Start a free trial
Menu

ISO

ISO management system standards

Quality and security teams running an ISO-based management system, and suppliers whose customers require one.

The ISO standards behind a management system, and how they divide: a few you can be certified against, and many more that are guidance or control sets supporting them. Knowing which is which decides what you can claim.

The distinction that decides what you can claim

ISO publishes tens of thousands of standards, and the ones a compliance team meets fall into two groups that are constantly confused. A small number are management system standards: they state requirements, and an accredited certification body can audit you against them and issue a certificate. The rest are guidance, codes of practice or control sets. They are just as useful, and you cannot be certified to them.

Getting this wrong is expensive in a tender. A supplier that writes "ISO 31000 certified" on a bid has told the evaluator something that cannot be true, because ISO 31000 is guidance and has no certification scheme. The same trap catches ISO 27002 and ISO 27005.

Quality

ISO 9001 is the quality management system standard, and the one most contracts mean when they ask for "a quality system". It is certifiable, and it is also the foundation the defence world builds on: AQAP 2110 contains its requirements and adds NATO's on top.

Information security

One certifiable standard, surrounded by publications that make it workable:

  • ISO 27001 - the information security management system. This is the certifiable one; everything below supports it.
  • ISO 27002 - the control set behind an ISO 27001 certificate: what each control actually means in practice.
  • ISO 27005 - guidance for the information security risk assessment that ISO 27001 clauses 6.1.2 and 6.1.3 require you to do.
  • ISO 27017 - cloud-specific controls, and the shared-responsibility boundary between you and your provider.
  • ISO 27018 - protection of personal data processed in the cloud.

ISO 27017 and ISO 27018 are codes of practice rather than separate certifications. You are certified against ISO 27001; those two extend the control set and can be brought inside that certificate's scope.

Risk

ISO 31000 is the international guidance for managing risk of any kind, and it is deliberately not certifiable. Its value is a common vocabulary and a defensible process, which is what an auditor is looking for when they ask how you decided something was acceptable.

How ISO fits with the defence standards

If you supply defence, ISO 9001 is rarely the whole ask. The AQAP publications build on it: AQAP 2110 contains the ISO 9001 requirements and adds configuration management, government quality assurance and contract risk, while AQAP 2310 does the same with EN 9100. So an ISO 9001 system is the foundation you would build either way, and the defence work is the delta on top.

Not the standard you were looking for?

ComplyTrain is not limited to the standards written up on this site. The product is built around a requirement tree, and a requirement tree can be built for any standard, agreement or contractual specification that has requirements in it - ISO 13485, ISO 14001, ISO 45001, IEC 62443, EN 9100 and the rest included. The pages here are what we have documented so far, not the boundary of what the system handles.

We add standards on request, and the list grows steadily. If the standard your customer or contract requires is not here, tell us which one you need and we will tell you what supporting it in your workspace involves.

How ComplyTrain helps you run an ISO management system

Most teams end up holding more than one of these at once - a quality system, a security system and a risk framework - and the overlap between them is where the duplicated effort lives:

  • The ISO 9001-structured quality system: audits, findings, corrective action to closure - Quality Management
  • Each standard's requirements as a tracked set, traced to the evidence that satisfies it, so one piece of evidence can answer several standards at once - Requirements Management
  • Manuals, procedures and documented information under revision control with sign-off - Document Control
  • A risk register on a consistent, calibrated scale, which is what ISO 31000 asks for and what ISO 27001 clause 6.1 needs - Risk Management
  • Competence records that prove understanding rather than attendance - Training Management

Because the requirement tree is the product's core rather than a per-standard feature, a standard we have not written a page for is a content job, not an engineering one. Ask, and it can be added.

ComplyTrain holds no ISO certification of its own and does not claim one. It is the system you build and run your own management system in, and where the evidence for your certificate lives.

Questions

Which ISO standards can you actually be certified against?

Of the ones covered here, ISO 9001 and ISO 27001. They state requirements, and an accredited certification body audits you against them. ISO 27002, ISO 27005, ISO 27017, ISO 27018 and ISO 31000 are guidance, codes of practice or control sets: they support a certification without being one. Claiming certification to any of those on a bid is a claim an evaluator can disprove.

Can we be certified to ISO 27017 or ISO 27018?

Not as standalone certificates. They are codes of practice that extend the ISO 27002 control set for cloud services and for personal data in the cloud. The certificate you hold is ISO 27001, and those controls can be brought inside its scope.

Is ISO 31000 certifiable?

No, and deliberately so. ISO 31000 is guidance for managing risk, not a set of auditable requirements. What it gives you is a common vocabulary and a defensible process - which is what an auditor is really asking for when they want to know how you concluded a risk was acceptable.

How does ISO 9001 relate to AQAP 2110?

AQAP 2110 contains the requirements of ISO 9001 and adds NATO's on top: configuration management, government quality assurance, risk to contract performance and the customer's right of access. So an ISO 9001 system is the foundation, and the AQAP work is the delta. AQAP 2310 does the same thing with EN 9100 for aviation and space.

The ISO standard we need is not listed here. Can you support it?

Yes. The pages on this site are the standards documented so far, not the limit of what the product handles - ComplyTrain is built around a requirement tree, and one can be built for any standard with requirements in it, ISO 13485, ISO 14001, ISO 45001 and IEC 62443 included. We add standards on request. Tell us which one you need and we will explain what supporting it in your workspace involves.

Implementation

Running more than one ISO standard without doing the work twice

The overlap between a quality system, a security system and a risk framework is where most of the duplicated effort hides.

  1. Separate the certifiable from the supporting

    Know which of your standards can carry a certificate and which cannot. It decides what you may write on a bid, and what an auditor will actually ask to see.

  2. Hold each standard as a requirement set

    Not as a manual. A tracked set is countable, and gaps are visible before somebody else finds them.

  3. Let one piece of evidence answer several standards

    Access control, supplier assessment and competence records appear in more than one standard. Traced properly, the same record satisfies each without being rewritten.

  4. Keep the risk assessment defensible

    A consistent, calibrated scale with the reasoning recorded is what ISO 31000 describes and what ISO 27001 clause 6.1 expects to see.

Need a standard that is not listed?

Tell us which one your contract cites and we will explain what supporting it in your workspace involves. We add standards on request.

Official sources

The primary sources behind this page. Where a standard is quoted here, the publisher's own page is the authority.

Run your ISO management system in one place

See how ComplyTrain maps to the standards you hold on a 30-minute demo, walked through on your own processes. And if a standard you need is not on this site yet, say so on the call - we add standards on request.