standards.sgit.ai / instruments / iso-27001

ISO/IEC 27001 Standard

This is the folder that cannot contain the standard, and saying so plainly makes it a more interesting page than a copy of the text would have been. ISO/IEC standards are copyrighted and sold. That is not an obstacle to route around; it is a fact about how the organisation is funded, and it reshapes what a folder here can legitimately hold.

Kind
Standard — it binds by certification: a third party assesses you against it and issues something
Issuer
ISO and IEC, via national member bodies
Family
27001 (requirements), 27002 (controls), 27005 (risk), 27036 (supplier relationships), 42001 (AI management)
Republishable
NO — copyrighted and sold. Not the requirement text, not Annex A verbatim, not a close paraphrase presented as a summary
source/ layer
Empty, deliberately. There are no retrieved bytes because there may not be
What is here
Clause references, the project's own control interpretations, crosswalks out, a reading guide, and this page about the paywall
Open question
Can the model hold a standard it cannot quote? Unresolved →

The blocker, stated precisely

You cannot republish ISO text. Not 27001, not 27002, not 27005, not 31000, not 42001. Not the requirement text, not Annex A verbatim, and not a close paraphrase presented as a summary — the last one being the route people take without noticing that they have taken it.

Selling these documents is how ISO and its national members are funded. This is a licensing blocker, not a writing task, and it is the single largest constraint on a site called standards. Worth noting: this project's own internal brief listed “ISO 27000” as a vault to build and never mentioned the constraint once. It would have been discovered late and expensively.

The same caution applies, in weaker form, to SOC 2 (AICPA) and PCI DSS (PCI SSC). Check per instrument; do not generalise from the EU-law case in either direction.

What this folder may legitimately hold

AllowedWhy
Clause references — numbers and titles“ISO/IEC 27001:2022 Annex A 8.2, Privileged access rights” is a citation, not a reproduction. This is what makes a crosswalk possible at all
The project's own control interpretationsWritten from scratch, and the project's own work. Not a paraphrase of the standard's wording
Crosswalks outTo instruments that are publishable. A bridge from an ISO clause reference to a GDPR article carries no ISO text at all
A reading guideWhat the standard is for, how it is structured, what certification involves, what it costs to obtain, what an auditor actually does
This pageAn honest account of the paywall and what it means for a public standards resource. Nobody else writes it
Not allowed
The requirement text · Annex A verbatim · a reproduction dressed as a summary · a “derived” control list that is the standard's list with the words changed

The open question this creates, and it is not rhetorical

Q3 — unresolved

Can the ontology hold a standard it cannot quote? The whole model assumes provision text as a node property: the content hash is a hash of the text, the analysis is cached against that hash, and verification means re-fetching the bytes and re-hashing them. For ISO, the text cannot be stored and cannot be published.

So what is left is a hollow provision node — identity, title, citation, no text, no content hash, no retrieval record. Is that the same kind of thing as a populated one, or a different thing wearing the same shape? Two consequences follow either way, and both are uncomfortable: a crosswalk into a hollow node cannot be checked by a reader without buying the standard, and the two-hash scheme degenerates to one hash, which removes the amendment-detection property entirely.

This folder cannot be designed until that is answered, which is why it is a page about the constraint rather than an instrument folder. The open questions →

The one real asset — ISO/IEC 27036

There is a single worked fragment in this project's material worth keeping, and it is a supplier control modelled as a node:

an ontology class for ComplianceRequirement… a node “Supplier Security Assessment Conducted”… linked to our Supplier node with a relationship like compliant_with if indeed we have evidence that an assessment was done.

The conditional at the end is the whole method in one clause. compliant_with is not asserted; it is conditional on evidence, and without the evidence the edge does not exist rather than existing as false. That is the grounding ladder stated by somebody who was not thinking about ladders.

What a reader actually wants here, and does not get

A site called “standards” will be asked how certification works, and there is nothing on this estate about it. Conformity assessment appears in three files; supervisory authority in four; attestation appears in eighty-eight and almost entirely in the cryptographic sense rather than the audit one.

So the reading guide this folder is supposed to have — what a Stage 1 and Stage 2 audit are, what a certification body is and who accredits it, what a statement of applicability does, what a certificate actually attests to and what it does not — is not written. It is net-new work and it is honestly the most useful thing this folder could contain, because it is the part that is not behind the paywall. Gap G8 →

The honest note about cost

An organisation that wants to know what ISO/IEC 27001 requires must buy it, per standard, per user, and the family runs to several documents. That is a legitimate funding model for a body that produces consensus standards, and it also means the normative content most cited in security is the content least available to read. A public resource cannot fix that. What it can do is be clear about which of its statements are references to a document you would have to buy, and which are the project's own writing that you can read here. Every page in this folder marks the difference.