ISO 27001

The world's leading international standard that specifies the requirements for establishing, maintaining, and continually improving an information security management system (ISMS).

What is ISO 27001?

ISO 27001, officially ISO/IEC 27001, sets requirements for an information security management system (ISMS). First, organizations use it to establish, operate, and improve information security. The standard uses a risk-based approach across people, processes, and technology. Therefore, it guides security management without requiring specific technologies. ISO and IEC published it in 2005 and revised it in 2013 and 2022. The current version is ISO/IEC 27001:2022.

What is an ISMS?

How is the standard structured?

  • Clauses 4 to 10: These clauses cover auditable requirements for context, leadership, planning, support, operations, performance evaluation, and improvement.
  • Annex A controls: The 2022 version lists 93 controls across four themes: organizational, people, physical, and technological. By comparison, the 2013 version had 114 controls across 14 domains.
  • Statement of Applicability (SoA): This required document explains which controls the organization includes or excludes and why.

What does certification involve?

Why does ISO 27001 matter?

  • Builds trust: As a result, certification shows customers, partners, and regulators that an organization manages security through a structured audit process.
  • Widely adopted: Today, tens of thousands of organizations across many sectors use this global security standard.
  • Supports other obligations: Aligning with ISO 27001 helps meet many legal, regulatory, and contractual security requirements.