Maurice Müller
Senior Content Manager
Maurice Müller é um jornalista e estratega de conteúdos com experiência em meios de comunicação impressos e digitais. Na Formalize, transforma temas complexos relacionados com a conformidade e a regulamentação em conteúdos claros e práticos para profissionais das áreas da conformidade, do risco e da segurança em toda a Europa.
Conclusões principais:
A ISO 27001 é a norma internacional para a criação e gestão de um Sistema de Gestão da Segurança da Informação (SGSI).
Baseia-se na tríade da CIA: confidencialidade, integridade e disponibilidade.
O Anexo A da revisão de 2022 define 93 controlos distribuídos por quatro áreas: organizacional, humana, física e tecnológica.
A conformidade significa estar alinhado com a norma; a certificação significa passar numa auditoria independente.
A certificação demora normalmente entre 6 e 12 meses, dependendo da dimensão da empresa e das ferramentas utilizadas.
O custo médio de uma violação de dados atingiu 4,99 $ milhões a nível global em 2026. Trata-se de um recorde histórico, de acordo com o Relatório da IBM sobre o Custo de uma Violação de Dados. A pressão regulatória tem aumentado com a mesma rapidez: só as multas ao abrigo do RGPD ultrapassaram os 6 mil milhões de euros desde 2018, segundo o CMS GDPR Enforcement Tracker. Clientes, parceiros e entidades reguladoras expectam, cada vez mais, provas de que uma organização leva a segurança da informação a sério, e não apenas como uma declaração numa página de vendas. A norma ISO 27001 proporciona às organizações um framework comprovado e reconhecido a nível mundial para salvaguardar sistematicamente os ativos de informação críticos. Substitui soluções pontuais e folhas de cálculo dispersas por um processo estruturado. É também a norma mais frequentemente solicitada em questionários de segurança de fornecedores e em processos de aquisição empresarial, o que torna a sua compreensão útil muito para além das equipas de segurança.
O que é a norma ISO 27001?
A ISO/IEC 27001 é a norma internacional para sistemas de gestão da segurança da informação (SGSI). Proporciona um framework para gerir e proteger dados sensíveis através de uma gestão sistemática dos riscos. A norma estabelece os requisitos que uma organização deve cumprir para identificar, tratar e monitorizar continuamente os riscos de segurança da informação.
A norma é publicada conjuntamente pela Organização Internacional de Normalização (ISO) e pela Comissão Eletrotécnica Internacional (IEC). É por isso que é designada como “ISO/IEC 27001”. A versão atual, ISO/IEC 27001:2022, reestruturou o conjunto de controlos da norma. Introduziu também terminologia atualizada para refletir os desafios modernos de segurança, tais como serviços na nuvem e inteligência de ameaças
A ISO 27001 é deliberadamente independente do setor. Aplica-se igualmente a uma startup de cinco pessoas e a uma empresa multinacional. Isto porque a norma define um processo de gestão de riscos, e não uma lista fixa de tecnologias a implementar. É também por isso que se combina bem com requisitos específicos de cada setor. Uma organização pode criar um único SGSI e alinhá-lo com a ISO 27001, bem como com outros frameworks, como o SOC 2 ou regulamentação específica do setor, em vez de gerir cada uma delas isoladamente. Essa flexibilidade é também a razão pela qual a norma é relevante para públicos tão diversos. Gestores de conformidade que definem o âmbito de um projeto de certificação, CISOs que decidem onde priorizar o investimento e líderes empresariais que avaliam a postura de segurança de um fornecedor acabam todos por perguntar, a dada altura, o que a ISO 27001 realmente exige.
Para conhecer em pormenor todos os requisitos da norma, consulte o guia da Formalize sobre a ISO 27001.
The core pillars: The CIA triad in ISO 27001
ISO 27001 is built around the protection of three core information security principles, together known as the CIA triad. The standard doesn't treat security as a single goal. Instead, it asks organizations to weigh three distinct, and sometimes competing, objectives for every information asset:
Confidentiality
Ensuring only authorized personnel can access sensitive information.
Integrity
Protecting data accuracy and preventing unauthorized alterations or tampering.
Availability
Ensuring systems and data are accessible to authorized users when needed.
An effective ISMS balances all three. Overinvesting in one undermines the others. For example, locking data down so tightly that authorized users can't do their jobs defeats the purpose. A risk assessment under ISO 27001 asks, for each asset, which of the three matters most and what could compromise it. That question is what turns the CIA triad from an abstract concept into a practical prioritization tool.
What is an Information Security Management System (ISMS)?
An ISMS is the practical mechanism behind ISO 27001. It's a management framework that connects people, processes, technology, and organizational risk management into a single, auditable system. It isn't a one-time IT project.
An ISMS defines how an organization identifies risks to its information assets. It also determines which controls to apply, who owns them, and how performance is reviewed over time. That's a meaningfully different challenge than deploying a firewall or an access control policy in isolation. In practice, an ISMS touches areas as varied as HR onboarding and offboarding, vendor contracts, physical office access, software development practices, and incident response. It reaches anywhere information flows through the organization.
Because the scope spans the entire organization, ISO 27001 requires clear ownership. Someone needs to be accountable for the risk register. Someone needs to sign off on the Statement of Applicability. And someone needs to review whether controls are still working as new risks emerge. Without that structure, security work tends to concentrate in IT. Yet many of the highest-impact risks, such as phishing or vendor breaches, sit outside it.
This is also where spreadsheet-based approaches tend to fail. A spreadsheet can hold a risk register or a control list. But it can't enforce ownership, trigger reviews, or link evidence to controls automatically. As the ISMS grows to cover more risks, controls, evidence, and stakeholders, spreadsheets become a liability rather than a system of record.
Key components of the ISO 27001 standard
The standard has two main parts. The first is the set of mandatory clauses that define how the ISMS itself must operate. The second is Annex A, the reference list of security controls an organization draws on. Auditors check every mandatory clause. But they only check the Annex A controls an organization has actually selected as relevant.
Clauses 4–10 (the ISMS framework)
Clauses 4 through 10 are mandatory for certification. They cover the context of the organization, leadership commitment, planning, support, operation, performance evaluation, and continual improvement. Practitioners commonly map this structure to the Plan-Do-Check-Act (PDCA) cycle:
Plan: Define the ISMS scope, assess risks, and set objectives.
Do: Implement the risk treatment plan and selected controls.
Check: Monitor, measure, and internally audit the ISMS.
Act: Address nonconformities and continually improve.
This cycle repeats continuously rather than running once. A risk identified during the "Check" phase, say a new vendor with access to customer data, feeds back into planning. That feedback loop is what keeps an ISMS current as the organization and its threat landscape change. It's not a one-time snapshot from the initial certification.
Annex A controls
Annex A of ISO/IEC 27001:2022 lists 93 controls, organized into four themes:
Organizational controls (37): policies, roles, supplier relationships, and incident management.
People controls (8): screening, awareness, and terms of employment.
Physical controls (14): protecting facilities, equipment, and media.
Technological controls (34): access control, cryptography, and monitoring.

ISO/IEC 27001:2022 update: The 2022 revision consolidated the previous 114 controls from 14 domains (in the 2013 version) into these 93 controls under four themes. The change reflects current risks like cloud security and threat intelligence. Organizations don't need to implement every control. They select the ones relevant to their risk assessment and document exclusions in a Statement of Applicability (SoA). The transition window for existing ISO 27001:2013 certificates closed on October 31, 2025. ISO/IEC 27001:2022 is now the only valid version; any certificate still referencing the 2013 edition is no longer recognized.
Annex A works as a reference list, not a checklist to complete in full. During certification, auditors don't expect all 93 controls in place. They expect the SoA to justify each exclusion and confirm that the controls the organization did select are actually operating, not just documented on paper. A common gap is implementing controls simply because they appear in the annex, rather than because a specific identified risk calls for them.
What is the difference between ISO 27001 compliance and certification?
These two terms are often used interchangeably, but they describe different stages:
Compliance means an organization has aligned its internal security practices and policies with the ISO 27001 standard.
Certification means an accredited third-party certification body has formally audited the organization and issued an official ISO 27001 certificate.
An organization can be compliant without being certified. But certification always requires demonstrated compliance, verified by an external auditor. Some organizations operate a compliant ISMS without pursuing formal certification, for example while preparing internally. Most customer and procurement requirements, though, specifically ask for the certificate itself, since it confirms an independent party has verified the claim.
How to achieve ISO 27001 certification: 5 steps

Scope definition and gap analysis. Identify which assets, systems, teams, and locations the ISMS will cover. Then evaluate existing security controls against the standard to see where the gaps are. Getting the scope right early avoids costly rework later. Too narrow, and the certificate won't cover what customers actually ask about. Too broad, and the project stalls under its own weight.
Risk assessment and treatment. Identify threats to each in-scope asset and score risks by likelihood and impact. Decide how to treat each one (accept, mitigate, transfer, or avoid). Then draft a Statement of Applicability (SoA) documenting which Annex A controls apply.
Control implementation. Put the selected Annex A controls into practice: policies, access controls, vendor due diligence, and other safeguards. Capture evidence as controls are rolled out, not after the fact.
Internal audit and management review. Test the ISMS internally, ideally by someone independent of day-to-day operation of the controls. This confirms it's operating as intended and ready for external review. Management then formally reviews the results and signs off.
Stage 1 and Stage 2 external audits. An accredited ISO registrar first reviews documentation and readiness (Stage 1). It then evaluates real-world implementation and evidence (Stage 2) before issuing certification. Annual surveillance audits follow to maintain it.
Most organizations complete this process in 6 to 12 months. The timeline depends on company size, complexity, and how much of the work is manual versus supported by dedicated tooling. Recertification happens on a three-year cycle, with lighter surveillance audits in between.
What are the benefits of ISO 27001?
ISO 27001 can help organizations:
Identify and manage information security risks systematically, instead of reacting to incidents after they happen.
Demonstrate security maturity to customers and partners, particularly in vendor security reviews and enterprise procurement.
Reduce the cost and frequency of security incidents, backed by controls that are tested, not just documented.
Get a head start toward other frameworks. A working ISMS already covers much of what NIS2 and DORA also require.
Give leadership and staff a consistent process for security decisions, instead of judgment calls that vary by person.
Streamlining ISO 27001 compliance with Formalize
Formalize embeds the official ISO/IEC 27001:2022 standard directly into the platform, through a collaboration with UNE, Spain's national standards body, formalized in April 2026. Teams work from the current, licensed content itself, instead of a separately purchased PDF. Formalize is the first GRC provider in Spain, and among the earliest in Europe, to secure this kind of direct collaboration with ISO/IEC representatives.
Formalize is also part of an official AI pilot with ISO and UNE. The pilot is developing an AI capability called Formalize IQ, intended to turn static ISO requirements into actionable, native workflows once it ships.
Formalize's ISMS software centralizes evidence collection and maps controls to risks, instead of tracking them across disconnected files. It keeps the organization continuously audit-ready, with visibility that stays current between certification cycles, not just in the weeks before an audit. That matters most at exactly the point spreadsheets tend to break down: when ownership needs to be clear, evidence needs to be traceable to a specific control, and reviewers need an up-to-date picture without chasing down the latest version of a file.
Information security risk rarely exists in isolation. That's why Formalize also connects ISO 27001 work to the organization's broader risk management framework. A phishing incident, for instance, can flow directly into updated risk scoring instead of staying siloed in an incident log.
ISO 27001 rarely stands alone in an organization's compliance stack either. Formalize maps its Annex A controls directly to other frameworks, including NIS2, and to national standards such as Spain's ENS, Belgium's CyFun, and Germany's BSI IT-Grundschutz. Update a control once, and that update carries through to every framework it's mapped to. That replaces re-proving the same control separately for each regulator, which is where most duplicate audit work actually comes from.
Formalize's pricing isn't seat-based either. Security teams can invite legal, operations, and outside auditors directly into the platform without paying per additional login. ISO 27001 work touches legal and operations regularly, and seat costs are a common reason those functions get left out of the tooling entirely.
Explore how Formalize can help you build and maintain an audit-ready ISO 27001 management system.