Compliance Monitoring in 2026: Know What Is Working
Your access policy says former employees lose production access promptly. The tickets are closed. But an account review...
An organization may use ISO 27001 to manage information security, ISO 27701 for privacy, ISO 27017 for cloud controls and ISO 22301 for continuity. The names often appear together in a security programme, but they do different jobs. Choosing the right standards begins with the risks, services and information the organization actually manages.
In 2026, the edition matters too. ISO/IEC 27701:2025 changed the privacy management landscape, ISO/IEC 27018:2025 updated guidance for personal information in public clouds, and ISO/IEC 27017:2026 updated cloud security guidance. An older list of ISO security standards can therefore point a team to the right topic but the wrong version or relationship between standards.
This guide explains where the main standards fit, which are management system requirements and which provide guidance, and how to turn their controls into evidence for cybersecurity compliance and risk decisions.
The International Organization for Standardization (ISO) and, for many technology standards, the International Electrotechnical Commission (IEC) publish standards that organizations can use to manage security, privacy, risk and resilience. A standard may set requirements for a management system or provide implementation guidance for a narrower subject.
That distinction affects certification. An organization may seek certification against a suitable management system standard through an independent certification body. Guidance standards do not all support standalone certification.
ISO itself does not certify organizations or issue certificates.
If a customer asks for “ISO compliance,” clarify which standard, edition, scope and form of assurance it expects.
If a customer asks for “ISO compliance,” clarify which standard, edition, scope and form of assurance it expects.
ISO standards also do not automatically satisfy a law or sector regulation. They can support a structured programme and provide reusable evidence, while specific legal and contractual duties must still be assessed separately.
| Standard | Current edition | Main use | Role in a security programme |
|---|---|---|---|
| ISO/IEC 27001 | 2022, with 2024 amendment | Information security management system (ISMS) requirements | Risk-based governance and an independently assessable ISMS |
| ISO/IEC 27002 | 2022 | Guidance on information security controls | Helps select and implement controls referenced by ISO 27001 Annex A |
| ISO/IEC 27701 | 2025 | Privacy information management system (PIMS) requirements and guidance | Manages risks and responsibilities around personally identifiable information |
| ISO/IEC 27017 | 2026 | Information security controls for cloud services | Clarifies customer and provider responsibilities and cloud-specific practices |
| ISO/IEC 27018 | 2025 | Protection of PII in public clouds acting as PII processors | Supports safeguards and accountability for cloud processing of personal data |
| ISO 22301 | 2019, with 2024 amendment | Business continuity management system requirements | Helps plan, exercise and improve continuity of critical activities |
| ISO 31000 | 2018 | Enterprise risk management guidelines | Provides broader principles and a common |
| ISO/IEC 42001 | 2023 | AI management system requirements | Structures governance of AI development, provision and use |
This is a selection, not a requirement to adopt every standard. Start with the business question that needs an answer: information security governance, privacy, cloud assurance, continuity, enterprise risk or AI governance.
ISO/IEC 27001:2022 defines requirements for an ISMS. It asks an organization to establish its context and scope, assess and treat information security risks, select controls, evaluate performance and improve. Its Annex A contains 93 reference controls. The organization determines necessary controls through risk treatment and records inclusion or exclusion in its Statement of Applicability (SoA).
ISO/IEC 27002:2022 provides more detailed guidance on controls. It is useful when teams need to translate a selected control into roles, technical measures and operational checks. ISO 27002 is a guidance standard; an organization is not certified to ISO 27002 in the way it may be certified to ISO 27001.
For 2026 operations, ask whether the ISMS reflects current assets, identities and suppliers. A SoA entry stating that a control is implemented should be supported by a defined scope and evidence. For example, an access control that works for older systems may miss newly deployed cloud applications.
The 2024 amendment to ISO 27001 asks organizations to consider whether climate change is a relevant issue in their context and notes that interested parties may have related requirements. It does not change the 93-control Annex A count.
The 2019 edition of ISO/IEC 27701 was commonly described as a privacy extension to ISO 27001 and ISO 27002. That description needs an update. ISO/IEC 27701:2025 is an independent management system standard for a Privacy Information Management System (PIMS), according to ISO. It can be used on its own, while alignment with an existing ISMS may make implementation more efficient.
The standard is relevant to organizations acting as controllers or processors of personally identifiable information (PII). It helps define privacy responsibilities, risks, controls and evidence. It can support work on data protection obligations, but certification or alignment should not be presented as automatic compliance with GDPR or any other law.
If your programme still maps privacy controls solely as an ISO 27001 extension, review the current PIMS scope and how privacy decisions are governed under the 2025 edition.
ISO/IEC 27017:2026 provides cloud-specific information security control guidance based on ISO 27002. It addresses both cloud service customers and providers and helps clarify responsibility where infrastructure and operations are shared. The 2026 edition replaced ISO/IEC 27017:2015.
Use it to examine questions such as who approves administrative access, who maintains logging, who handles incidents and which party is responsible for a configuration. A contract may allocate responsibility, but operational evidence is still needed to show the control is working.
ISO/IEC 27018:2025 has a narrower privacy focus: protection of PII in public cloud services when the provider acts as a PII processor. Its 2025 edition aligns with ISO/IEC 27002:2022 and includes additional implementation guidance. It replaced the 2019 edition.
A company that consumes cloud services may use both standards in supplier assessment and control design. It should still verify the provider’s actual services, assurance scope and shared-responsibility arrangements rather than assuming a standards reference covers every workload.
ISO 22301:2019, with a 2024 amendment, specifies requirements for a business continuity management system. It helps organizations identify critical activities, plan for disruptions, exercise responses and improve recovery arrangements. Security controls and continuity plans overlap, but an ISO 27001 ISMS alone does not demonstrate that every critical operation can recover to its required level.
ISO 31000:2018 gives principles and guidelines for managing risk across the enterprise. ISO lists it as the current published edition, although a revision is under development. It is useful for common risk language and decision-making beyond cybersecurity. ISO explicitly states that ISO 31000 itself is not a certifiable standard.
For a regulated or complex enterprise, use risk and continuity context to decide which security gaps matter most. An unprotected system supporting a critical business service may deserve a different response from a similar gap in a low-impact test environment.
ISO/IEC 42001:2023 sets requirements for an AI management system. It is relevant to organizations that develop, provide or use AI systems. It addresses governance, objectives, risk and impact management, and continual improvement for AI activities.
An existing ISMS can contribute security processes, but AI governance also raises questions about system purpose, data, oversight and changing behavior. Determine which AI uses are in scope, who owns them and what evidence supports review. Do not assume that ISO 27001 certification automatically covers AI management requirements.
This approach can reduce duplicate collection while preserving the distinct intent of each standard. It also gives leaders a clearer view of the risks that remain after a policy has been approved or a tool has been deployed.
Standards are documented in policies and control libraries; their operating evidence is spread across IAM, cloud, endpoint, vulnerability, SIEM, ITSM and other systems. SPOG.AI connects security and IT signals with assets, controls, risks and ownership to help teams assess coverage and effectiveness, prioritize findings and track remediation through revalidation.
For example, one identity control may support the ISO 27001 ISMS, a privacy programme and a cloud assurance review. A shared evidence layer can show the same control’s actual population and exceptions, while the governance team maps that evidence to each requirement with its proper scope. The platform supports oversight and audit preparation; it does not itself award certification or replace legal assessment.
See how SPOG.AI connects framework requirements with live control evidence.
Your access policy says former employees lose production access promptly. The tickets are closed. But an account review...
A SaaS company can have strong security practices and still struggle to answer a customer’s questionnaire. The team...
The backup dashboard is green. A customer asks how quickly a critical service can be restored after an...