ISO/IEC 27001

Also known as: ISO 27001

framework · cybersecurity · regulatory-standard

International standard specifying requirements for an information security management system (ISMS).

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). The standard takes a risk-based approach centered on a Plan-Do-Check-Act cycle with management commitment, risk assessment and treatment, and a Statement of Applicability documenting which controls from Annex A (which references ISO 27002) are applied. Certification by accredited bodies allows organizations to demonstrate ISMS conformance, making 27001 a frequent contractual requirement particularly for cloud and managed service providers. The 2022 revision substantially restructured Annex A from fourteen control categories to four themes (organizational, people, physical, technological).

Originators

ISO/IEC Joint Technical Committee 1, Subcommittee 27 high

Year / Decade

2005 (originally based on BS 7799-2); 2013 (major revision); 2022 (current revision) high

Primary sources

ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection — Information security management systems — Requirements high

Core components

Primary use case

Information security management system certification; demonstrating security maturity to customers and regulators; structured framework for security program design.

Common criticisms

Lineage

Siblings
ISO/IEC 27002, NIST Cybersecurity Framework, SOC 2, HITRUST CSF