ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.
How this compares to neighbouring topics
This page frames ISO 27001 from the operations angle: which controls a SOC carries and what evidence an auditor wants. For the Swiss reporting duty, see SOC & ISG 24h reporting. For EU regulation, see NIS2 Swiss subsidiaries and DORA requirements for the SOC. For data protection, see revFADP and SOC.
ISMS and SOC are not the same thing
An ISMS under ISO 27001 is a management system. It documents context, risks, roles, processes and controls and demonstrates their effectiveness. A SOC is an operational service: people and tooling that triage, escalate and respond to alerts around the clock. The ISMS describes what should happen when an incident occurs. The SOC detects incidents and responds promptly.
An ISO 27001 certificate confirms that the management system meets the requirements. It says nothing about how fast a security incident is detected or contained. Operations must deliver that effectiveness and demonstrate it through metrics. That is the SOC's role.
Annex A controls a SOC operationally carries
| Control (ISO/IEC 27001:2022 Annex A) | What the standard requires | What the SOC delivers |
|---|---|---|
| A.5.24 Incident management planning and preparation | Documented processes, roles, escalation paths. | Playbooks per alert type, escalation matrix with named roles, documented handovers. |
| A.5.25 Assessment and decision on security events | Criteria for when an event is an incident. | Triage thresholds in the SIEM, documented decision logic, ticket trail with timestamps. |
| A.5.26 Response to information security incidents | Response according to documented procedure. | 24/7 response team, containment actions in EDR/identity, documented response actions per case. |
| A.5.27 Learning from information security incidents | Lessons feed back into controls and rules. | Post-incident reviews, detection rule changes, awareness topics drawn from real cases. |
| A.5.28 Collection of evidence | Preserve evidence in a traceable way. | Immutable logs in the SIEM, forensic artefacts from the EDR, chain-of-custody documentation. |
| A.5.29/A.5.30 Information security in business continuity and ICT readiness | Continuity and recovery secured. | Detection coverage for recovery paths, tabletop participation, alignment with BCM playbooks. |
| A.8.15 Logging | The organisation logs activities and protects those records. | Central log ingestion with prioritised sources, integrity protection, defined retention. |
| A.8.16 Monitoring activities | The SOC detects anomalies and acts on them. | Detection content per business context, 24/7 alerting, documented false-positive reduction. |
Controls A.8.15 and A.8.16 lack 24/7 review despite coverage on paper. This creates a nonconformity because monitoring exists only formally. A managed SOC closes that gap without internal shift scheduling.
Clauses 9 and 10: measurement and improvement
ISO 27001:2022 requires monitoring, measurement, analysis and evaluation in clause 9 and continual improvement in clause 10. Auditors now ask for measurable effectiveness alongside policies. A SOC delivers the KPIs and the evidence that they drive improvement.
- MTTD and MTTR measured per alert class with target bands and trend view.
- Number of confirmed incidents per quarter, with categories and derived rule changes.
- False-positive rate per detection rule as an input for the detection engineering roadmap.
- Coverage maps (assets, log sources, MITRE ATT&CK) with documented gaps and closure plan.
- Tabletop and exercise records with measured improvement in role clarity and response time.
Audit preparation: what auditors want to see
- Statement of Applicability with a clear mapping from SOC-carried controls to playbooks and tool chain.
- Evidence that logs are complete, integrity-protected and retained long enough.
- Sample ticket trails from detection through to post-incident review, with timestamps.
- Record of a tabletop exercise with executive leadership and documented improvements.
- Metrics dashboard from the last management review that shows plainly what was measured and improved.
- Supplier landscape: contract, DPA and audit rights for the managed SOC provider with clear roles and data assignment.
For guidance on when an internal SOC becomes realistic, see Managed SOC vs. in-house. For the economics, see SOC cost Switzerland. For 24/7 operations, see SOC 24/7 operations.
Placement in SOC operations
SOC as a Service Switzerland describes day-to-day SOC operations that support ISO 27001 requirements.
Legal basis and sources
- ISO/IEC 27001, responsible committee ISO/IEC JTC 1/SC 27: committee.iso.org
Frequently asked questions
Does a SOC replace an ISMS?
A SOC does not replace an ISMS. An ISMS is a management system with policies, risks and controls. A SOC is the operational service that delivers several Annex A controls. They complement each other; neither replaces the other.
Which Annex A controls are most directly SOC-relevant?
The relevant controls are A.5.24 to A.5.30 (incident management, continuity, readiness, learning, evidence), A.8.15 (logging) and A.8.16 (monitoring). A SOC without a reference to these controls delivers no audit-ready evidence.
Does our managed SOC provider need to be ISO 27001 certified itself?
It is not formally required but practically expected. A certified provider materially eases supplier-management evidence (Annex A.5.19 to A.5.23) and shortens the audit discussion.
How does ISO 27001 relate to revFADP and ISG?
ISO 27001 controls cover large parts of the technical and organisational measures that revFADP (revised Federal Act on Data Protection) (art. 8) and ISG-adjacent rules require anyway. Organisations must define notification processes and thresholds for each regime, because recipients and deadlines differ.
Is alerting-only enough for ISO 27001 purposes?
Alerting-only suffices only in narrow exceptions. A.5.26 requires response according to procedure and A.5.28 requires evidence preservation. Without a response and forensics chain, organisations struggle to demonstrate these controls' effectiveness. A managed SOC with response is the pragmatic route.
Related terms
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- SOC 2 SOC 2 is a US auditing standard that assesses the security controls of service providers against the Trust Services Criteria.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- Vulnerability Management Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.