ISO/IEC
27001

Why "certified" doesn't mean "secure" — and what actually does.

A field note from the compliance bench · Alan Pazmino
01
What It Is

A Management System, Not a Checklist

ISO/IEC 27001 is the international standard for an information security management system. First published October 2005 — 2005-10-01, per the Wikidata record. It's not a product. It's a process for deciding how your organization protects information.

02
The Three Levers

Risk · Controls · Improvement

  • Risk assessment — find what matters, score the threat
  • Security controls — Annex A: 93 controls, 4 domains
  • Continuous improvement — the Plan-Do-Check-Act loop
CIA triad: Confidentiality, Integrity, Availability — every control traces back to one of these.
03
The Common Failure

$ audit_findings --scope redundant_paths

path_1 [ OK ] primary fiber, certified

path_2 [ OK ] secondary fiber, certified

path_3 [ OK ] backup microwave, certified

> WARN: all three share grounding reference U/G-7

$ risk_score --single_point_of_failure

CRITICAL — redundancy is theater without independence

The Bottom Line

Certificate ≠ Security

A certified ISMS is only as good as its living processes. Independent verification beats paperwork. Measure twice — with a second instrument — and never trust a single reading.

iso.org/standard/27001 · Wikidata Q852641
05