Standards & Compliance

What is ISO 27001?

Definition

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ISO 27001 is an internationally recognized standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It provides a framework for organizations to manage the security of assets such as financial information, intellectual property, employee details, and information entrusted by third parties. The standard is part of the ISO/IEC 27000 family, which includes supporting standards like ISO 27002 (code of practice for controls) and ISO 27005 (risk management).

The standard adopts a Plan-Do-Check-Act (PDCA) cycle. Organizations define an ISMS policy and scope (Plan), implement risk treatments and controls from Annex A (Do), monitor and review the system (Check), and take corrective actions (Act). Certification is granted by accredited bodies after a successful audit, demonstrating that the ISMS meets the requirements. The controls in Annex A cover 14 domains, including access control, cryptography, and incident response.

ISO 27001 fits into a broader compliance and security landscape. It is often used alongside other frameworks like SOC 2 for service organizations or as a foundation for meeting regulatory requirements such as GDPR. Many organizations pursue certification to gain a competitive advantage, as it signals a mature, risk-based approach to information security. The standard is applicable to any organization, regardless of size or industry.

Key facts

  • ISO 27001 specifies requirements for an Information Security Management System (ISMS).
  • Certification is awarded by accredited third-party auditors after a successful audit.
  • Annex A contains 114 controls across 14 domains, but organizations select relevant ones.
  • The standard follows a Plan-Do-Check-Act (PDCA) continuous improvement model.
  • It is compatible with other management system standards like ISO 9001 and ISO 22301.

How it works in practice

A financial services company handling sensitive client data implements ISO 27001 to formalize its security processes. After a gap analysis, it selects controls from Annex A for encryption, access control, and incident management. Following an internal audit and management review, it engages a accredited certification body for an external audit. Once certified, the company uses the certification in marketing materials to assure clients of its security posture.

Related terms

ISMS ISO 27002 ISO 27005 SOC 2 NIST Cybersecurity Framework GDPR Risk assessment

References

More in Standards & Compliance

BCP 14

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

GDPR

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

HIPAA

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Regional Internet Registry

A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.

Who Is Online

In total there are 53 users online: 0 registered, 47 guests and 6 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369