ISO 27001:2022 — Third Edition

Master
Information
Security.

The complete free learning platform for ISO 27001:2022. From zero to audit-ready — clear explanations, interactive quizzes, and real-world scenarios.

10
Clauses
93
Controls
11
New in 2022
10+
Practice Sets
📖
What is ISO 27001?
Plain-English intro for complete beginners
📋
The 10 Clauses
Requirements with deep-dive expandable detail
🛡️
All 93 Annex A Controls
Grouped, browsable, with real examples
🧠
Quizzes & Exam Prep
Knowledge checks + 10 practice exam sets
Confidentiality Integrity Availability Risk Assessment ISMS Annex A Controls Statement of Applicability Internal Audit ISO 27001:2022 Threat Intelligence Cloud Security Data Leakage Prevention Confidentiality Integrity Availability Risk Assessment ISMS Annex A Controls Statement of Applicability Internal Audit ISO 27001:2022 Threat Intelligence Cloud Security Data Leakage Prevention

Everything you need to learn ISO 27001

From your first encounter with the standard to being ready to support a real certification audit.

📖
Beginner Introduction
What ISO 27001 is, why it exists, how it differs from laws like GDPR, and the CIA triad explained simply.
📋
10 Clauses Deep-Dive
Every clause explained with overview summaries plus expandable in-depth content and real workplace examples.
🛡️
93 Controls — Grouped
All Annex A controls organised into logical sub-groups. Click any group to explore controls with examples.
11 New 2022 Controls
What changed from 2013, why each new control was added, and the real-world impact it addresses.
🧠
Knowledge Check Quizzes
Simple and medium difficulty. Get instant feedback with explanations for every wrong answer.
🎯
10 Practice Exam Sets
Exam-style questions — tricky, realistic, and scenario-based. Track your score per set. Download question bank.

What is ISO 27001?

No jargon. No assumptions. A clear explanation for someone completely new to information security.

Information security isn't just IT — it's everything.

ISO 27001 is an international standard that tells organizations how to manage information security. It doesn't prescribe exact technical tools — instead, it gives you a structured system called an ISMS (Information Security Management System) to identify risks and protect your information assets.

Think of it like this: if your organization handles any valuable information — customer data, employee records, financial data, trade secrets — ISO 27001 is the internationally recognized way to prove you're taking care of it properly.

The CIA Triad — the heart of it all

Every single security decision in ISO 27001 comes back to protecting three things:

C
Confidentiality
Only the right people can see the information. Example: your salary data should only be visible to HR and you — not to your colleagues.
I
Integrity
Information is accurate and hasn't been tampered with. Example: a financial report must not be altered by unauthorized people — the numbers must be trustworthy.
A
Availability
Information is accessible when needed. Example: your organization's email must be available during business hours — a ransomware attack that locks it down violates availability.

Framework vs Law — what's the difference?

This is one of the most common confusions for beginners. ISO 27001 is a voluntary framework, not a law. Laws like GDPR are mandatory. Here's how they differ:

🏗️ ISO 27001 — Framework / Standard
Voluntary — organizations choose to adopt it (though clients or contracts may require it)
Certifiable — a third-party auditor can award you an official certificate
Flexible — you define your own scope and choose relevant controls from Annex A
Risk-based — you decide which risks to treat based on your specific context
No legal penalties for not adopting it — but you may lose business opportunities
⚖️ Laws & Regulations (e.g. GDPR, HIPAA, NIS2)
Mandatory — you must comply if you operate in that jurisdiction or handle that type of data
Enforced by government regulators and can result in heavy fines or legal action
Prescriptive — specific requirements are non-negotiable (e.g. GDPR's 72-hour breach notification)
No certification — compliance is assessed through regulatory audits, not a voluntary certificate
Penalties can be severe — GDPR fines up to €20 million or 4% of global annual revenue

Real-world examples of each

Frameworks / Standards:

ISO 27001 ISO 27002 SOC 2 NIST CSF CIS Controls PCI DSS

Laws / Regulations:

GDPR (EU) HIPAA (US) NIS2 (EU) DORA (EU) PDPA
A company operating in the EU that handles personal data must comply with GDPR (mandatory — the law) AND may choose to also get ISO 27001 certified (voluntary — the framework) to demonstrate they have a solid security management system in place. Being ISO 27001 certified can actually help demonstrate GDPR compliance to regulators.

Why do organizations get certified?

🤝
Win enterprise clients
Many large organizations require suppliers to hold ISO 27001 before signing contracts.
🔍
Find security gaps
The risk assessment process forces you to identify vulnerabilities you didn't know existed.
📉
Reduce breaches
Implementing controls systematically significantly lowers the risk and impact of incidents.
🌍
International trust
ISO is globally recognized. Certification communicates your security posture across borders.

The 10 Clauses of ISO 27001:2022

Clauses 1–3 are introductory. The mandatory requirements are in Clauses 4–10. Click any clause to expand. Click "Deep Dive" for detailed requirements and examples.

Annex A — All 93 Controls

Controls are grouped by category, then sub-grouped by topic so they're easier to remember and review. Click a group, then a sub-group, then a control to see its description and a real-world example.

The 11 New Controls in ISO 27001:2022

When ISO 27001 was updated from the 2013 version, 11 brand-new controls were introduced in Annex A. Here's what each one means, why it was added, and the real-world impact.

Quizzes & Exam Prep

Choose your mode. Knowledge Check tests understanding. Practice Exams simulate real exam conditions with tricky, scenario-based questions.

📚
Knowledge Check
Simple and medium difficulty questions. Great for learning as you go. Instant explanation for every wrong answer.
Simple · Medium
🎯
Practice Exams
10 full practice sets. Scenario-based, tricky questions designed to challenge. Download the question bank as a PDF.
Exam Prep
Select a difficulty above to start

Select a Practice Set

Real-Life Scenarios

Each scenario presents a realistic workplace situation. Read it, choose your response, and learn which controls apply and why.