Skip to main content
← Back to glossary
Compliance & consent

ISO 27001 — ISO/IEC 27001:2022 — Information security management systems — Requirements

Qu'est-ce que ISO 27001?

Cette entrée n'est actuellement disponible qu'en anglais.

ISO 27001 is the international standard that specifies the requirements for an information security management system (ISMS): a defined scope, a risk-assessment and risk-treatment process, a statement of applicability selecting controls from the 2022 Annex A (organisational, people, physical, and technological), and a continuous improvement cycle. Accredited auditors can certify an organization's ISMS against those requirements, and enterprise procurement teams use the standard's clause and Annex-A numbering as the questionnaire format a security review is written in — for a European or certification-driven buyer, ISO 27001 is the default framework pack.

More detail

The standard is genuinely an ISMS specification, not a checklist of technical controls: a certifiable ISMS must define its scope explicitly, identify information-security risks to the assets in that scope, treat those risks, and document a Statement of Applicability that says which Annex-A controls are implemented, which are excluded, and why. The 2022 revision consolidated the control set into four families — A.5 organisational, A.6 people, A.7 physical, A.8 technological — which is the numbering buyers cite when they ask for evidence.

An audit produces a set of verifiable claims. A Stage 2 audit by an accredited certification body yields a certificate scoped to specific sites, services, and legal entities, with a validity window and a surveillance-audit cadence — a buyer can verify the certificate serial against the accreditation registry. The supporting artifacts include the risk register, the Statement of Applicability, internal-audit and management-review records, and the control-monitoring evidence the next surveillance audit checks.

On a CPaaS platform the surface an ISMS covers is wide: where message and call content, recordings, contact records, and API keys are stored and processed; who can access them and under which roles; how tenants are isolated from each other; how suppliers (cloud hosting, sub-processors) are vetted and notified of changes; how encryption, logging, backup, and monitoring are run; and how incidents are declared, logged, and learned from. Annex A maps cleanly onto those operational surfaces.

Devotel Orbit ships the tenant-facing half of the ISO 27001 evidence relationship rather than claiming a platform certification it has not yet completed — the certification itself is on the platform's public roadmap (planned 2027) and the platform states that plainly rather than implying one exists. What is live today: the evidence binder generates an ISO 27001 pack that maps the 2022 Annex-A families individually, separating platform-fixed rows (hosting region, encryption posture, sub-processor disclosures, supplier-relationship and business-continuity clauses) from workspace-derived rows (active API-key counts, contact-record aggregate counts from your own tenant), so a certificate-bound questionnaire returns evidence for the platform plus your own organization instead of a blank annex.

Questions fréquentes

What is the difference between ISO 27001 and SOC 2?
Both are independent signals about an organization's information security, but they differ in shape and provenance. ISO 27001 is the international standard for a certifiable ISMS — a defined scope, a Statement of Applicability against the 2022 Annex-A controls, and a certificate issued by an accredited body with surveillance audits — and it is the default frame European and enterprise procurement teams write in. SOC 2 is an AICPA attestation standard: an opinion issued by a CPA firm on controls mapped to the Trust Services Criteria, default in North-American SaaS procurement. The evidence Orbit's binder produces for either framework comes from the same surfaces — audit chain, access model, encryption posture, sub-processor list — regrouped to each framework's numbering.
Is Devotel Orbit ISO 27001 certified today?
Not yet — the platform's public compliance artifact table lists ISO 27001 certification as planned for 2027, and the docs state that plainly rather than implying an unearned certificate. What ships today is the tenant-facing side: an ISO 27001 Annex-A evidence pack you can generate on demand when a buyer's questionnaire cites the standard, plus the underlying controls (encryption, tenant isolation, sub-processor disclosure, tamper-evident audit chain) audited into the SOC 2 posture. Certification is a scoped artefact — do not treat any vendor statement as interchangeable with the certificate serial on an accreditation registry.
What is Annex A, and does CPaaS traffic fall under it?
Annex A is the control set the 2022 revision of the standard consolidates into four families — A.5 organisational, A.6 people, A.7 physical, A.8 technological — referenced by clause numbers procurement teams reuse (A.5.19 supplier relationships, A.5.30 ICT readiness for business continuity). Your CPaaS traffic is squarely in those families: A.5.19 covers the sub-processor list and the 30-day change-notice period; A.5.30 covers the backup cadence, quarterly restore tests, and recovery runbook; the A.8 family covers encryption at rest and in transit and the audit chain; and the infrastructure you inherit from Devotel's own ISMS (VPC isolation, private database networking, WAF, role-based access) is what the platform-fixed binder rows state explicitly.
How do I answer an ISO 27001 questionnaire that lands on my desk?
Generate the ISO 27001 pack in Settings → Compliance → Binder: it splits your answers into platform-fixed rows (identical for every workspace — hosting region, encryption posture, sub-processor disclosures) and workspace-derived rows (your tenant's active API-key count, contact-record aggregates), then numbers them against the Annex-A families in ISO/IEC 27001:2022 so a procurement spreadsheet can be answered clause-by-clause. Quarterly regeneration is the documented cadence; regenerate on the same day any of your own settings change, just as for the HIPAA pack. Choose PDF for a human reviewer or ZIP when the questionnaire accepts per-control files imported into a GRC tool.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.