Skip to content
New · Ask Viglyn, your AI compliance copilot. Ask your program anything.See it
ISO 27001

ISO 27001 on evidence that proves itself

Build your ISMS on continuous checks and tamper-evident evidence, then run Stage 1 and Stage 2 in the same place the evidence lives.

What it is

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It's risk-based: you scope the ISMS, assess risks, treat them with controls, and get certified by an accredited certification body through Stage 1 and Stage 2 audits.

Who it's for

Companies selling globally, where ISO 27001 certification is the common security baseline buyers recognize.

With Viglyn

How Viglyn runs ISO 27001

  • Automated checks collect evidence continuously from your cloud, identity, device, code, and HR systems
  • The risk module covers the ISMS core: a library to start from, 5x5 scoring with inherent and residual values, four treatment paths with approvals, and risks linked to controls
  • Stage 1 and Stage 2 run inside Viglyn with structured evidence requests and exportable workpapers
  • One set of evidence maps across frameworks, so ISO 27001 work counts toward SOC 2 too
FAQ

ISO 27001 questions

Is ISO 27001 a certification?
Yes. An accredited certification body audits your ISMS in two stages and issues the certificate. Viglyn is where you prepare and where the audit workflow runs; the certification decision is the body's alone.
How does ISO 27001 relate to SOC 2?
They share a large amount of underlying control work. In Viglyn one set of evidence maps across frameworks, so evidence collected for ISO 27001 also counts toward SOC 2.
Does Viglyn handle the risk assessment?
The risk management module gives you a library to start from, 5x5 scoring with customizable labels, inherent and residual scores, and four treatment paths that each require an approval. Risks link to the controls that treat them.

See ISO 27001 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.