Think of ISO 27001 as a framework, similar to NIST. ISO 27001 provides information security management standards and controls and ISO 27002 provides detailed guidance on various ways to implement and meet the information security standards defined within ISO 27001. An organization can claim that it has controls in place to meet the requirements of ISO 27001. That is not the same as being certified against ISO 27001. An independent auditor can perform testing against ISO 27001, resulting in certification. The type of audit performed will determine whether the effectiveness of controls over time is tested, or whether the audit is only to validate that controls are appropriately designed to meet ISO 27001.
-------------------------------------------
Original Message:
Sent: 08-05-2025 10:23 AM
From: Anonymous Member
Subject: IO 27001 - Operating Effectiveness
This message was posted by a user wishing to remain anonymous
Is it accurate to say ISO 27001 does not test the operating effectiveness of the controls in place. How factual is this and are there any resources that agree or disagree with this?
-------------------------------------------