Information Security
Available nowISO/IEC 27001 · 2022
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It covers both the management system (clauses 4–10) and the Annex A control set, the framework of choice when you sell globally.
116
requirements tracked
Core plans
Access
Add-on from $39/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 116 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 116 requirements
- In Keel’s scored scope
- 116 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs ISO/IEC 27001?
- Companies selling into Europe and beyond, where ISO 27001 is the common language
- Teams that want a certifiable, audited standard rather than an attestation
- Organizations building a durable security program, not a one-off checklist
What Keel does
How Keel helps with ISO/IEC 27001
- The full ISMS clauses plus the Annex A controls, crosswalked to your other frameworks
- Statement of Applicability and evidence tracking built in
- Readiness scoring across the whole standard so nothing slips before the audit
Collect once, comply everywhere
ISO/IEC 27001 shares canonical controls with NIST SP 800-53, SOC 2 and HIPAA and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding ISO/IEC 27001 rarely means starting from scratch.
Shares canonical controls with
- CIS Critical Security Controls
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
Features that help with ISO/IEC 27001: Risk register · Policy management · Vendor risk management · Controls & crosswalk · Evidence management
Other frameworks: CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · NIST SP 800-53 · All frameworks