ISO 27001
ISO/IEC 27001 is the international standard for information security. It sets out the requirements for an Information Security Management System (ISMS): a systematic, risk-based way to protect the confidentiality, integrity and availability of your information — and to prove it to customers, partners and regulators.
Read more ↓
What is ISO 27001?
ISO/IEC 27001 is the world's best-known standard for information security management. It defines the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). The current version is ISO/IEC 27001:2022. It works hand in hand with ISO/IEC 27002, which gives detailed guidance on the security controls an organization can select and implement. Rather than prescribing specific technologies, ISO 27001 takes a risk-based approach: you assess your information-security risks and choose the controls that treat them.
How ISO 27001 works
At the heart of ISO 27001 is the ISMS — a management system that brings people, processes and technology together to manage information-security risk. Organizations identify and assess their risks, then select and apply appropriate controls (drawn from the Annex A control set, detailed in ISO/IEC 27002:2022), document their approach, and continually monitor and improve it. Because it follows the same high-level structure as other ISO management-system standards, ISO 27001 integrates well with standards such as ISO 9001 and ISO 20000.
Why organizations use ISO 27001
Who is ISO 27001 for?
ISO 27001 is relevant to any organization that handles sensitive information, of any size or sector. It is especially useful for information security officers, risk and compliance managers, IT managers, auditors and consultants — and for anyone responsible for protecting data and meeting security obligations.
What ISO 27001 covers
ISO 27001 covers the full information-security management cycle: leadership and context, risk assessment and treatment, the selection of controls, competence and awareness, operations, performance evaluation (including internal audit) and continual improvement. Achieving certification means an accredited body has independently verified that your ISMS meets the standard.