ISO/IEC 27001 is the international standard for information security management systems (ISMS): a certifiable framework for how an organization identifies, manages and reduces information security risk. In European B2B procurement it is the most commonly requested security credential, often alongside or instead of SOC 2. The standard is published by ISO/IEC.
Key facts:
- Certification is issued by accredited bodies after auditing your ISMS, with surveillance audits annually and recertification on a three-year cycle.
- The current version (ISO/IEC 27001:2022) organizes Annex A into 93 controls across organizational, people, physical and technological themes.
- ISO 27001 certifies the management system, the way you run security, not any single technology.
ISO 27001 vs SOC 2
Many vendors end up doing both; the underlying control work overlaps heavily. For financial entities, DORA layers operational resilience on top; for regulated critical sectors, NIS2 maps naturally onto the same ISMS foundations.
The Annex A controls that run through email
Several controls are decided in the mailbox: protection against malware, information transfer, technical vulnerability management, incident management and response, supplier relationships, and user access management all have email as a primary exposure surface, because phishing and business email compromise are how most information security incidents actually begin. An ISMS that treats email as an afterthought fails where attacks actually start.
Where email security fits, honestly
No product delivers ISO 27001; the certificate covers your whole management system. Sentaro contributes the email-layer controls and their evidence: threat protection as the operating control, continuous logs as audit evidence for surveillance audits, incident detection feeding the incident management process, and OAuth/app visibility supporting access and supplier controls. The risk assessments, policies, Statement of Applicability and management reviews remain yours.
This page is general guidance, not legal advice.