Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 623

ISO/IEC 27001

Reviewed byCybersecurity entrepreneur & security researcher

What is ISO/IEC 27001?

ISO/IEC 27001The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified.


ISO/IEC 27001 is the leading international standard for information security management, jointly published by ISO and the IEC. The current 2022 edition specifies requirements for establishing, operating, monitoring, and continually improving an Information Security Management System (ISMS), built on risk assessment, a Statement of Applicability, and periodic management review. The management-system clauses (4–10) are mandatory; Annex A lists 93 reference controls aligned with ISO/IEC 27002, down from 114 in the 2013 revision, now grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34).

A notable recent change is Amendment 1:2024 (published February 2024), which added climate-change considerations to clauses 4.1 and 4.2 — organisations must now determine whether climate change is a relevant issue for the ISMS and whether interested parties have climate-related requirements. No new Annex A controls were introduced.

Certification is issued by an accredited third-party body, not by ISO itself, following a Stage 1 (documentation) and Stage 2 (implementation) audit, with surveillance audits annually and full recertification every three years. It differs from the US SOC 2 attestation: 27001 certifies that a management system exists and works, whereas SOC 2 reports on control effectiveness against the Trust Services Criteria. Certification is widely required in B2B contracts, public procurement, and supply-chain due diligence.

flowchart TD
  A[Define ISMS scope + context] --> B[Risk assessment & treatment]
  B --> C[Select Annex A controls]
  C --> D[Statement of Applicability]
  D --> E[Implement & operate controls]
  E --> F[Internal audit + management review]
  F --> G[Stage 1 & Stage 2 certification audit]
  G --> H[Certificate issued - 3-year cycle]
  H --> I[Annual surveillance audits]
  I --> F

Examples

  1. 01

    A SaaS provider achieving ISO/IEC 27001 certification to win European enterprise contracts.

  2. 02

    A bank using an ISMS to manage regulatory and operational risk.

Frequently asked questions

What is ISO/IEC 27001?

The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified. It belongs to the Compliance & Frameworks category of cybersecurity.

What does ISO/IEC 27001 mean?

The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified.

How do you defend against ISO/IEC 27001?

Defences for ISO/IEC 27001 typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for ISO/IEC 27001?

Common alternative names include: ISO 27001, 27001.

Related terms

See also