ISO/IEC 27001
Also known as: ISO 27001
International standard specifying requirements for an information security management system (ISMS).
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). The standard takes a risk-based approach centered on a Plan-Do-Check-Act cycle with management commitment, risk assessment and treatment, and a Statement of Applicability documenting which controls from Annex A (which references ISO 27002) are applied. Certification by accredited bodies allows organizations to demonstrate ISMS conformance, making 27001 a frequent contractual requirement particularly for cloud and managed service providers. The 2022 revision substantially restructured Annex A from fourteen control categories to four themes (organizational, people, physical, technological).
Core components
- Context establishment
- Leadership commitment
- Risk assessment and treatment
- Statement of Applicability
- Annex A controls (referencing ISO 27002)
- PDCA cycle
- Internal audit
- Management review
- Continual improvement
Primary use case
Information security management system certification; demonstrating security maturity to customers and regulators; structured framework for security program design.
Common criticisms
- Process-heavy approach can produce documentation without genuine security improvement
- certification audits sample-based and time-bounded
- substantial implementation cost particularly for small organizations
- Annex A control set may not address all domain-specific risks.
Lineage
- Siblings
- ISO/IEC 27002, NIST Cybersecurity Framework, SOC 2, HITRUST CSF