Definition · External Attack Surface Management
What is ISO 27001?
ISO/IEC 27001 is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It specifies the requirements for an information security management system (ISMS) — the governance, risk assessment, documentation and improvement machinery around security, rather than a fixed list of technical settings. The current edition is ISO/IEC 27001:2022.
Structure of the standard
The main clauses cover context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists reference controls, organised in the 2022 edition into organisational, people, physical and technological themes. Organisations select controls based on their own risk assessment and record the reasoning in a Statement of Applicability, so two certified organisations can legitimately implement very different control sets.
Certification is issued by an accredited certification body after a two-stage audit, with surveillance audits during the certificate’s three-year cycle. Related documents in the same family — notably ISO/IEC 27002 — provide implementation guidance but are not certifiable.
What it means for external exposure
Nothing in the standard tells you which ports to close. What it does require is that you know what you are protecting and can show the controls work. That makes an accurate inventory of internet-facing assets a practical prerequisite: an ISMS whose asset register omits half the organisation’s subdomains or its shadow IT is describing a different organisation from the one attackers see.
Auditors also look for evidence over time rather than a single clean report. Recurring external scanning, tracked findings and demonstrable remediation timescales feed technical vulnerability management controls, patch management and the monitoring and improvement clauses.
Related concepts
Compare with Cyber Essentials, a much narrower UK baseline, and SOC 2, a US attestation report rather than a certification. For control-level configuration detail, CIS Benchmarks are often used alongside an ISMS. See also vulnerability management and defence in depth.