When and where did ISO 27001 originate?
To understand the purpose of the ISO 27001 standard, it’s important to know how the framework first came about.
Check out the video below for a brief overview or keep reading.
A brief history of ISO 27001
If looking at the lifecycle of the ISO/IEC 27001 standard page, you'll see it was first published by the International Organization for Standardization (ISO) in partnership with the International Electrotechnical Commission (IEC) in 2013. However, the development of this standard actually began decades earlier.
In the early 1990s, the UK government’s Department of Trade and Industry (DTI) asked the Commercial Computer Security Centre (CCSC) to create a set of evaluation criteria for determining the security of IT products, which led to the creation of ITSEC.
The CCSC was also asked to create a code of best practices for information security. The result was a document known as DISC PD003. Work on DISC PD003 continued and was split into two major fronts: BS7799-1 and BS7799-2.
BS7799-2 created a formal standard for developing an Information Security Management System (ISMS). First published in 1998 by the British Standards Institution (BSI), this standard was formally adopted as ISO 27001 in October 2005.
- In 2013, ISO/IEC 27001 was revised to align with Annex SL, the high-level structure used for all ISO management system standards.
- In 2017, minor wording and formatting updates were published.
- In 2022, ISO/IEC 27001 was updated again, reducing Annex A controls from 114 to 93 and organizing them into four categories: Organizational, People, Physical, and Technological. The update also addressed modern risks such as cloud services, remote work, and threat intelligence.
What about BS7799-1?
In the late 1990s, the BS7799-1 document was organized into 10 sections, each one outlining a series of controls and control objectives. This document laid the groundwork for ISO 27002, the companion standard for ISO 27001, but it would take decades.
First, in December 2000, ISO adopted BS7799-1 as the basis for creating its ISO/IEC 17799 standard.
Over a year later, in Oslo in April 2001, ISO/IEC held a meeting to discuss major revisions to ISO 17799, and work on a new version of the standard continued from 2001-2004. The new version of ISO 17799 was voted on and confirmed in April 2005 in Vienna and published in June 2005.
Finally, in 2007, ISO/IEC 17799 was renamed as ISO/IEC 27002. Like ISO 27001, this companion guidance standard was also updated in 2022.
The origin of the Information Security Management System (ISMS)
As businesses moved into the digital age and data security become more of a priority, most companies had specific security controls in place. However, those controls were usually implemented ad hoc or in an attempt to follow various best practices. Different departments and office locations had different controls and processes, making larger initiatives like business continuity planning difficult.
The concept of an information security management system (ISMS) was introduced to help companies take a holistic, systematic approach to information security across the entire organization. Building and maintaining an ISMS helps companies take a more thoughtful and intentional approach to identifying and managing risks.
The ISO/IEC 27001 standard outlines requirements for building, maintaining, and continuously improving an ISMS that evolves with emerging threats.
Which version of ISO 27001 is current?
ISO/IEC 27001:2022, as amended in 2024, is the only edition organizations can be certified against today. The 2013 edition has been withdrawn, and certificates issued under it expired on October 31, 2025.
| Edition | Published | Status |
|---|---|---|
| ISO/IEC 27001:2005 | 2005 | Withdrawn; replaced by the 2013 edition |
| ISO/IEC 27001:2013 | 2013 | Withdrawn; certificates expired October 31, 2025 |
| ISO/IEC 27001:2022 | October 2022 | Current edition |
| ISO/IEC 27001:2022/Amd 1:2024 | February 2024 | Current; adds climate change considerations to Clauses 4.1 and 4.2 |
The 2022 edition consolidated Annex A from 114 controls in 14 domains to 93 controls in four themes, added 11 new controls such as threat intelligence and information security for cloud services, and made smaller changes to Clauses 4 to 10, including a new Clause 6.3 on planning changes to the ISMS.
Amendment 1 added a single requirement and a note: organizations must determine whether climate change is a relevant issue for their ISMS, and recognize that interested parties may have climate-related requirements. For most organizations that means a documented assessment, not a new control program.
You may also see references to a 2017 version. EN ISO/IEC 27001:2017 was the European adoption of the 2013 standard rather than a separate revision, which is why it doesn't appear in the table above.
Recommended Reading

ISO 27001:2022 and ISO 27002:2022 Explained: What Were The Updates & How to Comply
Read More