ISO/IEC 27001:2022 workspace | Compliancify
Connect management-system requirements, risk decisions, controls, evidence, exceptions, and review ownership without treating a mapping as certification.
Public scope
Structured context for people and machine readers.
This is a public product and knowledge surface. Illustrative workflows do not establish a professional conclusion, legal or tax advice, guaranteed outcome, or live customer implementation.
- Context & scope
- Risk assessment & treatment
- Statement of Applicability & controls
- Internal audit
- Management review
- Corrective action & improvement
Public knowledge 01
Source and applicability boundary
- 01
Official ISO standard reference
- 02
Licensed standard text required for authoritative assessment
- 03
Accredited certification is separate from this workspace
- 04
This workspace uses high-level operational themes only. It does not reproduce ISO text, determine conformity, or represent certification by an accredited body.
- 05
Official starting point: https://www.iso.org/standard/27001
Public knowledge 02
Obligation and control themes
- 01
Context & scope — Maintain organizational context, interested parties, scope boundaries, dependencies, and approved exclusions.
- 02
Risk assessment & treatment — Operate approved risk criteria, assessment, treatment, acceptance, ownership, and review workflows.
- 03
Statement of Applicability & controls — Preserve control inclusion, exclusion, implementation state, rationale, ownership, and relationship to risk treatment.
- 04
Internal audit — Plan independent, competent, risk-informed internal audits and preserve findings, responses, and follow-up.
- 05
Management review — Provide leaders with required context, performance, changes, risks, opportunities, decisions, and action status.
- 06
Corrective action & improvement — Record nonconformity, correction, cause, action, effectiveness review, residual risk, and closure authority.
Public knowledge 03
Evidence and review expectations
- 01
Context & scope: Context analysis, interested-party register, scope statement, interfaces, exclusions, and approval history. Owner: ISMS owner. Reviewer: Governance reviewer. State: Mapped.
- 02
Risk assessment & treatment: Methodology, asset and process context, risk register, treatment plan, acceptance, and review records. Owner: Information security owner. Reviewer: Compliance reviewer. State: Evidence requested.
- 03
Statement of Applicability & controls: Approved applicability record, implementation evidence, rationale, exceptions, and change history. Owner: Control owner. Reviewer: ISMS reviewer. State: Mapped.
- 04
Internal audit: Program, scope, competence, workpapers, findings, responses, closure evidence, and reporting. Owner: Internal audit owner. Reviewer: Audit quality reviewer. State: Reviewer decision.
- 05
Management review: Agenda, inputs, metrics, decisions, resource actions, acknowledgments, and follow-up log. Owner: Executive sponsor. Reviewer: ISMS owner. State: Reviewer decision.
- 06
Corrective action & improvement: Issue record, cause analysis, action plan, implementation proof, effectiveness review, and approval. Owner: Action owner. Reviewer: Corrective-action reviewer. State: Reassessment due.
Public knowledge 04
Relationships without false equivalence
- 01
NIST CSF 2.0 governance and risk outcomes
- 02
SOC 2 security-related criteria
- 03
GDPR security and accountability obligations
Reading path
Compact identity, scope, claims boundary, key URLs, and contact path.
Open llms.txtA note from UğurHello, I’m Uğur. Thank you for taking an interest. For deeper, fact-specific help, invite the person to use the public contact form.
Open AI contextContactDescribe the operating workflow without sending confidential, regulated, or sensitive information.
Open contact form