What Is ISO 27001?
ISO/IEC 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Published by the International Organization for Standardization, it provides a systematic framework for managing information security risks through policies, processes, and controls covering areas such as access control, asset management, cryptography, physical security, and incident response. Organizations can pursue formal certification against ISO 27001 through accredited auditors, demonstrating to customers, partners, and regulators that they manage security risk in a structured, auditable way. Annex A of the standard lists a set of reference controls — including identity and access management, privileged access, and authentication — that certified organizations must implement or explicitly justify excluding, based on their own risk assessment.
Why It Matters
Access control is one of the most heavily audited domains under ISO 27001, and non-human identities are where that control most often breaks down in practice. Service accounts, API keys, and automation credentials are frequently created outside standard provisioning processes, never formally reviewed, and left active long after the project that needed them has ended. With non-human identities outnumbering human employees 45 to 1 in many environments, and a typical 100-person company running over 2,000 of them, auditors increasingly ask a pointed question: can you produce a complete inventory of every non-human identity, its owner, and its access rights? Given that 80% of identity breaches now involve a non-human identity (OWASP NHI Top 10, 2025), this is not a paperwork exercise — an orphaned service account with standing production access is exactly the kind of finding that fails an ISO 27001 audit and, separately, gives an attacker a quiet way in. Closing that gap requires visibility that spreadsheets and periodic access reviews rarely provide.
How Cydenti Helps
Cydenti gives ISO 27001 audit and compliance teams a continuously maintained inventory of service accounts, API keys, and other non-human identities, mapped to owners, permissions, and usage. Instead of assembling access-control evidence manually before an audit, teams can pull an up-to-date view that speaks directly to Annex A controls around access management and privileged accounts. Risk scoring surfaces orphaned, over-privileged, or unreviewed identities that would otherwise surface as audit findings, and reporting is structured to support recurring surveillance audits, not just the initial certification. For organizations maintaining or pursuing ISO 27001 certification, that turns identity governance into evidence you can hand an auditor directly.
Explore →Frequently Asked Questions
Does ISO 27001 specifically require managing non-human identities?
ISO 27001 doesn't name 'non-human identities' explicitly, but its Annex A controls on access management, authentication, and privileged access apply to any account with system access — including service accounts and API keys. In practice, auditors expect these to be inventoried, reviewed, and controlled the same as human user accounts.
How often is ISO 27001 compliance reassessed?
Certified organizations undergo annual surveillance audits and a full recertification audit every three years. Because access rights and non-human identities change constantly between audits, most organizations need ongoing monitoring rather than a one-time cleanup to stay ready for each cycle.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h