CyberGlossary

Compliance & Frameworks

ISO/IEC 27001

Also known as: ISO 27001, 27001

Definition

The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified.

ISO/IEC 27001 is the leading international standard for information security management, jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The current 2022 edition specifies requirements for establishing, operating, monitoring, and continually improving an Information Security Management System (ISMS), including risk assessment, statement of applicability, and management review. Annex A lists 93 reference controls aligned with ISO/IEC 27002. Organizations can obtain accredited third-party certification, which is widely recognized in B2B contracts, public procurement, and supply-chain due diligence around the world.

Examples

  • A SaaS provider achieving ISO/IEC 27001 certification to win European enterprise contracts.
  • A bank using an ISMS to manage regulatory and operational risk.

Related terms