Back to Glossary

International standard

ISO/IEC 27001

An international standard specifying requirements for an Information Security Management System (ISMS).

Related domain: CybersecurityConcept ID: concept-iso-27001

Definition

ISO/IEC 27001 is an international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).

Human Explanation

It describes how an organisation should manage Information Security to identify and control Risk systematically.

Why it Matters

It provides a globally recognised management framework and supports Trust among customers, partners and regulators.

Conceptual Boundary

ISO/IEC 27001 does not prescribe particular security technologies or products. It defines management system requirements and leaves implementation choices to the organisation.

Practical Perspective

Certification does not mean an organisation is completely secure. It confirms that a structured Information Security Management System is in place.

Related Concepts

Official Source

ISO/IEC 27001