ISO/IEC 27001 Standard
This is the folder that cannot contain the standard, and saying so plainly makes it a more interesting page than a copy of the text would have been. ISO/IEC standards are copyrighted and sold. That is not an obstacle to route around; it is a fact about how the organisation is funded, and it reshapes what a folder here can legitimately hold.
- Kind
- Standard — it binds by certification: a third party assesses you against it and issues something
- Issuer
- ISO and IEC, via national member bodies
- Family
- 27001 (requirements), 27002 (controls), 27005 (risk), 27036 (supplier relationships), 42001 (AI management)
- Republishable
- NO — copyrighted and sold. Not the requirement text, not Annex A verbatim, not a close paraphrase presented as a summary
source/layer- Empty, deliberately. There are no retrieved bytes because there may not be
- What is here
- Clause references, the project's own control interpretations, crosswalks out, a reading guide, and this page about the paywall
- Open question
- Can the model hold a standard it cannot quote? Unresolved →
The blocker, stated precisely
Selling these documents is how ISO and its national members are funded. This is a licensing blocker, not a writing task, and it is the single largest constraint on a site called standards. Worth noting: this project's own internal brief listed “ISO 27000” as a vault to build and never mentioned the constraint once. It would have been discovered late and expensively.
The same caution applies, in weaker form, to SOC 2 (AICPA) and PCI DSS (PCI SSC). Check per instrument; do not generalise from the EU-law case in either direction.
What this folder may legitimately hold
| Allowed | Why |
|---|---|
| Clause references — numbers and titles | “ISO/IEC 27001:2022 Annex A 8.2, Privileged access rights” is a citation, not a reproduction. This is what makes a crosswalk possible at all |
| The project's own control interpretations | Written from scratch, and the project's own work. Not a paraphrase of the standard's wording |
| Crosswalks out | To instruments that are publishable. A bridge from an ISO clause reference to a GDPR article carries no ISO text at all |
| A reading guide | What the standard is for, how it is structured, what certification involves, what it costs to obtain, what an auditor actually does |
| This page | An honest account of the paywall and what it means for a public standards resource. Nobody else writes it |
| Not allowed |
|---|
| The requirement text · Annex A verbatim · a reproduction dressed as a summary · a “derived” control list that is the standard's list with the words changed |
The open question this creates, and it is not rhetorical
Can the ontology hold a standard it cannot quote? The whole model assumes provision text as a node property: the content hash is a hash of the text, the analysis is cached against that hash, and verification means re-fetching the bytes and re-hashing them. For ISO, the text cannot be stored and cannot be published.
So what is left is a hollow provision node — identity, title, citation, no text, no content hash, no retrieval record. Is that the same kind of thing as a populated one, or a different thing wearing the same shape? Two consequences follow either way, and both are uncomfortable: a crosswalk into a hollow node cannot be checked by a reader without buying the standard, and the two-hash scheme degenerates to one hash, which removes the amendment-detection property entirely.
This folder cannot be designed until that is answered, which is why it is a page about the constraint rather than an instrument folder. The open questions →
The one real asset — ISO/IEC 27036
There is a single worked fragment in this project's material worth keeping, and it is a supplier control modelled as a node:
an ontology class forComplianceRequirement… a node “Supplier Security Assessment Conducted”… linked to our Supplier node with a relationship likecompliant_withif indeed we have evidence that an assessment was done.
The conditional at the end is the whole method in one clause. compliant_with is not asserted; it is conditional on evidence, and without the evidence the edge does not exist rather than existing as false. That is the grounding ladder stated by somebody who was not thinking about ladders.
What a reader actually wants here, and does not get
So the reading guide this folder is supposed to have — what a Stage 1 and Stage 2 audit are, what a certification body is and who accredits it, what a statement of applicability does, what a certificate actually attests to and what it does not — is not written. It is net-new work and it is honestly the most useful thing this folder could contain, because it is the part that is not behind the paywall. Gap G8 →
The honest note about cost
An organisation that wants to know what ISO/IEC 27001 requires must buy it, per standard, per user, and the family runs to several documents. That is a legitimate funding model for a body that produces consensus standards, and it also means the normative content most cited in security is the content least available to read. A public resource cannot fix that. What it can do is be clear about which of its statements are references to a document you would have to buy, and which are the project's own writing that you can read here. Every page in this folder marks the difference.