All solutions Solution · ISO/IEC 27001

Build an ISMS that carries the certification

From risk treatment through the Statement of Applicability to the internal audit: isidaten maps the ISO/IEC 27001 cycle in one place, so the evidence for the certification audit is always ready.

Request a demo
Background

What ISO/IEC 27001 requires

ISO/IEC 27001 is the international standard for an information security management system. It requires the management-system framework from clauses 4 to 10 and the controls from Annex A. Certification is granted by an accredited body. The effort rarely sits in the single control but in keeping risk, measure and evidence consistent over time instead of reassembling them before every audit.

Context, scope and leadership (clauses 4 to 5)Risk assessment and treatment (clauses 6 and 8)Statement of Applicability (SoA)Annex A controls (organizational, people, physical, technological)Internal audit (clause 9.2) and management review (clause 9.3)Monitoring, measurement and continual improvement
FAQ

Frequently asked questions

What is the Statement of Applicability?

The SoA documents which Annex A controls are applicable and why, including justification for excluded controls. isidaten derives it from risk treatment instead of maintaining it separately.

Does isidaten issue the certification?

No. Certification is issued by an accredited certification body. isidaten builds and runs the ISMS and provides the evidence you take into the audit.

How do ISO 27001 and BSI IT-Grundschutz differ?

ISO 27001 is risk-based and international, IT-Grundschutz is module-based and common in the German public sector. isidaten supports both approaches on one platform.

Does isidaten cover all Annex A controls?

The controls are managed, assessed and linked to evidence within the ISMS. The technical measures themselves are implemented in your environment; isidaten keeps their status and evidence consistent.

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.