ISO/IEC 27001:2022 is the international standard for information security management systems. Clients in finance, healthcare and the public sector increasingly ask software suppliers whether they are certified, and what that means for the way software is built. ALGOFACT is certified to ISO 27001:2022, and this article explains in general terms how the standard relates to software delivery and what a client can reasonably expect to see.

What the standard is

ISO 27001 does not prescribe specific technologies. It defines a management system in which an organization identifies its information security risks, selects controls to treat them, documents its policies and procedures, and reviews them regularly. Compliance is checked by an accredited certification body through an initial audit and recurring surveillance audits.

The 2022 edition reorganized the control catalog in Annex A into four themes: organizational, people, physical and technological. It also added controls such as secure coding, configuration management and data leakage prevention, which are directly relevant to software teams.

What it does not guarantee

Certification shows that an organization operates a managed system for information security. It does not state that a particular product is free of vulnerabilities, and it does not certify the design of an individual application. The scope of the certificate also matters. It covers the sites, services and processes named in the scope statement, so a client should read the scope and the statement of applicability.

Controls that affect software delivery

Several controls shape everyday engineering work.

  • Access control and least privilege. People receive access to repositories, environments and data according to their role, and access is reviewed and removed when roles change.
  • Separation of environments. Development, test and production are kept apart, and production data is not used in development without protection.
  • Code review and change management. Changes are reviewed, tracked and approved before release, so that each production change can be traced to a request and a reviewer.
  • Secrets management. Passwords, keys and tokens are kept in a managed store and not in source code.
  • Dependency and vulnerability scanning. Third-party libraries and container images are scanned, and findings are triaged and fixed within defined times.
  • Logging. Security-relevant events are recorded and protected from tampering.
  • Backup and recovery. Backups are taken on a schedule, protected and tested by restoring them.
  • Supplier and client data handling. Client data is used only for the agreed purpose, stored in agreed locations and returned or deleted at the end of the engagement.

Evidence and traceability

A client can ask to see more than a certificate. Reasonable requests include the scope and statement of applicability, the information security policy, the secure development procedure, the access review records, a summary of recent audit results, and the incident management process. For a specific project, a client may ask for the review history of changes, the results of dependency scans, the backup test records and the list of personnel with access to its environments.

Traceability is the common thread. A good process lets a team show who changed what, who approved it and when it was released, and that is as useful to the engineering team during an incident as it is to an auditor.

Effect on procurement

In finance, health and the public sector, tender documents often list ISO 27001 as a requirement or as a scored criterion. Banks and insurers extend their own supplier risk programs to their vendors. Healthcare providers handle sensitive personal data and need assurance about how suppliers manage it. Having a certificate shortens part of the due diligence, because many questionnaire items are already covered by documented controls.

Limits

Certification does not replace a security review of a specific system. Threat modeling, penetration testing and architecture review of the application remain necessary, particularly for systems that process sensitive data or are exposed to the internet. The most useful way to treat ISO 27001 is as the foundation for a supplier's working practices, with project-level security assessment built on top of it.