Compliance

ISO 27001

ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification confirms that an organisation systematically manages risks and regularly reviews its security measures.

How it works

The standard requires an ISMS with clear roles, policies, and risk management. The organisation assesses its risks and selects suitable controls from Annex A. The 2022 version includes 93 controls, divided into organisational, people, physical, and technical measures. Internal audits and management reviews drive continuous improvement. An accredited body audits the ISMS and issues the certificate for three years.

A client might request proof of information security before signing a contract. The ISO 27001 certificate and its scope can replace a long questionnaire. The client verifies that the scope covers all the relevant services. Annual surveillance audits demonstrate that the system is actively maintained.

What to look out for

  • Check the scope of application. A certificate for a small part of the company says little about the rest.
  • A certificate is not proof of detailed security. It confirms a functioning management system.
  • The 2022 version adds new controls, for example on threat intelligence and monitoring activities.
  • Plan sufficient time for implementation, often a year or more.

Switzerland and regulation

There is no general obligation for ISO 27001 certification in Switzerland. However, many clients and public tenders require it. The standard helps to implement requirements from the revFADP (revised Federal Act on Data Protection), FINMA circulars, and the ISG.

Relevance for the SOC

Several controls relate directly to the operation of a SOC. These include logging, monitoring, incident handling, and threat intelligence. A SOC provides the necessary evidence through Cases, reports, and key performance indicators.

How we implement it

ANOMAL is certified to ISO 27001. Our SOC reports provide you with evidence for controls related to monitoring and incident handling.

How ANOMAL implements this