2026-09-21 · KeXinMaterials Redaktionsteam
ISO 27001 Informationssicherheits-Managementsystem + Schutzkoffer B2B-Compliance-Leitfaden
ISO/IEC 27001:2022 "Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Informationssicherheits-Managementsysteme" ist der globale ISMS-Standard. Erforderlich für Organisationen, die sensible Daten + IT-Systeme + Verteidigungselektronik + Finanz- + Gesundheitswesen verarbeiten.
ISO 27001 Scope + Editions
ISO 27001 published by ISO + IEC. Current revision ISO/IEC 27001:2022. Specifies ISMS requirements. 93 Annex A controls.
ISO/IEC 27001:2022: Current edition (October 2022). Replaces ISO/IEC 27001:2013.
Publisher: ISO + IEC. Joint Technical Committee 1 (JTC1/SC 27 - Information security, cybersecurity and privacy protection).
Title: "Information security, cybersecurity and privacy protection - Information security management systems - Requirements".
Scope: Requirements for Information Security Management System (ISMS). Includes policies + processes + controls + risk management.
Geographic: International standard. Adopted as AS/NZS ISO/IEC 27001 in Australia/NZ. Recognized globally for security compliance.
ISO 27001 Annex A: 93 controls in 4 themes (Organizational 37 + People 8 + Physical 14 + Technological 34). Updated in 2022 from 114 controls (2013).
ISO 27002: Implementation guidance for Annex A controls. Best practices for each control.
ISO 27000 family: 30+ standards. 27001 (ISMS) + 27002 (controls) + 27005 (risk) + 27018 (cloud) + 27701 (PII) + 27017 (cloud security).
Geographic adoption: ISO 27001 + SOC 2 + NIST CSF (US-specific). Many organizations certify both ISO 27001 + SOC 2 for global market.
Geographic alternatives: SOC 2 (US, AICPA) + NIST CSF (US, NIST) + Cyber Essentials (UK, NCSC) + TISAX (automotive, Germany VDA ISA).
B2B relevance: For B2B protective cases containing IT equipment (servers, network switches, comms gear, defense electronics with classified data), ISO 27001 ISMS at supplier level is procurement requirement.
ISMS Risk Assessment + Statement of Applicability
ISO 27001 risk assessment identifies info-sec risks. Statement of Applicability (SoA) lists applicable Annex A controls + justification.
Risk assessment: Identify information security risks. Threats + vulnerabilities + impacts + likelihood.
Risk methodology: ISO 27005 + risk = threat x vulnerability x impact. Or quantitative (FAIR, OCTAVE) + qualitative.
Risk criteria: Organization defines acceptable risk level. Different organizations have different criteria based on risk appetite.
Risk treatment: (1) Reduce (apply controls). (2) Accept (within acceptable risk). (3) Avoid (eliminate risk source). (4) Transfer (insurance, contract).
Statement of Applicability (SoA): Required Annex A document. Lists all 93 controls + applicable (yes/no) + justification + implementation status.
Risk treatment plan (RTP): Required document. Lists selected controls + implementation timeline + responsible persons.
Risk register: Required document. Lists identified risks + treatment decisions + owners + residual risk.
Risk owners: Senior managers accountable for risk treatment. Different from control owners.
Residual risk: Risk remaining after controls applied. Must be within acceptable risk criteria.
Management review: Annual review of ISMS by top management. Includes risk treatment effectiveness + incidents + audit results + continual improvement.
B2B relevance: Request supplier ISMS SoA + Risk Treatment Plan + Management Review minutes + Audit Report (Stage 2 + annual surveillance).
ISO 27002 Annex A Controls (93 total)
ISO 27001:2022 Annex A has 93 controls in 4 themes: Organizational (37), People (8), Physical (14), Technological (34).
Organizational controls (37): Policies + roles + responsibilities + asset management + access control + supplier relationships + incident management + business continuity + compliance.
People 5 (8): Screening + terms of employment + awareness + training + disciplinary process + termination + remote working + breach reporting.
Physical controls (14): Perimeter security + entry controls + office security + equipment protection + storage media handling + physical monitoring + environmental threats + cabling security + maintenance + secure disposal.
Technological controls (34): User access + privileged access + secret authentication + information access restriction + secure coding + mobile device policy + teleworking + logging + monitoring + malware + backup + vulnerability management + penetration testing + incident response + compliance + network security + data classification + encryption + system security + development + test data.
Control types: Preventive (firewall) + Detective (IDS) + Corrective (incident response). Mix of all three recommended.
Annex A 5.1-5.37: Organizational. Includes policies (5.1-5.2), roles (5.3-5.4), asset management (5.9-5.12), access control (5.15-5.18), supplier (5.19-5.23), incident (5.24-5.28), continuity (5.29-5.30), compliance (5.31-5.37).
Annex A 6.1-6.8: People. Includes screening (6.1), employment (6.2-6.4), disciplinary (6.5), termination (6.6), remote work (6.7), breach reporting (6.8).
Annex A 7.1-7.14: Physical. Includes perimeter (7.1), entry (7.2-7.4), secure areas (7.5-7.7), environmental (7.8-7.10), equipment (7.11-7.14).
Annex A 8.1-8.34: Technological. Includes access (8.2-8.5), authentication (8.5-8.8), data classification (8.12-8.13), cryptography (8.24), network (8.20-8.22), malware (8.7), vulnerability (8.6), logging (8.15-8.17), monitoring (8.16), backup (8.13), incident (8.7), development (8.28-8.31).
Implementation guidance: ISO 27002 provides detailed implementation guidance for each control. Latest ISO 27002:2022 aligned with 27001:2022.
B2B relevance: For B2B protective cases containing sensitive data, supplier ISMS + applicable Annex A controls + SoA + implementation evidence required.
ISO 27001 Certification + Test Lab
ISO 27001 ISMS certification requires accredited body audit. Test lab + certification workflow.
Certifying bodies: BSI + DNV + TUV NORD + TUV SUD + TUV Rheinland + DEKRA + LRQA + SGS + Bureau Veritas. All ISO/IEC 17021-1 accredited for ISO 27001.
Accreditation: ISO 17021-1 (Management systems auditing). IAF MLA (Multilateral Recognition Arrangement).
Certification process: Stage 1 (documentation review) + Stage 2 (on-site audit) + Certificate (3 years) + Surveillance (annual) + Recertification (3 years).
Stage 1 (Documentation): Review ISMS scope + policy + SoA + Risk Treatment Plan + internal audit + management review. 1-2 days.
Stage 2 (On-site audit): Verify implementation + competence + controls + monitoring. 3-10 days. Interviews + observations + document review.
Certificate validity: 3 years initial + annual surveillance + recertification. Total 5-7 year cycles.
Surveillance audit: Annual visit. Sample new controls + verify corrective actions + check ongoing compliance. 1-3 days.
Recertification: Every 3 years. Full audit of ISMS.
Cost: ISO 27001 certification EUR 10,000-100,000 depending on organization size + complexity + scope. Stage 1 + Stage 2 + Certificate EUR 15,000-50,000 typical.
Duration: 6-12 months total. Including implementation + Stage 1 + Stage 2 + certification.
Common scope exclusions: Annex A controls marked N/A (not applicable) must be justified in SoA. Cannot exclude fundamental clauses (4-10) of ISO 27001.
Statement of Applicability length: 10-30 pages typical. Lists 93 controls + applicable + implementation status + justification.
Internal audit: Required annually. Conducted by trained internal auditors or external auditor. Documented in ISMS records.
Common B2B mistakes: (1) Certifying ISMS but not enforcing on sub-suppliers. (2) Missing physical / people controls for remote work. (3) Outdated Annex A (still using 2013 version). (4) Missing cryptography for cloud data. (5) No management review evidence.
B2B recommendation: For B2B protective cases containing sensitive data, request supplier ISO 27001 certificate (in date) + SoA + Risk Treatment Plan + Management Review minutes + Surveillance audit report + applicable Annex A controls.
ISO 27001 + Sector Standards (TISAX, NIST CSF, SOC 2)
ISO 27001 is generic. Sectors have derived standards: TISAX (automotive) + NIST CSF (US) + SOC 2 (US, financial). Often required together.
TISAX (Trusted Information Security Assessment Exchange): Automotive industry. German VDA ISA (Information Security Assessment) standard. TISAX labels 1-5.
TISAX labels: AL 1 (basic) + AL 2 (standard) + AL 3 (high) + AL 4 (very high). Different maturity levels.
TISAX assessment: Conducted by ENX Association approved assessment providers. Results shared via TISAX platform.
TISAX scope: OEM automotive suppliers + IT service providers + R&D partners. Required for VW + BMW + Mercedes + Audi + Porsche + Tesla.
NIST CSF (Cybersecurity Framework): US NIST publication. 5 functions (Identify + Protect + Detect + Respond + Recover). Voluntary framework.
NIST CSF tiers: Tier 1 (Partial) + Tier 2 (Risk-Informed) + Tier 3 (Repeatable) + Tier 4 (Adaptive). Maturity progression.
NIST CSF profiles: Customized implementation for specific industry / organization. Different from ISO 27001 risk-based.
SOC 2 (Service Organization Control 2): US AICPA standard. Trust Services Criteria (TSC). Type I (point-in-time) + Type II (period).
SOC 2 TSC: Security + Availability + Processing Integrity + Confidentiality + Privacy. Type II covers period (6-12 months).
SOC 2 vs ISO 27001: SOC 2 = US-based + point-in-time + service organization specific. ISO 27001 = global + ongoing + generic ISMS. Both have similar control objectives.
Common combinations: ISO 27001 + SOC 2 (financial + global) + ISO 27001 + TISAX (automotive + global) + NIST CSF + SOC 2 (US federal + financial).
B2B procurement per sector: Financial = SOC 2 + ISO 27001. Automotive = TISAX + ISO 27001. Healthcare = HIPAA + ISO 27001. Federal = NIST CSF + ISO 27001.
Common B2B mistakes: (1) Certifying ISO 27001 but not maintaining SoA currency. (2) Missing TISAX when required by automotive. (3) SOC 2 Type I only (need Type II for period verification).
B2B recommendation: For B2B protective cases containing IT equipment + sensitive data, request supplier ISMS certification (ISO 27001 / TISAX / SOC 2 / NIST CSF) + SoA + recent surveillance audit + applicable controls + Annex A statement.
Wesentliche Erkenntnisse
- ISO/IEC 27001:2022 ISMS ist der globale Informationssicherheitsstandard mit 93 Annex-A-Kontrollen (Organisation 37 + Menschen 8 + Physisch 14 + Technologisch 34).
- Zertifizierung 3-Jahres-Zertifikat + jährliche Überwachung + Rezertifizierung. Kosten EUR 10K-100K je nach Größe + Geltungsbereich.
- Statement of Applicability (SoA) listet alle 93 Kontrollen + anwendbar (ja/nein) + Begründung + Implementierungsstatus auf.
- Sektorspezifisch: TISAX (Automotive) + NIST CSF (US) + SOC 2 (US Finanz). Oft zusammen mit ISO 27001 erforderlich.
- B2B-Empfehlung: Für Schutzkoffer mit sensiblen Daten + IT-Ausrüstung + Verteidigungselektronik ISO 27001 + SoA + aktuelles Audit + anwendbare Annex-A-Kontrollen verlangen.
FAQ
q
a
q
a
q
a
q
a
q
a