Skip to main content

Compliance

What is ISO 27001?

ISO 27001 is the standard for information security. See what certification requires, who needs it, and how to meet the requirements.

In short

ISO 27001 is the international standard for information security management systems, commonly abbreviated ISMS.

The standard describes how an organisation systematically identifies its risks, selects appropriate security controls and documents that the controls actually work and are maintained over time. It is relevant for every business that handles sensitive data or wants to prove its security level to customers, partners and authorities. In practice, certification works as a recognised seal of quality in tenders and supplier assessments.

Three points are worth knowing: ISO 27001 is the only standard in the 27000 family you can be certified against, the work is built on continuous risk assessment rather than a one-off effort, and the standard overlaps heavily with the requirements of NIS2, so the two efforts can reuse each other's documentation.

MI Support IT helps Danish businesses establish the controls, documentation and technical solutions needed to comply with ISO 27001.

Back to the glossary

What is ISO 27001?

ISO 27001 is the international standard for information security. It describes the requirements for an ISMS (an information security management system), where you systematically map your risks, select controls to manage them and document that it all works in practice. The standard does not dictate specific technologies; it requires that your security work is risk-based, documented and continuously improved. That makes ISO 27001 the backbone of serious work with cybersecurity, and the proof that customers and authorities most often ask for.

What is the difference between ISO 27001, 27002 and 27005?

The three standards belong together, but each has its own role:

  • ISO 27001 contains the requirements for the management system. It is the one you can be certified against.
  • ISO 27002 is a guide to the concrete security controls (access management, encryption, logging and more), a reference for how the controls are implemented.
  • ISO 27005 is a methodology standard for risk assessment: how you identify, analyse and prioritise risks.

In short: 27001 says what is required, 27002 how the controls can be carried out, and 27005 how you assess the risks behind the choices. ENISA, the EU's cybersecurity agency, refers broadly to the 27000 family as the foundation of good security practice.

Who needs ISO 27001?

Certification is voluntary, but in practice it becomes a requirement for many:

  • Suppliers to larger companies and the public sector, where the certificate is requested in tenders and supplier management.
  • Businesses covered by regulation: The requirements in NIS2 and good IT compliance align closely with the standard's controls.
  • SaaS and data-heavy businesses that need to prove customer data is in safe hands.

Even without certification, the ISO 27001 requirements are a strong skeleton to build your security work around.

What does an ISO 27001 certification cost?

The price depends on more factors than the certification audit itself: the size and complexity of the organisation, how mature your current security is (the gap that needs closing), whether you have internal resources or need outside help, and the ongoing maintenance: internal audits, annual surveillance audits and re-certification every three years. The biggest cost is typically not the certificate, but the working hours spent establishing and running the management system. Expect a process measured in months, not weeks.

ISO 27001 and NIS2: how do they fit together?

NIS2 imposes legal requirements for risk management, incident handling, supplier security and contingency planning. These are areas the ISO 27001 controls already cover. A certified ISMS is therefore an excellent starting point for NIS2 compliance: risk assessments, policies and documentation can be reused directly. Conversely, ISO 27001 does not automatically make you NIS2 compliant: The directive has its own requirements for, among other things, registration and incident reporting. See also the guidance from the Danish Centre for Cyber Security on systematic security work.

How MI Support IT can help

We help with the practical foundation under ISO 27001: gap analysis, implementation of technical controls such as MFA, backup and certificate management via PKI management, plus ongoing operation of your security through IT security. Contact us if you want an assessment of how far you are from being able to comply with the standard.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.