ISO 27001
The international standard for information security management systems. Required for many enterprise deals — especially in Europe and APAC — and a strong signal of mature security operations.
Mapped, monitored, and audit-ready.
Every ISO 27001 control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.
Talarity's pre-built control library covering ISO 27001, with linked evidence, owners, and testing schedules.
Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.
- ISMS documentation and policy versions
- Statement of Applicability with control justifications
- Risk treatment plans and residual risk records
- Internal audit reports and management reviews
- Vendor due diligence and supplier risk records
Your ISO 27001 dashboard
Every completed ISO 27001 assessment updates this automatically — where you stand now, how that has changed, and which areas need work.
What gets easier with Talarity.
ISO 27001 demands a full ISMS — risk register, statement of applicability, internal audits, management reviews — not just controls.
Talarity ships every ISMS artifact as a first-class object. Risk register quantifies in dollars; SoA generates from your control selection; internal audits and management reviews track in the platform.
External auditors ask for traceability: 'Show me how this control connects to this risk and this evidence.'
Click any control to see its risk linkages, evidence artifacts, owner, and testing history. One click, full traceability.
The 2022 update reduced controls from 114 to 93 — but reorganized everything. Migrating from 2013 mappings is painful.
Talarity ships the 2013 → 2022 mapping out of the box. Existing controls migrate automatically; you don't redo work.
Surveillance audits annually plus a full re-cert every 3 years — staying audit-ready year-round is expensive.
Continuous monitoring with drift detection. If a control falls out of compliance, you know before the auditor does.
ISO 27001 — common questions
- What changed in ISO 27001:2022 compared with the 2013 version?
- Annex A was restructured from 114 controls in 14 domains into 93 controls in four themes — Organisational, People, Physical and Technological. Eleven controls are new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Most existing controls were merged rather than removed, so organisations certified against the 2013 version generally remap rather than rebuild.
- What is the difference between ISO 27001 and SOC 2?
- ISO 27001 certifies a management system: you prove you run an ISMS with defined scope, risk treatment, objectives and continual improvement, and an accredited body issues a certificate. SOC 2 is an attestation report written by a CPA firm describing your controls against the Trust Services Criteria, and the reader forms their own view. ISO is more common outside North America and with international buyers; SOC 2 dominates US enterprise procurement. The underlying controls overlap heavily, so most of the evidence serves both.
- What is a Statement of Applicability?
- The Statement of Applicability records, for every Annex A control, whether it applies to your ISMS, the justification for including or excluding it, and its implementation status. It is the document auditors work from, and it is mandatory. Because it must stay consistent with your risk treatment plan as controls change, keeping it accurate by hand is where most ISMS drift originates.
- How long does ISO 27001 certification take?
- Certification is a two-stage external audit. Stage 1 reviews your documentation and ISMS readiness; Stage 2 tests that the system is operating. You need the ISMS running long enough to have produced real records — internal audit, management review, risk treatment decisions — before Stage 2 is meaningful. Surveillance audits then follow annually, with recertification on a three-year cycle, so ISO is an ongoing programme rather than a one-off project.
- Do we need to implement all 93 Annex A controls?
- No. Annex A is a reference set, not a mandatory checklist. You select controls based on your risk assessment and justify any exclusions in the Statement of Applicability. What auditors test is whether your selection follows logically from your identified risks — an exclusion with a sound justification is acceptable, an unexplained gap is not.
Working with ISO 27001
Step-by-step walkthroughs from the Talarity library.
- Compliance·8 min readPackage your audit evidence once — for the auditor, regulator, or customerAn auditor asks for your evidence and it's scattered across framework reports, vendor attestations, policy sign-offs, and resilience tests. Evidence Distribution Packages assemble the signed artifacts you already produced into one immutable package, then hand it to each audience as a redacted, watermarked, time-limited copy — with a record of who received what.
- Compliance·7 min readFramework readiness to audit package — the whole cycle on one screenAudit prep usually means a spreadsheet scramble — chasing evidence, tracking which controls are covered, re-checking what's expired. Talarity keeps a live readiness picture for every framework (SOC 2, ISO 27001, CIS, and more) — coverage, gaps, evidence freshness — and packages it into an auditor-ready export in one click.
- Compliance·7 min readContinuous compliance is a tooling problem, not a process problemEvery compliance program eventually decides it needs to be 'continuous.' Most then try to fix it with process. The actual fix is upstream — in the tools that make evidence freshness a default, not a sprint.
- Compliance·14 min readThe evidence nobody can deleteA legal hold is a promise that a specific piece of evidence will still exist months from now, made to people who will check. This is where you place one in Talarity, what the record has to survive, and — just as important — what a hold does not freeze.
Ready to ship ISO 27001?
Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.