ISO 27001
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS).
An ISMS organises how an organisation manages information security risks. It connects responsibilities, risk assessment, selected controls, monitoring and improvement, with the aim of protecting information confidentiality, integrity and availability.
The standard can be applied by organisations of different sizes and sectors. Implementing an ISMS and obtaining independent certification are distinct steps; a reference to the standard alone does not demonstrate certification.
Variant: ISO27001. Family: Standards and frameworks.
Read the risk assessment guide · Discuss your ISMS needs
Reference: ISO — ISO/IEC 27001.