Security, Resilience & Assurance · International
ISO/IEC 27001 — Information Security Management
The leading international standard for information security management systems (ISMS). Certification is voluntary but widely required by enterprise customers and procurement processes as evidence of a mature security programme.
REGULATORInternational Organization for Standardization (ISO)
REGIONInternational
EFFECTIVEFirst published 2005; current edition ISO/IEC 27001:2022
Who it applies to
- Any organisation seeking independently certified information security governance
- Vendors responding to enterprise security questionnaires and procurement due diligence
- Organisations building a risk-based ISMS covering people, process and technology
Key requirements
- A documented Information Security Management System (ISMS)
- Risk assessment and risk treatment methodology
- Annex A controls covering access control, cryptography, physical security and more
- Internal audits and management review
- Continual improvement, evidenced over successive audit cycles
Maximum penaltyNot statutory — non-conformities can result in suspension or withdrawal of certification by the accredited certification body
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates ISO/IEC 27001 compliance
Continuous monitoring, evidence and reporting for ISO/IEC 27001 — alongside every other framework you need to satisfy.