Compliance
ISO 27001
ISO/IEC 27001 information security management system
ISO/IEC 27001 is the international standard for an information security management system, an ISMS. It defines a structured, risk-based approach to protecting the confidentiality, integrity, and availability of an organisation's information, rather than prescribing a fixed checklist of technical controls that applies identically to every organisation regardless of its actual risk profile.
Why ISO 27001 matters in a Microsoft estate
ISO 27001 matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How ISO 27001 shows up in practice
The standard's core mechanism is the ISMS itself: a documented, continuously operated management system covering risk assessment, a defined set of controls selected specifically to address the risks that assessment identifies (drawn from the standard's Annex A control catalogue), internal audit, and a formal management review cycle. All of this is built to support ongoing continual improvement, rather than a one-off compliance exercise completed and then left static. Certification against ISO 27001 requires an accredited external certification body to audit the organisation's ISMS.
Critically, certification is granted for the specific scope the organisation defines and puts forward for audit, which may cover the whole organisation or a deliberately narrower boundary such as one product, one service line, or one specific data centre. A valid certificate always needs checking against its actual stated scope, rather than assumed to cover everything the organisation does. This distinguishes ISO 27001 clearly from Cyber Essentials. Cyber Essentials verifies a fixed, relatively narrow set of basic technical controls, largely at a point in time, while ISO 27001 certifies an entire ongoing management system and risk process.
This makes ISO 27001 a materially larger undertaking to achieve and maintain, but also significantly more comprehensive assurance for a customer or auditor evaluating a supplier's security posture. Once certified, the ISMS is not static. It requires ongoing internal audits, periodic external surveillance audits from the certification body to maintain the certificate between full recertification cycles, and evidence of continual improvement. This means ISO 27001 compliance work does not conclude at the point of initial certification but continues as a standing operational discipline, with audit evidence, incident records, and risk register updates that need to be maintained and demonstrably current, rather than reconstructed only when the next audit approaches.