDPR demands "appropriate technical and organizational measures" to protect personal data – an ISMS provides structure and evidence for this, but does not replace data-protection compliance. With the EU NIS2 Directive and its national implementation, mid-sized companies in critical sectors are increasingly coming under statutory security obligations; an existing ISO 27001 ISMS is a solid starting point here, even though NIS2 sets its own requirements. For operators of audit-proof systems, ISO 27001 and the GoBD complement each other sensibly without being identical.

Example

Example: a mid-sized company chooses a cloud ERP

A manufacturer of electronic components with around 120 employees replaces its outdated system and compares several cloud ERP providers. Alongside features and price, information security moves to the fore: a major customer from the automotive industry contractually requires that all systems processing its technical drawings and order data be operated at a provider certified to ISO 27001.

During the selection process, the team has each provider present the ISO 27001 certificate of the data center and – if available – of the ERP operations, and checks the scope. A provider whose certificate covers only the data center but not the application operations is eliminated. The chosen provider can additionally present its Statement of Applicability and its arrangements for access rights and data backup. In this way the mid-sized company meets the customer requirement without having to build a full ISMS itself – the certified supply chain provides the proof.

Frequently asked questions

ISO 27001 is a voluntary standard for an information security management system. The GDPR is a binding law protecting personal data. An ISO 27001 ISMS provides structure and evidence for the technical and organizational measures the GDPR requires, but does not replace data-protection compliance.
A certificate is valid for three years. During this period, annual surveillance audits take place that confirm the continuing effectiveness of the ISMS. After three years, a full re-certification audit is due.
No. If you use an ERP at a certified provider, you benefit from its security level without needing a certificate yourself. Your own certification only becomes necessary when customers, tenders or statutory requirements demand it of your company.
The 2022 version streamlined the Annex A control catalog from 114 to 93 controls and restructured it into four themes – organizational, people, physical, technological. Newly added are measures on cloud services, threat intelligence and secure software development, among others.

Questions about ISO 27001 in your ERP project?

We advise vendor-neutrally – and implement it ourselves on request.

Free consultation