Glossary
What is ISO/IEC 27001 (ISMS)?
ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a documented framework for identifying security risks and applying controls to them. Unlike SOC 2, it produces a certificate issued by an accredited certification body, valid for a fixed term with periodic surveillance audits.
Last updated:
The core of ISO 27001 is not a control checklist but a process: identify assets and risks, decide how to treat each risk, select controls accordingly, then monitor and improve. Annex A provides the reference control set, but the standard expects an organisation to justify which controls apply to it.
That justification lives in the Statement of Applicability, and it is the document worth reading. Certification tells a buyer that an ISMS exists and was audited; the SoA and the certificate's scope tell the buyer what it actually covers. A certificate scoped to one product line or one office is common, and is materially different from one covering the whole company.
In Japan, ISMS certification under this standard is widely recognised in enterprise procurement and is often the first credential a buyer asks for. It is generally better understood by Japanese buyers than SOC 2, which is more established in the US market — one reason vendors selling into both markets end up maintaining both.
Neither credential removes the questionnaire. Certification says a management system meets a standard; buyers still ask about their own specific concerns — where data sits, who the subprocessors are, what happens on breach. The evidence behind those answers is stable, but it is re-transcribed into each buyer's format by hand.
Sources: [1]
Frequently asked questions
- Is ISO 27001 the same as ISMS certification in Japan?
- In practice Japanese buyers use ISMS認証 to mean certification against ISO/IEC 27001, issued by an accredited body. The terms are used interchangeably in procurement, though the certificate itself names the standard and the accreditation scheme.
- Should we ask for ISO 27001 or SOC 2?
- Ask what you actually need to know. If you need assurance that a management system exists and is externally audited, ISO 27001 answers it. If you need evidence that specific controls operated over a period, a SOC 2 Type II answers it better. Requiring both is common but doubles vendor cost, which smaller vendors may decline to absorb.
Skip the discovery calls.
Describe what you need and let AgentDoor's agents interview the vendors for you — you get a decision-ready shortlist, not six meetings.
We'll reach out at launch. No spam, ever.