ISO/IEC 27001 is the international standard for an information security management system — an ISMS. It does not prescribe a fixed set of security controls so much as require a governed system for deciding which controls you need, applying them, checking they work, and improving them. Certification is issued by an accredited body against that system, not against any single technology.
The current version, ISO/IEC 27001:2022, carries 93 controls in Annex A, reorganised into four themes — organisational, people, physical and technological. That is down from 114 in the 2013 revision, though the reduction came mostly from merging overlapping controls rather than dropping requirements, and eleven controls are genuinely new.
Two artefacts do most of the work in practice. The Statement of Applicability records which Annex A controls apply, which do not, and why — and it has to stay in lockstep with reality, not with the version you submitted at certification. And the certificate runs on a three-year cycle with annual surveillance audits, so an ISMS that only comes alive before an audit will be found out in year two.
For third-party risk, the relevant clauses are the supplier controls in Annex A theme 5 — supplier relationships, security within supplier agreements, and monitoring and review of supplier services. They are the reason a vendor's ISO 27001 certificate is evidence about their suppliers as well as about them.