What is ISO 27001?
ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
ISO 27001 is an internationally recognized standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It provides a framework for organizations to manage the security of assets such as financial information, intellectual property, employee details, and information entrusted by third parties. The standard is part of the ISO/IEC 27000 family, which includes supporting standards like ISO 27002 (code of practice for controls) and ISO 27005 (risk management).
The standard adopts a Plan-Do-Check-Act (PDCA) cycle. Organizations define an ISMS policy and scope (Plan), implement risk treatments and controls from Annex A (Do), monitor and review the system (Check), and take corrective actions (Act). Certification is granted by accredited bodies after a successful audit, demonstrating that the ISMS meets the requirements. The controls in Annex A cover 14 domains, including access control, cryptography, and incident response.
ISO 27001 fits into a broader compliance and security landscape. It is often used alongside other frameworks like SOC 2 for service organizations or as a foundation for meeting regulatory requirements such as GDPR. Many organizations pursue certification to gain a competitive advantage, as it signals a mature, risk-based approach to information security. The standard is applicable to any organization, regardless of size or industry.
Key facts
- ISO 27001 specifies requirements for an Information Security Management System (ISMS).
- Certification is awarded by accredited third-party auditors after a successful audit.
- Annex A contains 114 controls across 14 domains, but organizations select relevant ones.
- The standard follows a Plan-Do-Check-Act (PDCA) continuous improvement model.
- It is compatible with other management system standards like ISO 9001 and ISO 22301.
How it works in practice
Related terms
References
More in Standards & Compliance
BCP 14
BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.
BCP 38
BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.
GDPR
The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.
HIPAA
HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.
IANA
IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.
ICANN
ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.
IETF
The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.
ITU-T
ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.
PCI DSS
PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.
Regional Internet Registry
A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.